Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,390
- High8,612
- Medium7,064
- Low795
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-37830—34.7%
——10——CVE-2024-51495—34.7%
——10——CVE-2026-608436.5 MED34.7%
——10Vulnerability in the Oracle Citizen Interaction Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Citizen Interaction Center. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Citizen Interaction Center accessible data as well as unauthorized access to critical data or complete access to all Oracle Citizen Interaction Center accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).49dCVE-2024-5234—34.7%
——10——CVE-2020-8023—34.7%
——10——CVE-2026-0698—34.7%
——10——CVE-2023-28884—34.7%
——10——CVE-2022-31669—34.7%
——10——CVE-2025-6007—34.7%
——10——CVE-2026-4349—34.7%
——10——CVE-2023-21994—34.7%
——10——CVE-2024-11560—34.7%
——10——CVE-2017-0739—34.7%
——10——CVE-2026-2552—34.7%
——10——CVE-2015-8818—34.7%
——10——CVE-2023-1071—34.7%
——10——CVE-2023-50935—34.7%
——10——CVE-2021-41613—34.7%
——10——CVE-2022-50799—34.7%
——10——CVE-2024-5239—34.7%
——10——CVE-2006-0558—34.7%
——10——CVE-2015-4232—34.7%
——10——CVE-2025-1906—34.7%
——10——CVE-2026-7707—34.7%
——10——CVE-2024-11553—34.7%
——10——CVE-2025-59151—34.7%
——10——CVE-2026-203109.1 CRI34.7%
——10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.40dCVE-2024-4907—34.7%
——10——CVE-2017-7760—34.7%
——10——CVE-2014-9718—34.7%
——10——CVE-2026-896149.8 CRI34.7%
——10In the Linux kernel, the following vulnerability has been resolved:
ntfs: bound the free-cluster bitmap scan to the volume
vol->lcn_empty_bits_per_page is sized from vol->nr_clusters at mount, but
ntfs_cluster_alloc() bounds its scan of that array by the size of $Bitmap.
Those are independent on-disk quantities and the mount-time check only
rejects a $Bitmap that is too small, so an image whose $Bitmap covers more
clusters than the volume has lets the scan index past the array. A run
whose LCN lies in that gap takes the allocator straight there, since the
caller passes the file's own last LCN as its locality hint. KASAN reports
a slab out-of-bounds read when a file on such a volume is extended.
Clamp the scan to what that array covers, mirroring the max_index
calculation the mount-time scan already uses, and reject a decoded LCN
at or beyond nr_clusters in the mapping pairs decoder. Conforming
volumes are unaffected.11dCVE-2024-42020—34.7%
——10——CVE-2026-4716—34.7%
——10——CVE-2017-3246—34.7%
——10——CVE-2022-35709—34.7%
——10——CVE-2026-758368.8 HIG34.7%
——10The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST /api/v1/menubar/actions/{plugin}/{action} endpoint only checks the baseline api.access permission and never evaluates the authorize field a plugin registered for that action. Any authenticated caller with api.access can therefore invoke a privileged menubar action directly, bypassing the intended authorization. No plugin bundled with core Grav currently registers a privileged authorize handler, so on a stock install the impact is latent; the flaw affects any first- or third-party plugin relying on the documented authorize semantics.15dCVE-2026-547259.6 CRI34.7%
——10vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.13dCVE-2025-6009—34.7%
——10——CVE-2025-8023—34.7%
——10——CVE-2025-462066.5 MED34.7%
——10An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion81d