Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,410
- Medium6,691
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-42960—31.5%
——9——CVE-2025-0402—31.5%
——9——CVE-2024-38827—31.5%
——9——CVE-2024-48985—31.5%
——9——CVE-2026-706807.1 HIG31.5%
——9Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Applications DBA. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).21dCVE-2024-40726—31.5%
——9——CVE-2025-27685—31.5%
——9——CVE-2023-1209—31.5%
——9——CVE-2023-27651—31.5%
——9——CVE-2026-159187.5 HIG31.5%
——9VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required39dCVE-2022-44002—31.5%
——9——CVE-2024-10185—31.5%
——9——CVE-2021-34358—31.5%
——9——CVE-2008-1593—31.5%
——9——CVE-2020-3601—31.5%
——9——CVE-2025-43720—31.5%
——9——CVE-2026-257268.1 HIG31.5%
——9Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. These secrets are generated upon first startup and persisted in the database. An attacker can exploit this by obtaining the administrator's account creation time (via public API endpoints) to narrow the search window for the PRNG seed, and use known hashid to validate the seed. By brute-forcing the seed (demonstrated to take <3 hours on general consumer PC), an attacker can predict the secret_key. This allows them to forge valid JSON Web Tokens (JWTs) for any user, including administrators, leading to full account takeover and privilege escalation. This issue has been patched in version 4.13.0.58dCVE-2026-328477.5 HIG31.5%
——9DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to traverse outside FRONTEND_DIST and exposing sensitive files such as SSH private keys, TLS certificates, and application secrets with a single HTTP request.69dCVE-2024-23773—31.5%
——9——CVE-2019-12621—31.5%
——9——CVE-2023-44317—31.5%
——9——CVE-2021-0243—31.5%
——9——CVE-2024-5271—31.5%
——9——CVE-2023-22936—31.5%
——9——CVE-2025-69380—31.5%
——9——CVE-2025-23041—31.5%
——9——CVE-2026-748869.8 CRI31.5%
——9openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.20dCVE-2021-26273—31.5%
——9——CVE-2024-13134—31.5%
——9——CVE-2024-12132—31.5%
——9——CVE-2026-737518.8 HIG31.5%
——9An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.6dCVE-2007-3532—31.5%
——9——CVE-2026-30783—31.5%
——9——CVE-2019-18216—31.5%
——9——CVE-2025-37178—31.5%
——9——CVE-2012-3205—31.5%
——9——CVE-2026-845987.5 HIG31.5%
——9A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. An attacker with physical access to a trust-paired device may be able to read and write arbitrary files.5dCVE-2013-1820—31.5%
——9——CVE-2026-183298.2 HIG31.5%
——9Description
NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, allowing the request to proceed instead of being denied, resulting in an authentication or authorization bypass and unauthorized access to protected resources.
Impact
This vulnerability may allow remote attackers to bypass js_access controls. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.18dCVE-2026-194997.7 HIG31.5%
——9Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.
Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.
At the time of publication, no network-facing application impact is known.3d