Vulnerabilities exploitable today
352,162in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,073
- High6,924
- Medium5,904
- Low547
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-655407.1 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.3hCVE-2026-655397.1 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.3hCVE-2026-655374.3 MED—
——0Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.3hCVE-2026-655366.5 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.3hCVE-2026-655354.3 MED—
——0Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.3hCVE-2026-577036.3 MED—
——0Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.3hCVE-2026-655345.9 MED—
——0Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.3hCVE-2026-573677.1 HIG—
——0Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.3hCVE-2026-655314.8 MED—
——0Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.3hCVE-2026-655304.3 MED—
——0Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.3hCVE-2026-577017.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.3hCVE-2026-655295.3 MED—
——0Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.3hCVE-2026-131196.5 MED—
——0The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys directly as column identifiers in the SET clause of an UPDATE statement built inside RTEC_Db_Admin::update_entry(). Only esc_sql() (mysqli_real_escape_string) is applied to the identifier; that function escapes quotes, backslashes, and a few control characters but does not escape spaces, equals signs, parentheses, or hyphens, so an attacker can break out of the identifier context and inject subqueries (terminated with a SQL comment). This makes it possible for authenticated attackers, with Contributor-level access and above who can edit the targeted event, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.5hCVE-2026-274234.3 MED—
——0Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.3hCVE-2026-577047.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.3hCVE-2026-595149.3 CRI—
——0Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.3hCVE-2026-655286.5 MED—
——0Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.3hCVE-2026-14286——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.13dCVE-2025-66334—0.0%
——0——CVE-2026-243497.1 HIG0.0%
——0A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.7hCVE-2025-48625—0.0%
——0——CVE-2026-49945——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15dCVE-2026-49946——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.15dCVE-2026-50268—0.0%
——0——CVE-2026-50238——
——0Rejected reason: Red Hat Product Security has concluded that this CVE is not required. The reported issue has been classified as a regular bug and will be addressed through the standard bug-fixing process.20dCVE-2026-16552——
——0Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.4hCVE-2026-47105——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.23dCVE-2025-45764—0.0%
——0——CVE-2023-21178—0.0%
——0——CVE-2025-47407—0.0%
——0——CVE-2026-252717.8 HIG0.0%
——0Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.16dCVE-2026-28549—0.0%
——0——CVE-2025-66326—0.0%
——0——CVE-2026-28551—0.0%
——0——CVE-2026-61692——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a duplicate of CVE-2026-61454. Notes: All CVE users should reference CVE-2026-61454 instead of this candidate.10dCVE-2026-58407——
——0Rejected reason: Please submit CVE requests for each vulnerability.10dCVE-2026-0121—0.0%
——0——CVE-2025-48575—0.0%
——0——CVE-2026-58461——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.9dCVE-2026-0158—0.0%
——0——