Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,949
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-4589—27.3%
——8——CVE-2025-583758.1 HIG27.3%
——8Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.8dCVE-2025-6268—27.3%
——8——CVE-2026-7585—27.3%
——8——CVE-2024-21065—27.3%
——8——CVE-2011-0007—27.3%
——8——CVE-2016-1717—27.3%
——8——CVE-2026-770009.8 CRI27.3%
——8The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address.24dCVE-2020-0526—27.3%
——8——CVE-2024-9850—27.3%
——8——CVE-2024-28076—27.3%
——8——CVE-2025-10047—27.3%
——8——CVE-2024-50928—27.3%
——8——CVE-2022-3629—27.3%
——8——CVE-2026-105229.8 CRI27.3%
——8The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover.
Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory.
Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.13dCVE-2022-2465—27.3%
——8——CVE-2026-28674—27.3%
——8——CVE-2025-49692—27.3%
——8——CVE-2025-9198—27.3%
——8——CVE-2026-180319.8 CRI27.3%
——8The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.28dCVE-2026-180567.5 HIG27.3%
——8The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without performing any application ID or audience validation — specifically, no /debug_token verification and no comparison of the token's app_id against the configured hp_facebook_app_id. This makes it possible for unauthenticated attackers to authenticate as any existing WordPress user, including administrators, whose email address is associated with a Facebook account for which the attacker can obtain any valid access token. Important Note: To exploit the vulnerability, the attacker must obtain the victim's access token.8dCVE-2013-0534—27.3%
——8——CVE-2023-47014—27.3%
——8——CVE-2024-32573—27.3%
——8——CVE-2020-11919—27.3%
——8——CVE-2026-456787.5 HIG27.3%
——8OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.56dCVE-2025-4892—27.3%
——8——CVE-2026-783629.8 CRI27.3%
——8The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.8dCVE-2025-1366—27.3%
——8——CVE-2026-659236.8 MED27.3%
——8A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.48dCVE-2024-27188—27.3%
——8——CVE-2025-54563—27.3%
——8——CVE-2026-162999.8 CRI27.3%
——8The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.21dCVE-2022-37817—27.3%
——8——CVE-2025-156734.9 MED27.3%
——8The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.21dCVE-2024-37602—27.3%
——8——CVE-2018-6269—27.3%
——8——CVE-2026-30972—27.3%
——8——CVE-2023-30748—27.3%
——8——CVE-2019-25501—27.3%
——8——