Vulnerabilidades explotables hoy
352,162en la vista actual
Score único combinando CVSS, membresía KEV y EPSS. Cada CVE con su ficha propia — timeline desde publicación hasta explotación activa.
En catálogo KEV1,653
Nuevos KEV · 24H0
Exploit Today ≥ 701,590
Distribución · última ventana
- Crítico2,073
- Alto6,924
- Medio5,904
- Bajo547
Ventana
Severidad
Filtros
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-577176.5 MED—
——0Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.6hCVE-2026-577357.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.6hCVE-2026-577677.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.6hCVE-2026-577697.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.6hCVE-2026-577849.6 CRÍ—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.6hCVE-2026-577858.8 ALT—
——0Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.6hCVE-2025-36916—0.0%
——0——CVE-2026-578086.5 MED—
——0Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.6hCVE-2026-578097.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.6hCVE-2026-595127.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.6hCVE-2026-595136.5 MED—
——0Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.6hCVE-2026-595418.8 ALT—
——0Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.6hCVE-2026-595458.1 ALT—
——0Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.6hCVE-2026-595477.5 ALT—
——0Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.6hCVE-2026-595547.5 ALT—
——0Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.6hCVE-2026-5955510.0 CRÍ—
——0Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.6hCVE-2026-619437.5 ALT—
——0Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.6hCVE-2026-619447.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.6hCVE-2026-619456.5 MED—
——0Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.6hCVE-2026-619466.5 MED—
——0Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.6hCVE-2026-619499.3 CRÍ—
——0Unauthenticated SQL Injection in Bookly <= 27.7 versions.6hCVE-2026-619509.3 CRÍ—
——0Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.6hCVE-2026-619519.8 CRÍ—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.6hCVE-2026-619547.5 ALT—
——0Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.6hCVE-2026-619725.3 MED—
——0Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.6hCVE-2026-619734.3 MED—
——0Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.6hCVE-2026-619815.4 MED—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.6hCVE-2026-648003.5 BAJ—
——0In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default6hCVE-2026-648027.8 ALT—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration6hCVE-2026-648037.8 ALT—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK6hCVE-2026-648077.8 ALT—
——0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration6hCVE-2026-648088.4 ALT—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling6hCVE-2026-648098.4 ALT—
——0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter6hCVE-2026-648104.3 MED—
——0In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking6hCVE-2026-648117.8 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration6hCVE-2026-6481210.0 CRÍ—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session6hCVE-2026-6481310.0 CRÍ—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session6hCVE-2026-648148.6 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session6hCVE-2026-648158.1 ALT—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files6hCVE-2026-654525.3 MED—
——0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.6h