Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-28197—32.1%
——10——CVE-2025-32878—32.1%
——10——CVE-2025-54473—32.1%
——10——CVE-2017-13666—32.1%
——10——CVE-2017-16536—32.1%
——10——CVE-2021-4162—32.1%
——10——CVE-2024-21086—32.1%
——10——CVE-2025-32423—32.1%
——10——CVE-2024-11206—32.1%
——10——CVE-2026-22243—32.1%
——10——CVE-2026-685007.5 HIG32.1%
——10Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.11dCVE-2025-60036—32.1%
——10——CVE-2016-9911—32.1%
——10——CVE-2022-29436—32.1%
——10——CVE-2024-21024—32.1%
——10——CVE-2024-21025—32.1%
——10——CVE-2024-44217—32.1%
——10——CVE-2025-60035—32.1%
——10——CVE-2006-6101—32.1%
——10——CVE-2026-28221—32.1%
——10——CVE-2024-37568—32.1%
——10——CVE-2026-12862—32.1%
——10——CVE-2024-21022—32.1%
——10——CVE-2026-13602—32.1%
——10We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:
*
The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay
contain a code path that is intended for the transport of session
parameters from a tab with isolated cookies (e.g. in the pretix widget)
to a new tab. For this purpose, a set of session parameters is
cryptographically signed and then passed to the new tab as a URL
parameter. The plugins perform no further validation of the session
parameters, other than the cryptographic signature being valid. This is
fixed with the releases issued today by strictly validating that no
session parameters outside of the scope of the respective plugin may be
set.
*
An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer
headers for outgoing links to prevent leakage of secrets in URLs. This
redirect page also requires cryptographically signed parameters.
Unfortunately, it uses the same key and salt for the signature as the
previously mentioned feature in the payment integration plugins. A
motivated attacker with access to at least one event in the backend can
trick the system into cryptographically signing arbitrary content using
specially crafted links. In combination with the previous issue, the
attacker could use this to set and modify arbitrary parameters on their
user session by injecting the signed parameters into the feature of the
payment providers. This is fixed with the releases issued today by using
different salts for the signature for each plugin and feature.
*
A third, unrelated feature in the core system is used for admin users
to act on behalf of another user, mostly for debugging purposes. With
being able to insert arbitrary parameters into a session, an attacker
can abuse this feature to change their session from their actual user to
any user in the system by guessing a valid user ID. This is fixed with
the release today by requiring unguessable information to be contained
in the session of the user to switch to.81dCVE-2026-132306.5 MED32.1%
——10An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechanism, which exposes
sensitive geolocation information without requiring authentication. This issue
allows an attacker on the same local network to retrieve geolocation-related
data through crafted responses.
The
vulnerability impacts confidentiality only, with no evidence of integrity of
availability impact.46dCVE-2021-0259—32.1%
——10——CVE-2026-507405.4 MED32.1%
——10A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.75dCVE-2025-2305—32.1%
——10——CVE-2026-212848.1 HIG32.1%
——10Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.25dCVE-2024-40706—32.1%
——10——CVE-2023-25961—32.1%
——10——CVE-2026-33979—32.1%
——10——CVE-2023-20171—32.1%
——10——CVE-2025-32436—32.1%
——10——CVE-2025-32982—32.1%
——10——CVE-2023-46754—32.1%
——10——CVE-2026-12049—32.1%
——10——CVE-2024-21037—32.1%
——10——CVE-2024-9470—32.1%
——10——CVE-2025-22131—32.1%
——10——