Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-50092—31.9%
——10——CVE-2024-43370—31.9%
——10——CVE-2014-8172—31.9%
——10——CVE-2025-3875—31.9%
——10——CVE-2026-922157.3 HIG31.9%
——10A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The identifier of the patch is 2bb8423060308bbdea8ba468dabed4fc256d18ea. To fix this issue, it is recommended to deploy a patch.5dCVE-2024-12799—31.9%
——10——CVE-2025-43224—31.9%
——10——CVE-2025-109393.7 LOW31.9%
——10A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.22dCVE-2023-6564—31.9%
——10——CVE-2024-30176—31.9%
——10——CVE-2026-872257.1 HIG31.9%
——10Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).3dCVE-2024-140426.3 MED31.9%
——10A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S6a Interface. Performing a manipulation of the argument os.len results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 2.7.2 is able to mitigate this issue. The patch is named e89aa79efe629ae90f59dcdf8847c117d9a7da86. It is suggested to upgrade the affected component.40dCVE-2025-46580—31.9%
——10——CVE-2017-0532—31.9%
——10——CVE-2024-9881—31.9%
——10——CVE-2026-1664—31.9%
——10——CVE-2026-153066.1 MED31.9%
——10The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.67dCVE-2022-25657—31.9%
——10——CVE-2025-54079—31.9%
——10——CVE-2023-3434—31.9%
——10——CVE-2020-16202—31.9%
——10——CVE-2024-45413—31.9%
——10——CVE-2023-23145—31.9%
——10——CVE-2024-37662—31.9%
——10——CVE-2026-29182—31.9%
——10——CVE-2024-23211—31.9%
——10——CVE-2022-36042—31.9%
——10——CVE-2022-29090—31.9%
——10——CVE-2024-6044—31.9%
——10——CVE-2024-348977.5 HIG31.9%
——10Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.79dCVE-2025-25942—31.9%
——10——CVE-2024-47565—31.9%
——10——CVE-2025-23696—31.9%
——10——CVE-2025-62166—31.9%
——10——CVE-2020-8632—31.9%
——10——CVE-2023-35992—31.9%
——10——CVE-2026-533967.1 HIG31.9%
——10In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
nfsd4_create_file() has two bugs in its ACL handling:
The return value of nfsd4_acl_to_attr() is silently discarded. When
the NFSv4-to-POSIX ACL conversion fails (e.g., -EINVAL for
unsupported ACE types), the file is created without any ACL and the
client receives NFS4_OK. This violates RFC 7530/8881 which require
the server to reject unsupported attributes on CREATE.
When start_creating() fails after ACL attributes have been populated
in attrs (either via nfsd4_acl_to_attr or via ownership transfer from
open->op_dpacl/op_pacl), the function jumps to out_write which skips
nfsd_attrs_free(). The posix_acl allocations are leaked. A client
can trigger this repeatedly with OPEN(CREATE), ACL attributes, and an
invalid filename (e.g., longer than NAME_MAX).
Fix both by capturing the nfsd4_acl_to_attr() return value and by
changing the early error paths to jump to out instead of out_write.
Initialize child to ERR_PTR(-EINVAL) so that end_creating() is safe
to call even if start_creating() was never reached.35dCVE-2025-14989—31.8%
——10——CVE-2023-26147—31.8%
——10——CVE-2024-55226—31.8%
——10——