Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654366.8 MED—
———Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.2hCVE-2026-106004.3 MED—
———Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-006943hCVE-2026-655575.9 MED—
———Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.2hCVE-2026-655585.4 MED—
———Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.2hCVE-2025-59181——
———Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.3hCVE-2026-655616.5 MED—
———Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.2hCVE-2026-655626.5 MED—
———Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.2hCVE-2026-655635.9 MED—
———Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.2hCVE-2025-59180——
———Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.3h