Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,589
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-92374.3 MED33.4%
——10The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete, archive, unarchive, and duplicate arbitrary job listings — along with their associated stages, meta, addresses, and applications — by supplying an arbitrary integer job_id. The nonce verified by Dispatcher::dispatch() is exposed to all authenticated front-end visitors via wp_head script localization, meaning subscribers can trivially obtain it and satisfy the nonce check without possessing any elevated privilege.76dCVE-2026-2836—33.4%
——10——CVE-2024-2972—33.4%
——10——CVE-2023-49189—33.4%
——10——CVE-2026-9616—33.4%
——10——CVE-2025-1972—33.4%
——10——CVE-2025-53859—33.4%
——10——CVE-2025-8051—33.4%
——10——CVE-2026-1589—33.4%
——10——CVE-2023-47228—33.4%
——10——CVE-2024-31179—33.4%
——10——CVE-2025-384719.8 CRI33.4%
——10In the Linux kernel, the following vulnerability has been resolved:
tls: always refresh the queue when reading sock
After recent changes in net-next TCP compacts skbs much more
aggressively. This unearthed a bug in TLS where we may try
to operate on an old skb when checking if all skbs in the
queue have matching decrypt state and geometry.
BUG: KASAN: slab-use-after-free in tls_strp_check_rcv+0x898/0x9a0 [tls]
(net/tls/tls_strp.c:436 net/tls/tls_strp.c:530 net/tls/tls_strp.c:544)
Read of size 4 at addr ffff888013085750 by task tls/13529
CPU: 2 UID: 0 PID: 13529 Comm: tls Not tainted 6.16.0-rc5-virtme
Call Trace:
kasan_report+0xca/0x100
tls_strp_check_rcv+0x898/0x9a0 [tls]
tls_rx_rec_wait+0x2c9/0x8d0 [tls]
tls_sw_recvmsg+0x40f/0x1aa0 [tls]
inet_recvmsg+0x1c3/0x1f0
Always reload the queue, fast path is to have the record in the queue
when we wake, anyway (IOW the path going down "if !strp->stm.full_len").56dCVE-2016-9101—33.4%
——10——CVE-2023-1298—33.4%
——10——CVE-2023-25670—33.4%
——10——CVE-2025-11679—33.4%
——10——CVE-2023-25660—33.4%
——10——CVE-2024-38895—33.4%
——10——CVE-2023-25659—33.4%
——10——CVE-2023-47528—33.4%
——10——CVE-2022-31012—33.4%
——10——CVE-2023-48737—33.4%
——10——CVE-2024-9928—33.4%
——10——CVE-2023-25663—33.4%
——10——CVE-2017-15306—33.4%
——10——CVE-2020-36758—33.4%
——10——CVE-2017-3551—33.4%
——10——CVE-2026-1657—33.4%
——10——CVE-2025-59481—33.4%
——10——CVE-2026-163569.8 CRI33.4%
——10Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.61dCVE-2024-12289—33.4%
——10——CVE-2023-25669—33.4%
——10——CVE-2023-33409—33.4%
——10——CVE-2026-195347.5 HIG33.4%
——10undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.7dCVE-2023-25676—33.4%
——10——CVE-2023-47660—33.4%
——10——CVE-2024-10928—33.4%
——10——CVE-2016-8668—33.4%
——10——CVE-2024-31183—33.4%
——10——CVE-2023-25032—33.4%
——10——