Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,292
- Medium6,568
- Low706
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-737217.2 HIG30.3%
——9Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.16dCVE-2025-22639—30.3%
——9——CVE-2026-5737—30.3%
——9——CVE-2025-26416—30.3%
——9——CVE-2024-45659—30.3%
——9——CVE-2023-41655—30.3%
——9——CVE-2003-0846—30.3%
——9——CVE-2024-53826—30.3%
——9——CVE-2002-1722—30.3%
——9——CVE-2025-7693—30.3%
——9——CVE-2024-34815—30.3%
——9——CVE-2025-0081—30.3%
——9——CVE-2026-558147.5 HIG30.3%
——9Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.32dCVE-2022-34834—30.3%
——9——CVE-2021-28709—30.3%
——9——CVE-2026-608318.1 HIG30.3%
——9Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).28dCVE-2026-23977—30.3%
——9——CVE-2022-45841—30.3%
——9——CVE-2025-40657—30.3%
——9——CVE-2026-613078.1 HIG30.3%
——9Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Common Application Objects). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CC Common Application Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).14dCVE-2026-32256—30.3%
——9——CVE-2023-41734—30.3%
——9——CVE-2017-12580—30.3%
——9——CVE-2017-4938—30.3%
——9——CVE-2024-12159—30.3%
——9——CVE-2026-711128.1 HIG30.3%
——9Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).14dCVE-2026-684319.1 CRI30.3%
——9In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate minimum PDU size for transform requests
The receive path applies the minimum SMB2 PDU size check only when
ProtocolId is SMB2_PROTO_NUMBER. A packet carrying
SMB2_TRANSFORM_PROTO_NUM bypasses the check even when the negotiated
dialect does not provide transform handling.
On an SMB 2.1 connection, a short transform packet therefore reaches
init_smb2_rsp_hdr(), which interprets the request as a full SMB2 header
and reads beyond the request allocation. The copied fields can then be
returned to the unauthenticated client.
Compression transforms are converted to ordinary SMB2 messages before
protocol validation. After that conversion, validate ordinary SMB2
requests against SMB2_MIN_SUPPORTED_PDU_SIZE and require encryption
transform requests to contain both a transform header and an SMB2
header. This rejects truncated requests before work allocation.26dCVE-2022-38409—30.3%
——9——CVE-2025-32390—30.3%
——9——CVE-2026-664417.5 HIG30.3%
——9Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.35dCVE-2019-11486—30.3%
——9——CVE-2026-31611—30.3%
——9——CVE-2022-42406—30.3%
——9——CVE-2026-34164—30.3%
——9——CVE-2024-2299—30.3%
——9——CVE-2022-38410—30.3%
——9——CVE-2023-52209—30.3%
——9——CVE-2024-0858—30.3%
——9——CVE-2016-8656—30.3%
——9——CVE-2025-30802—30.3%
——9——