Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-0802—33.6%
——10——CVE-2026-42272—33.6%
——10——CVE-2020-2731—33.6%
——10——CVE-2025-10617—33.6%
——10——CVE-2024-33857—33.6%
——10——CVE-2026-165605.3 MED33.6%
——10A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.62dCVE-2026-2114—33.6%
——10——CVE-2026-44439—33.6%
——10——CVE-2026-2088—33.6%
——10——CVE-2026-470494.9 MED33.6%
——10Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).57dCVE-2026-62861—33.6%
——10TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes a caller against a client-supplied workspaceId but sends the client-supplied domain name to the shared Vercel project before verifying that the domain belongs to that workspace. This issue is fixed in version 3.18.0.26dCVE-2024-37767—33.6%
——10——CVE-2024-37269—33.6%
——10——CVE-2024-47923—33.6%
——10——CVE-2026-91128.8 HIG33.6%
——10Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)64dCVE-2026-91268.8 HIG33.6%
——10Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)61dCVE-2025-49546—33.6%
——10——CVE-2023-32505—33.6%
——10——CVE-2023-32515—33.6%
——10——CVE-2026-1884—33.6%
——10——CVE-2024-36832—33.6%
——10——CVE-2026-81732—33.6%
——10WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.24dCVE-2024-44906—33.6%
——10——CVE-2024-6675—33.6%
——10——CVE-2026-199653.7 LOW33.6%
——10A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response discrepancy. The attack can be initiated remotely. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.0.0-beta.33 is able to resolve this issue. Patch name: eac0b05dafdb0ddf8b9139dad8929aaba86568ca. You should upgrade the affected component.33dCVE-2023-37874—33.6%
——10——CVE-2026-2196—33.6%
——10——CVE-2026-680799.8 CRI33.6%
——10In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.47dCVE-2024-6233—33.6%
——10——CVE-2025-63372—33.6%
——10——CVE-2026-28818—33.6%
——10——CVE-2022-26476—33.6%
——10——CVE-2024-5704—33.6%
——10——CVE-2022-36111—33.6%
——10——CVE-2025-20179—33.6%
——10——CVE-2026-28519—33.6%
——10——CVE-2026-159557.5 HIG33.6%
——10IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.6dCVE-2024-55411—33.6%
——10——CVE-2025-8336—33.6%
——10——CVE-2022-38390—33.6%
——10——