Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-2221—29.1%
——9——CVE-2026-28447—29.1%
——9——CVE-2026-3797—29.1%
——9——CVE-2025-11449—29.1%
——9——CVE-2026-207768.6 HIG29.1%
——9Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.22dCVE-2024-27193—29.1%
——9——CVE-2026-2279—29.0%
——9——CVE-2026-488595.3 MED29.0%
——9Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.
When the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This timing difference is detectable in a single authentication attempt and allows an unauthenticated attacker to distinguish valid from invalid usernames.
The user_passwords and password options are documented as intended for test purposes; the recommended alternative is pwdfun, which is not affected by this vulnerability.
This vulnerability is associated with program files lib/ssh/src/ssh_auth.erl and lib/ssh/src/ssh_options.erl.
This issue affects OTP from OTP 29.0 before OTP 29.0.2, corresponding to ssh from 6.0 before 6.0.1.10dCVE-2025-656727.5 HIG29.0%
——9Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.75dCVE-2026-34942—29.0%
——9——CVE-2014-4357—29.0%
——9——CVE-2025-39515—29.0%
——9——CVE-2025-32495—29.0%
——9——CVE-2025-31817—29.0%
——9——CVE-2025-30813—29.0%
——9——CVE-2026-21965—29.0%
——9——CVE-2014-1604—29.0%
——9——CVE-2002-1871—29.0%
——9——CVE-2024-36556—29.0%
——9——CVE-2025-31741—29.0%
——9——CVE-2026-22341—29.0%
——9——CVE-2026-709598.1 HIG29.0%
——9Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).23dCVE-2025-10439—29.0%
——9——CVE-2025-31844—29.0%
——9——CVE-2025-31745—29.0%
——9——CVE-2026-186477.3 HIG29.0%
——9A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.36dCVE-2026-791397.5 HIG29.0%
——9Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)21dCVE-2025-22390—29.0%
——9——CVE-2020-10290—29.0%
——9——CVE-2025-30836—29.0%
——9——CVE-2025-30551—29.0%
——9——CVE-2025-30826—29.0%
——9——CVE-2009-0874—29.0%
——9——CVE-2025-4738—29.0%
——9——CVE-2018-1505—29.0%
——9——CVE-2025-31733—29.0%
——9——CVE-2025-31805—29.0%
——9——CVE-2019-20532—29.0%
——9——CVE-2025-39543—29.0%
——9——CVE-2025-31737—29.0%
——9——