Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,735
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-138027.5 HIG29.9%
——9Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)78dCVE-2026-506306.5 MED29.9%
——9A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.42dCVE-2023-50913—29.9%
——9——CVE-2015-7403—29.9%
——9——CVE-2016-10102—29.9%
——9——CVE-2026-568306.5 MED29.9%
——9Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.3dCVE-2024-35153—29.9%
——9——CVE-2025-9431—29.9%
——9——CVE-2026-1606—29.9%
——9——CVE-2026-46861—29.9%
——9——CVE-2025-22602—29.9%
——9——CVE-2023-26923—29.9%
——9——CVE-2025-2291—29.9%
——9——CVE-2026-44635—29.9%
——9——CVE-2025-28233—29.9%
——9——CVE-2023-26084—29.9%
——9——CVE-2024-8388—29.9%
——9——CVE-2024-34099—29.9%
——9——CVE-2026-872388.8 HIG29.9%
——9Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).2dCVE-2026-46721—29.9%
——9——CVE-2026-168708.8 HIG29.9%
——9Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests — including credentials and tokens — to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. The Snowflake PHP PDO Driver and Snowflake ODBC Driver embed the affected library; fixes are available in versions 4.1.0 and 3.19.0 respectively. Users must manually upgrade.50dCVE-2025-0696—29.9%
——9——CVE-2026-144267.5 HIG29.9%
——9Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)77dCVE-2025-12963—29.9%
——9——CVE-2024-57488—29.9%
——9——CVE-2025-0695—29.9%
——9——CVE-2026-685588.5 HIG29.9%
——9Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line check. The delivery path's fetchSafe guard already blocked the reported IPv4 destination, but its separate IPv4-only resolver and duplicated blocklist created inconsistent all-address-family enforcement and drift risk between input-time and connection-time validation. Version 9.74 makes server/lib/ssrfGuard.js resolve all addresses with `dns.lookup({ all: true })`, validate every result through the shared isIpBlocked logic, pin the connection, and block redirects. This issue is fixed in version 9.74.9dCVE-2024-5997—29.9%
——9——CVE-2024-6494—29.9%
——9——CVE-2024-2753—29.9%
——9——CVE-2026-25509—29.9%
——9——CVE-2025-54066—29.9%
——9——CVE-2019-3717—29.9%
——9——CVE-2025-53895—29.9%
——9——CVE-2026-44500—29.9%
——9——CVE-2021-0600—29.9%
——9——CVE-2024-38471—29.9%
——9——CVE-2024-49551—29.9%
——9——CVE-2005-3070—29.9%
——9——CVE-2023-48087—29.9%
——9——