Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-54305—31.3%
——9——CVE-2024-9451—31.3%
——9——CVE-2008-0890—31.3%
——9——CVE-2008-5985—31.3%
——9——CVE-2025-45474—31.3%
——9——CVE-2026-12305—31.3%
——9——CVE-2024-13217—31.3%
——9——CVE-2025-57266—31.3%
——9——CVE-2023-24047—31.3%
——9——CVE-2026-540777.1 HIG31.3%
——9ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command or /api/v1/query can supply HTTP or HTTPS destinations to make server-side requests to internal services, or file:// paths to read files accessible to the server process and ingest the results as queryable records. The XML importer also permits DTD processing and external entities, enabling entity expansion. The root-only /api/v1/server administration endpoint is not affected. The fix requires updateSecurity permission, blocks local-network import destinations by default through arcadedb.server.security.importBlockLocalNetworks, supports the arcadedb.server.security.importAllowedLocalPaths file allow-list, and disables XML DTD processing and external entities. This issue is fixed in version 26.6.1.6dCVE-2023-297247.8 HIG31.3%
——9The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.74dCVE-2013-4326—31.3%
——9——CVE-2023-40329—31.3%
——9——CVE-2013-2047—31.3%
——9——CVE-2026-851074.3 MED31.3%
——9A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. copyImageFromUrl() entry point no longer reachable on current main. That function did exist at v2026.8.3 but was removed by v2026.8.19. The modern copy-image path is Electron-native event.sender.copyImageAt().18dCVE-1999-0141—31.3%
——9——CVE-2024-33997—31.3%
——9——CVE-2025-67791—31.3%
——9——CVE-2025-41362—31.3%
——9——CVE-2024-5851—31.3%
——9——CVE-2025-14600—31.3%
——9An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.20dCVE-2021-4260—31.3%
——9——CVE-2026-592839.1 CRI31.3%
——9Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier20dCVE-2017-1000111—31.3%
——9——CVE-2022-35277—31.3%
——9——CVE-2025-59713—31.3%
——9——CVE-2025-32596—31.3%
——9——CVE-2015-7362—31.3%
——9——CVE-2023-6541—31.3%
——9——CVE-2023-1450—31.3%
——9——CVE-2024-57256—31.3%
——9——CVE-2023-39922—31.3%
——9——CVE-2025-54865—31.3%
——9——CVE-2024-25573—31.3%
——9——CVE-2023-40328—31.3%
——9——CVE-2003-0998—31.3%
——9——CVE-2023-38544—31.3%
——9——CVE-2019-19581—31.3%
——9——CVE-2024-5523—31.3%
——9——CVE-2024-36036—31.3%
——9——