Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-1836—31.7%
——10——CVE-2025-13881—31.7%
——10——CVE-2026-739309.9 CRI31.7%
——10Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19 and 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).25dCVE-2023-6680—31.7%
——10——CVE-2023-52372—31.7%
——10——CVE-2022-46680—31.7%
——10——CVE-2025-8071—31.7%
——10——CVE-2025-7175—31.7%
——10——CVE-2022-22618—31.7%
——10——CVE-2024-36677—31.7%
——10——CVE-2021-42106—31.7%
——10——CVE-2023-52108—31.7%
——10——CVE-2024-34991—31.7%
——10——CVE-2005-3148—31.7%
——10——CVE-2023-543944.3 MED31.7%
——10PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication.12dCVE-2021-45464—31.7%
——10——CVE-2023-52552—31.7%
——10——CVE-2025-30265—31.7%
——10——CVE-2017-9984—31.7%
——10——CVE-2025-28858—31.7%
——10——CVE-2025-65094—31.7%
——10——CVE-2024-43511—31.7%
——10——CVE-2024-48010—31.7%
——10——CVE-2021-42107—31.7%
——10——CVE-2006-0035—31.7%
——10——CVE-2024-383818.8 HIG31.7%
——10In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: Fix uninit-value in nci_rx_work
syzbot reported the following uninit-value access issue [1]
nci_rx_work() parses received packet from ndev->rx_q. It should be
validated header size, payload size and total packet size before
processing the packet. If an invalid packet is detected, it should be
silently discarded.48dCVE-2025-59206—31.7%
——10——CVE-2019-8755—31.7%
——10——CVE-2026-3980—31.7%
——10——CVE-2025-26560—31.7%
——10——CVE-2024-13575—31.7%
——10——CVE-2013-7135—31.7%
——10——CVE-2023-28490—31.7%
——10——CVE-2024-31291—31.7%
——10——CVE-2026-82756—31.7%
——10Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header.
BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.
This issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.13dCVE-2023-52115—31.7%
——10——CVE-2024-5682—31.7%
——10——CVE-2023-37501—31.7%
——10——CVE-2025-34281—31.7%
——10——CVE-2025-26544—31.7%
——10——