Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37439—32.5%
——10——CVE-2016-5793—32.5%
——10——CVE-2026-826217.3 HIG32.5%
——10A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a manipulation of the argument action can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.21dCVE-2026-147409.1 CRI32.5%
——10DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment.
The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.73dCVE-2025-69305—32.5%
——10——CVE-2009-2743—32.5%
——10——CVE-2025-14386—32.5%
——10——CVE-2024-30950—32.5%
——10——CVE-2026-923564.3 MED32.5%
——10A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.5dCVE-2026-353948.3 HIG32.5%
——10Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and content provider access. This vulnerability is fixed in 0.0.50.59dCVE-2023-27607—32.5%
——10——CVE-2026-188089.8 CRI32.5%
——10Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection.
This issue affects KIO (Klemsan Internet Objects): before v1.9.20dCVE-2025-10765—32.5%
——10——CVE-2026-532688.2 HIG32.5%
——10In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack_irc: fix possible out-of-bounds read
When parsing fails after we've matched the command string we
should bail out instead of trying to match a different command.
This helper should be deprecated, given prevalence of TLS I doubt it has
any relevance in 2026.14dCVE-2024-33272—32.5%
——10——CVE-2009-1673—32.5%
——10——CVE-2026-802039.8 CRI32.5%
——10The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSuperWithinScope()). As a result, an API key scoped below full super authority but belonging to a super-admin account can act against other super-admin accounts—disabling their 2FA, deleting their avatar, minting new API keys under their identity, or deleting their existing API keys.19dCVE-2023-0972—32.5%
——10——CVE-2025-10000—32.5%
——10——CVE-2025-13079—32.5%
——10——CVE-2024-11462—32.5%
——10——CVE-2004-1144—32.5%
——10——CVE-2014-0177—32.5%
——10——CVE-2026-35262—32.5%
——10——CVE-2026-624738.3 HIG32.5%
——10Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as unauthorized access to critical data or complete access to all Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).46dCVE-2015-8993—32.5%
——10——CVE-2010-5332—32.5%
——10——CVE-2025-13683—32.5%
——10——CVE-2011-0999—32.5%
——10——CVE-2023-2030—32.5%
——10——CVE-2025-9609—32.5%
——10——CVE-2026-34692.7 LOW32.5%
——10A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.59dCVE-2023-39500—32.5%
——10——CVE-2024-13504—32.5%
——10——CVE-2024-8718—32.5%
——10——CVE-2022-42372—32.5%
——10——CVE-2021-0063—32.5%
——10——CVE-2024-8800—32.5%
——10——CVE-2017-16646—32.5%
——10——CVE-2005-4552—32.5%
——10——