Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,949
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-180319.8 CRI27.3%
——8The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.28dCVE-2024-32573—27.3%
——8——CVE-2024-37602—27.3%
——8——CVE-2023-47014—27.3%
——8——CVE-2026-28674—27.3%
——8——CVE-2025-9198—27.3%
——8——CVE-2026-180567.5 HIG27.3%
——8The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without performing any application ID or audience validation — specifically, no /debug_token verification and no comparison of the token's app_id against the configured hp_facebook_app_id. This makes it possible for unauthenticated attackers to authenticate as any existing WordPress user, including administrators, whose email address is associated with a Facebook account for which the attacker can obtain any valid access token. Important Note: To exploit the vulnerability, the attacker must obtain the victim's access token.8dCVE-2013-0534—27.3%
——8——CVE-2025-49692—27.3%
——8——CVE-2025-59045—27.3%
——8——CVE-2023-23427—27.3%
——8——CVE-2024-30178—27.3%
——8——CVE-2016-4634—27.3%
——8——CVE-2016-4960—27.3%
——8——CVE-2001-0806—27.3%
——8——CVE-2012-3128—27.3%
——8——CVE-2006-0380—27.3%
——8——CVE-2023-5377—27.3%
——8——CVE-2026-187769.8 CRI27.3%
——8The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.28dCVE-2026-40727—27.3%
——8——CVE-2018-6269—27.3%
——8——CVE-2019-25501—27.3%
——8——CVE-2026-4358—27.3%
——8——CVE-2016-5242—27.3%
——8——CVE-2026-156309.9 CRI27.3%
——8A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).5dCVE-2017-18790—27.3%
——8——CVE-2021-25656—27.3%
——8——CVE-2023-35783—27.3%
——8——CVE-2024-54253—27.3%
——8——CVE-2022-37818—27.3%
——8——CVE-2024-358878.8 HIG27.3%
——8In the Linux kernel, the following vulnerability has been resolved:
ax25: fix use-after-free bugs caused by ax25_ds_del_timer
When the ax25 device is detaching, the ax25_dev_device_down()
calls ax25_ds_del_timer() to cleanup the slave_timer. When
the timer handler is running, the ax25_ds_del_timer() that
calls del_timer() in it will return directly. As a result,
the use-after-free bugs could happen, one of the scenarios
is shown below:
(Thread 1) | (Thread 2)
| ax25_ds_timeout()
ax25_dev_device_down() |
ax25_ds_del_timer() |
del_timer() |
ax25_dev_put() //FREE |
| ax25_dev-> //USE
In order to mitigate bugs, when the device is detaching, use
timer_shutdown_sync() to stop the timer.2dCVE-2026-640689.8 CRI27.3%
——8In the Linux kernel, the following vulnerability has been resolved:
netfs: Fix missing locking around retry adding new subreqs
Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take
the appropriate lock when adding extra subrequests into
stream->subrequests.9dCVE-2024-33007—27.3%
——8——CVE-2026-810918.6 HIG27.3%
——8The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it without inspecting the host, so loopback, link-local and private addresses were all accepted, as were names that resolve to them, and the validation was not reapplied to a redirect the destination returned. A caller could therefore make the server issue requests to addresses reachable only from the host it runs on and read the responses. The current code calls isSafeProxyTarget, which checks the resolved address against private, loopback and link-local ranges before proxying and bounds the number of redirects followed.20dCVE-2025-1366—27.3%
——8——CVE-2026-783629.8 CRI27.3%
——8The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.8dCVE-2020-11919—27.3%
——8——CVE-2026-456787.5 HIG27.3%
——8OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.56dCVE-2026-659236.8 MED27.3%
——8A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.48dCVE-2025-4892—27.3%
——8——