Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,705
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-409418.1 HIG34.1%
——10In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: don't read past the mfuart notifcation
In case the firmware sends a notification that claims it has more data
than it has, we will read past that was allocated for the notification.
Remove the print of the buffer, we won't see it by default. If needed,
we can see the content with tracing.
This was reported by KFENCE.50dCVE-2023-33750—34.1%
——10——CVE-2024-12177—34.1%
——10——CVE-2026-619499.3 CRI34.1%
——10Unauthenticated SQL Injection in Bookly <= 27.7 versions.62dCVE-2025-23406—34.1%
——10——CVE-2022-48140—34.1%
——10——CVE-2026-581787.5 HIG34.1%
——10The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.54dCVE-2026-56068—34.1%
——10——CVE-2020-12499—34.1%
——10——CVE-2024-3718—34.1%
——10——CVE-2025-20196—34.1%
——10——CVE-2001-1400—34.1%
——10——CVE-2024-4903—34.1%
——10——CVE-2026-576839.3 CRI34.1%
——10Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.83dCVE-2026-577079.3 CRI34.1%
——10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.72dCVE-2023-295384.3 MED34.1%
——10Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.35dCVE-2023-33257—34.1%
——10——CVE-2026-707228.2 HIG34.1%
——10Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Advanced Inbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Inbound Telephony accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Advanced Inbound Telephony. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).30dCVE-2026-23983—34.1%
——10——CVE-2023-33394—34.1%
——10——CVE-2025-22799—34.1%
——10——CVE-2009-1144—34.1%
——10——CVE-2011-0710—34.1%
——10——CVE-2026-878763.0 LOW34.1%
——10Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.2dCVE-2001-1530—34.1%
——10——CVE-2024-12299—34.1%
——10——CVE-2010-3357—34.1%
——10——CVE-2025-29152—34.1%
——10——CVE-2017-18347—34.1%
——10——CVE-2026-920369.8 CRI34.1%
——10Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.2dCVE-2024-32983—34.1%
——10——CVE-2026-24052—34.1%
——10——CVE-2019-18996—34.1%
——10——CVE-2020-10768—34.1%
——10——CVE-2017-3745—34.1%
——10——CVE-2022-491388.8 HIG34.1%
——10In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_event: Ignore multiple conn complete events
When one of the three connection complete events is received multiple
times for the same handle, the device is registered multiple times which
leads to memory corruptions. Therefore, consequent events for a single
connection are ignored.
The conn->state can hold different values, therefore HCI_CONN_HANDLE_UNSET
is introduced to identify new connections. To make sure the events do not
contain this or another invalid handle HCI_CONN_HANDLE_MAX and checks
are introduced.
Buglink: https://bugzilla.kernel.org/show_bug.cgi?id=21549750dCVE-2026-123525.9 MED34.1%
——10This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.72dCVE-2025-20620—34.1%
——10——CVE-2026-67477.5 HIG34.1%
——10Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.70dCVE-2019-19166—34.1%
——10——