Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,510
- Medium6,635
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8741—30.6%
——9——CVE-2019-25582—30.6%
——9——CVE-2026-43888—30.6%
——9——CVE-2025-63685—30.6%
——9——CVE-2015-7024—30.6%
——9——CVE-2013-6200—30.6%
——9——CVE-2025-65821—30.6%
——9——CVE-2024-55232—30.6%
——9——CVE-2025-219678.8 HIG30.6%
——9In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix use-after-free in ksmbd_free_work_struct
->interim_entry of ksmbd_work could be deleted after oplock is freed.
We don't need to manage it with linked list. The interim request could be
immediately sent whenever a oplock break wait is needed.51dCVE-2017-11001—30.6%
——9——CVE-2026-704697.5 HIG30.6%
——9Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not check multiple instances of the Content-Encoding header and did not reject non-standard identifiers for gzip encoding, allowing a malicious client to send crafted requests that could consume excessive amounts of memory. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which disables decompression of gzip-encoded HTTP requests regardless of header number or encoding identifiers.1dCVE-2025-32665—30.6%
——9——CVE-2024-352657.0 HIG30.6%
——9Windows Perception Service Elevation of Privilege Vulnerability60dCVE-2026-7669—30.6%
——9——CVE-2023-47786—30.6%
——9——CVE-2024-44920—30.6%
——9——CVE-2025-14284—30.6%
——9——CVE-2026-3793—30.6%
——9——CVE-2025-10711—30.6%
——9——CVE-2026-64961—30.6%
——9ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain uninitialized in certain code paths. An unauthenticated attacker who can determine a user's identifier and registration timestamp can generate a valid token and authenticate as an existing user, including administrator, without knowing the password.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.21dCVE-2026-42274—30.6%
——9——CVE-2024-5379—30.6%
——9——CVE-2022-25213—30.6%
——9——CVE-2024-34404—30.6%
——9——CVE-2024-22278—30.6%
——9——CVE-2024-5313—30.6%
——9——CVE-2024-37177—30.6%
——9——CVE-2024-34346—30.6%
——9——CVE-2023-6028—30.6%
——9——CVE-2025-32636—30.6%
——9——CVE-2026-181064.3 MED30.6%
——9IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.32dCVE-1999-0171—30.6%
——9——CVE-2022-22999—30.6%
——9——CVE-2021-20730—30.6%
——9——CVE-2022-40284—30.6%
——9——CVE-2026-626368.6 HIG30.6%
——9Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Reports Developer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Reports Developer accessible data as well as unauthorized update, insert or delete access to some of Oracle Reports Developer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Reports Developer. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).29dCVE-2026-3868—30.6%
——9——CVE-2026-22473—30.6%
——9——CVE-2024-34121—30.6%
——9——CVE-2026-398726.5 MED30.6%
——9The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.32d