Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-5471—31.7%
——10——CVE-2022-2503—31.7%
——10——CVE-2023-3577—31.7%
——10——CVE-2019-11095—31.7%
——10——CVE-2022-29853—31.7%
——10——CVE-2025-28865—31.7%
——10——CVE-2025-0342—31.7%
——10——CVE-2025-6837—31.7%
——10——CVE-2026-8326—31.7%
——10Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.
This issue affects SparkView: before build 1127.62dCVE-2026-86578.2 HIG31.7%
——10Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of Object.prototype.78dCVE-2026-31613—31.7%
——10——CVE-2026-289478.8 HIG31.7%
——10A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.35dCVE-2024-48902—31.7%
——10——CVE-2015-4922—31.7%
——10——CVE-2024-52996—31.7%
——10——CVE-2026-609059.6 CRI31.7%
——10Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L).25dCVE-2026-21889—31.7%
——10——CVE-2025-49705—31.7%
——10——CVE-2025-23728—31.7%
——10——CVE-2026-44600—31.7%
——10——CVE-2020-3204—31.7%
——10——CVE-2023-27362—31.7%
——10——CVE-2025-31080—31.7%
——10——CVE-2026-0209—31.7%
——10——CVE-2025-30906—31.7%
——10——CVE-2025-28855—31.7%
——10——CVE-2018-20052—31.7%
——10——CVE-2026-0207—31.7%
——10——CVE-2026-601968.4 HIG31.7%
——10Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).55dCVE-2025-27267—31.7%
——10——CVE-2025-221109.8 CRI31.7%
——10In the Linux kernel, the following vulnerability has been resolved:
netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error
It is possible that ctx in nfqnl_build_packet_message() could be used
before it is properly initialize, which is only initialized
by nfqnl_get_sk_secctx().
This patch corrects this problem by initializing the lsmctx to a safe
value when it is declared.
This is similar to the commit 35fcac7a7c25
("audit: Initialize lsmctx to avoid memory allocation error").53dCVE-2025-31462—31.7%
——10——CVE-2025-31455—31.7%
——10——CVE-2024-4562—31.7%
——10——CVE-2025-23735—31.7%
——10——CVE-2025-30905—31.7%
——10——CVE-2026-48725—31.7%
——10——CVE-2025-23964—31.7%
——10——CVE-2026-8291—31.7%
——10——CVE-2025-49700—31.7%
——10——