Vulnerabilities exploitable today
352,162in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,073
- High6,924
- Medium5,904
- Low547
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654736.5 MED—
——0Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.4hCVE-2026-648158.1 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files4hCVE-2026-648148.6 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session4hCVE-2026-655167.2 HIG—
——0Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.4hCVE-2026-655244.3 MED—
——0Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.4hCVE-2026-654756.5 MED—
——0Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS.
This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.4hCVE-2026-619477.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.4hCVE-2026-6481310.0 CRI—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session4hCVE-2026-6481210.0 CRI—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session4hCVE-2026-648117.8 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration4hCVE-2026-648104.3 MED—
——0In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking4hCVE-2026-655255.3 MED—
——0Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.4hCVE-2026-654765.3 MED—
——0Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.4hCVE-2026-648098.4 HIG—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter4hCVE-2026-655327.6 HIG—
——0Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.4hCVE-2026-595449.8 CRI—
——0Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.4hCVE-2026-595439.9 CRI—
——0Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.4hCVE-2026-655336.5 MED—
——0Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.4hCVE-2026-648088.4 HIG—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling4hCVE-2026-655385.9 MED—
——0Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.4hCVE-2026-648077.8 HIG—
——0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration4hCVE-2026-595427.7 HIG—
——0Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.4hCVE-2026-595409.8 CRI—
——0Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.4hCVE-2026-656069.6 CRI—
——0SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.4hCVE-2026-648037.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK4hCVE-2026-648027.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration4hCVE-2026-658967.1 HIG—
——0Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation.4hCVE-2026-654777.5 HIG—
——0Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.4hCVE-2026-654785.4 MED—
——0Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.4hCVE-2026-648003.5 LOW—
——0In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default4hCVE-2026-619815.4 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.4hCVE-2026-619734.3 MED—
——0Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.4hCVE-2026-654795.4 MED—
——0Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.4hCVE-2026-62165——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61446. Reason: This candidate is a duplicate of CVE-2026-61446. Notes: All CVE users should reference CVE-2026-61446 instead of this candidate.8dCVE-2026-619725.3 MED—
——0Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.4hCVE-2026-131196.5 MED—
——0The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identifier; that function escapes quotes, backslashes, and a few control characters but does not escape spaces, equals signs, parentheses, or hyphens, so an attacker can break out of the identifier context and inject subqueries (terminated with a SQL comment). This makes it possible for authenticated attackers, with Contributor-level access and above who can edit the targeted event, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.6hCVE-2026-595269.3 CRI—
——0Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.4hCVE-2026-654806.5 MED—
——0Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.4hCVE-2026-595259.3 CRI—
——0Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.4hCVE-2026-654817.5 HIG—
——0Contributor Local File Inclusion in Vino <= 1.9 versions.4h