Vulnerabilities exploitable today
378,309in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,340
- High8,555
- Medium6,824
- Low769
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-32759—31.6%
——9——CVE-2026-189528.1 HIG31.6%
——9Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.32dCVE-2026-289478.8 HIG31.6%
——9A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.35dCVE-2015-4922—31.6%
——9——CVE-2022-44646—31.6%
——9——CVE-2025-6900—31.6%
——9——CVE-2023-36126—31.6%
——9——CVE-2017-18385—31.6%
——9——CVE-2022-29852—31.6%
——9——CVE-2020-28416—31.6%
——9——CVE-2024-52995—31.6%
——9——CVE-2023-2444—31.6%
——9——CVE-2019-0122—31.6%
——9——CVE-2005-1265—31.6%
——9——CVE-2025-65493—31.6%
——9——CVE-2022-32872—31.6%
——9——CVE-2019-25058—31.6%
——9——CVE-2023-25609—31.6%
——9——CVE-2006-2147—31.6%
——9——CVE-2002-2384—31.6%
——9——CVE-2013-3235—31.6%
——9——CVE-2018-20927—31.6%
——9——CVE-2019-19059—31.6%
——9——CVE-2026-2693—31.6%
——9——CVE-2026-21889—31.6%
——9——CVE-2018-20509—31.6%
——9——CVE-2018-19608—31.6%
——9——CVE-2015-8328—31.6%
——9——CVE-2017-18384—31.6%
——9——CVE-2026-21219—31.6%
——9——CVE-2026-31467—31.6%
——9——CVE-2025-29998—31.6%
——9——CVE-2024-52996—31.6%
——9——CVE-2026-8326—31.6%
——9Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Depending on implementation, the vulnerability can be exploited by an unauthenticated attacker.
This issue affects SparkView: before build 1127.63dCVE-2023-46447—31.6%
——9——CVE-2023-23693—31.6%
——9——CVE-2025-47682—31.6%
——9——CVE-2026-603167.2 HIG31.5%
——9Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).56dCVE-2026-347847.5 HIG31.5%
——9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS adapter). This allows access to files that should be protected by afterFind trigger authorization logic or built-in validators such as requireUser. This issue has been patched in versions 8.6.71 and 9.7.1-alpha.1.60dCVE-1999-0190—31.5%
——9——