Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-602334.3 MED30.8%
——9Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).54dCVE-2023-28496—30.8%
——9——CVE-2023-33329—30.8%
——9——CVE-2026-128948.8 HIG30.8%
——9A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands.8dCVE-2023-29438—30.8%
——9——CVE-2026-764284.9 MED30.8%
——9A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database.
This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the session database. To exploit this vulnerability, the attacker must have valid administrative credentials.1dCVE-2023-28934—30.8%
——9——CVE-2025-14925—30.8%
——9——CVE-2023-33328—30.8%
——9——CVE-2022-47437—30.8%
——9——CVE-2023-24005—30.8%
——9——CVE-2026-580245.7 MED30.8%
——9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Api/ApiUserrights.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.72dCVE-2023-29170—30.8%
——9——CVE-2023-38482—30.8%
——9——CVE-2005-0070—30.8%
——9——CVE-2024-3368—30.8%
——9——CVE-2023-25977—30.8%
——9——CVE-2022-45827—30.8%
——9——CVE-2023-36530—30.8%
——9——CVE-2024-24099—30.7%
——9——CVE-2021-45604—30.7%
——9——CVE-2016-3908—30.7%
——9——CVE-2007-6063—30.7%
——9——CVE-2023-37983—30.7%
——9——CVE-2026-41263—30.7%
——9——CVE-2026-348297.5 HIG30.7%
——9Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-Length header, such as with HTTP chunked transfer encoding, multipart parsing continues until end-of-stream with no total size limit. For file parts, the uploaded body is written directly to a temporary file on disk rather than being constrained by the buffered in-memory upload limit. An unauthenticated attacker can therefore stream an arbitrarily large multipart file upload and consume unbounded disk space. This results in a denial of service condition for Rack applications that accept multipart form data. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.57dCVE-2025-12934—30.7%
——9——CVE-2024-53621—30.7%
——9——CVE-2024-8832—30.7%
——9——CVE-2025-13619—30.7%
——9——CVE-2026-927838.1 HIG30.7%
——9Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.3dCVE-2023-25483—30.7%
——9——CVE-2026-597047.1 HIG30.7%
——9Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent.71dCVE-2022-0852—30.7%
——9——CVE-2007-0406—30.7%
——9——CVE-2018-10601—30.7%
——9——CVE-2024-31288—30.7%
——9——CVE-2018-1000142—30.7%
——9——CVE-2021-0942—30.7%
——9——CVE-2014-1320—30.7%
——9——