Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-168877.5 HIG32.5%
——10IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.35dCVE-2023-43857—32.5%
——10——CVE-2026-27053—32.5%
——10——CVE-2017-1093—32.5%
——10——CVE-2026-789676.5 MED32.5%
——10Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2024-6621—32.5%
——10——CVE-2023-31459—32.5%
——10——CVE-2024-9218—32.5%
——10——CVE-2025-29313—32.5%
——10——CVE-2024-8741—32.5%
——10——CVE-2024-9222—32.5%
——10——CVE-2025-1718—32.5%
——10——CVE-2015-4053—32.5%
——10——CVE-2026-172717.5 HIG32.5%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.35dCVE-2026-665839.8 CRI32.5%
——10Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.32dCVE-2024-34804—32.5%
——10——CVE-2024-9060—32.5%
——10——CVE-2024-9210—32.5%
——10——CVE-2024-41903—32.5%
——10——CVE-2026-547559.6 CRI32.5%
——10Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.21dCVE-2024-9435—32.5%
——10——CVE-2024-5613—32.5%
——10——CVE-2026-803467.1 HIG32.5%
——10StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating the check happens in execution logic. That holds only for asynchronous materialized views: LocalMetastore.dropMaterializedView calls Authorizer.checkMaterializedViewAction inside a branch taken when the resolved table is a MaterializedView. A legacy synchronous materialized view is stored as a rollup index on an OlapTable rather than a MaterializedView, so the other branch runs, reaching AlterJobMgr.processDropMaterializedView and MaterializedViewHandler, neither of which contains any Authorizer call. The former locates the target by scanning every OlapTable in the named database for a matching rollup index, and the latter validates only table state and name conflicts. Any authenticated account can therefore drop a legacy synchronous materialized view belonging to any database, holding no grant on the view, the base table or the database, and the drop is indistinguishable from an authorized one.24dCVE-2022-41144—32.5%
——10——CVE-2025-1908—32.5%
——10——CVE-2022-2995—32.5%
——10——CVE-2022-41143—32.5%
——10——CVE-2025-92366.3 MED32.5%
——10A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 2.12 mitigates this issue. Upgrading the affected component is advised. The vendor confirms: "The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced."6dCVE-2026-46400—32.5%
——10HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in HAXCMS PHP only validates file extensions using a regex pattern without checking the actual file content or MIME type. This allows attackers to upload malicious files (e.g., PHP webshells) disguised as legitimate image files, potentially leading to remote code execution. Version 25.0.0 contains a fix for the issue.61dCVE-2026-507218.1 HIG32.5%
——10Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of remote IKE peers are not affected.74dCVE-2002-0761—32.5%
——10——CVE-2026-739939.8 CRI32.5%
——10Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.32dCVE-2026-785435.3 MED32.5%
——10IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop.12dCVE-2012-5640—32.5%
——10——CVE-2009-5066—32.5%
——10——CVE-2025-69111—32.5%
——10——CVE-2024-11820—32.5%
——10——CVE-2023-26544—32.5%
——10——CVE-2023-45150—32.5%
——10——CVE-2017-16646—32.5%
——10——