Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15351—32.5%
——10——CVE-2026-812707.5 HIG32.5%
——10Apache Allura: exposure of non-public information via search.
This issue affects Apache Allura: through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.13dCVE-2024-49399—32.5%
——10——CVE-2025-69227—32.5%
——10——CVE-2019-15348—32.5%
——10——CVE-2025-59221—32.5%
——10——CVE-2026-693445.5 MED32.5%
——10Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.4dCVE-2024-8189—32.5%
——10——CVE-2024-57189—32.5%
——10——CVE-2026-33755—32.5%
——10——CVE-2023-2837—32.5%
——10——CVE-2026-692865.5 MED32.5%
——10Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.5dCVE-2023-25896—32.5%
——10——CVE-2024-44019—32.5%
——10——CVE-2023-46378—32.5%
——10——CVE-2020-4497—32.5%
——10——CVE-2026-818295.3 MED32.5%
——10A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.6hCVE-2026-695275.5 MED32.5%
——10Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.5dCVE-2026-43296—32.5%
——10——CVE-2026-193038.1 HIG32.5%
——10IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.11dCVE-2026-100755.3 MED32.5%
——10DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.62dCVE-2022-3233—32.5%
——10——CVE-2025-1830—32.5%
——10——CVE-2025-30475—32.5%
——10——CVE-2024-50423—32.5%
——10——CVE-2023-20180—32.5%
——10——CVE-2023-45140—32.5%
——10——CVE-2026-203269.8 CRI32.5%
——10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20326 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.3dCVE-2024-9697—32.5%
——10——CVE-2018-21081—32.5%
——10——CVE-2023-0674—32.5%
——10——CVE-2026-150439.8 CRI32.5%
——10DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.
DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.
SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.
The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.69dCVE-2024-11893—32.5%
——10——CVE-2024-43143—32.5%
——10——CVE-2025-6552—32.5%
——10——CVE-2023-7332—32.5%
——10PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service.69dCVE-2023-47836—32.5%
——10——CVE-2018-25294—32.5%
——10——CVE-2025-13881—32.5%
——10——CVE-2026-171707.5 HIG32.5%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size.27d