Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,734
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-768654.9 MED29.9%
——9Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An attacker can trigger the flaw by supplying crafted input to these handlers, causing a denial of service.2dCVE-2024-52902—29.9%
——9——CVE-2026-340316.5 MED29.9%
——9Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.57dCVE-2024-12560—29.9%
——9——CVE-2026-763129.4 CRI29.9%
——9In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/additional-configuration-for-embedded-reports) and Embed scheduled reports (https://help.splunk.com/en/splunk-enterprise/create-dashboards-and-reports/reporting-manual/10.4/report-management/embed-scheduled-reports) in the Splunk documentation.22dCVE-2023-7234—29.9%
——9——CVE-2026-325599.9 CRI29.9%
——9Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.22dCVE-2026-46721—29.9%
——9——CVE-2025-49124—29.9%
——9——CVE-2023-37360—29.9%
——9——CVE-2024-11154—29.9%
——9——CVE-2024-12584—29.9%
——9——CVE-2024-21035—29.9%
——9——CVE-2025-66862—29.9%
——9——CVE-2017-1086—29.9%
——9——CVE-2025-0918—29.9%
——9——CVE-2026-454885.4 MED29.9%
——9User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.73dCVE-2026-608488.1 HIG29.9%
——9Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Contracts accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).49dCVE-2024-12239—29.9%
——9——CVE-2016-1418—29.9%
——9——CVE-2022-22160—29.9%
——9——CVE-2020-8026—29.9%
——9——CVE-2024-46055—29.9%
——9——CVE-2025-28233—29.9%
——9——CVE-2024-8388—29.9%
——9——CVE-2026-568427.5 HIG29.9%
——9A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.74dCVE-2026-182857.8 HIG29.9%
——9Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the load_rehab_pile_dataset method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28749.17dCVE-2022-4400—29.9%
——9——CVE-2006-0353—29.9%
——9——CVE-2019-20613—29.9%
——9——CVE-2023-22931—29.9%
——9——CVE-2010-2956—29.9%
——9——CVE-2001-0178—29.9%
——9——CVE-2016-8669—29.9%
——9——CVE-2022-27861—29.9%
——9——CVE-2024-49551—29.9%
——9——CVE-2005-3070—29.9%
——9——CVE-2024-38471—29.9%
——9——CVE-2008-3855—29.9%
——9——CVE-2021-0600—29.9%
——9——