Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-3613—31.7%
——10——CVE-2024-2312—31.7%
——10——CVE-2026-8288—31.7%
——10——CVE-2025-29084—31.7%
——10——CVE-2026-35248.8 HIG31.7%
——10Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-0062146dCVE-2025-23680—31.7%
——10——CVE-2025-31085—31.7%
——10——CVE-2021-28952—31.7%
——10——CVE-2017-9961—31.7%
——10——CVE-2025-32580—31.7%
——10——CVE-2019-19582—31.7%
——10——CVE-2023-0620—31.7%
——10——CVE-2005-4881—31.7%
——10——CVE-2013-3227—31.7%
——10——CVE-2025-31086—31.7%
——10——CVE-2008-5395—31.7%
——10——CVE-2026-9587—31.7%
——10An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.66dCVE-2022-48344—31.7%
——10——CVE-2025-26541—31.7%
——10——CVE-2026-12194—31.7%
——10PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.77dCVE-2020-36322—31.7%
——10——CVE-2025-10744—31.7%
——10——CVE-2025-26546—31.7%
——10——CVE-2026-7402—31.7%
——10——CVE-2026-192907.5 HIG31.7%
——10IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.5dCVE-2025-31078—31.7%
——10——CVE-2016-0678—31.7%
——10——CVE-2026-28423—31.7%
——10——CVE-2025-32503—31.7%
——10——CVE-2005-1265—31.7%
——10——CVE-2022-32872—31.7%
——10——CVE-2016-4036—31.7%
——10——CVE-2025-65493—31.7%
——10——CVE-2016-5471—31.7%
——10——CVE-2025-31445—31.7%
——10——CVE-2025-30913—31.7%
——10——CVE-2025-27267—31.7%
——10——CVE-2026-601968.4 HIG31.7%
——10Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).55dCVE-2025-49700—31.7%
——10——CVE-2025-221109.8 CRI31.7%
——10In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error
It is possible that ctx in nfqnl_build_packet_message() could be used
before it is properly initialize, which is only initialized
by nfqnl_get_sk_secctx().
This patch corrects this problem by initializing the lsmctx to a safe
value when it is declared.
This is similar to the commit 35fcac7a7c25
("audit: Initialize lsmctx to avoid memory allocation error").53d