Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,511
- Medium6,637
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-2848—30.6%
——9——CVE-2023-28529—30.6%
——9——CVE-2025-62426—30.6%
——9——CVE-2024-46475—30.6%
——9——CVE-2022-36796—30.6%
——9——CVE-2017-10997—30.6%
——9——CVE-2024-46916—30.6%
——9——CVE-2022-28697—30.6%
——9——CVE-2026-23689—30.6%
——9——CVE-2020-24307—30.6%
——9——CVE-2024-13669—30.6%
——9——CVE-2024-11369—30.6%
——9——CVE-2016-7439—30.6%
——9——CVE-2024-56009—30.6%
——9——CVE-2025-24358—30.6%
——9——CVE-2023-47877—30.6%
——9——CVE-2024-4354—30.6%
——9——CVE-2018-5497—30.6%
——9——CVE-2023-50371—30.6%
——9——CVE-2024-9223—30.6%
——9——CVE-2026-830887.7 HIG30.6%
——9Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).2dCVE-2026-97506.5 MED30.6%
——9An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.57dCVE-2026-530029.8 CRI30.6%
——9In the Linux kernel, the following vulnerability has been resolved:
netfilter: conntrack: remove sprintf usage
Replace it with scnprintf, the buffer sizes are expected to be large enough
to hold the result, no need for snprintf+overflow check.
Increase buffer size in mangle_content_len() while at it.
BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270
Write of size 1 at addr [..]
vsnprintf+0xea5/0x1270
sprintf+0xb1/0xe0
mangle_content_len+0x1ac/0x280
nf_nat_sdp_session+0x1cc/0x240
process_sdp+0x8f8/0xb80
process_invite_request+0x108/0x2b0
process_sip_msg+0x5da/0xf50
sip_help_tcp+0x45e/0x780
nf_confirm+0x34d/0x990
[..]8dCVE-2026-919686.5 MED30.6%
——9vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.2dCVE-2017-11002—30.6%
——9——CVE-2013-2128—30.6%
——9——CVE-2025-2238—30.6%
——9——CVE-2025-26911—30.6%
——9——CVE-2007-1876—30.6%
——9——CVE-2026-27689—30.6%
——9——CVE-2025-62066—30.6%
——9——CVE-2024-23635—30.6%
——9——CVE-2025-69216—30.6%
——9——CVE-2017-11040—30.6%
——9——CVE-2021-45486—30.6%
——9——CVE-2026-54514—30.6%
——9——CVE-2016-1339—30.6%
——9——CVE-2019-1725—30.6%
——9——CVE-2023-40684—30.6%
——9——CVE-2024-10182—30.6%
——9——