Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,708
- Medium6,690
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22553—28.3%
——9——CVE-2026-27138—28.3%
——9——CVE-2026-593116.8 MED28.3%
——9A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.1216dCVE-2026-1944—28.3%
——9——CVE-2025-66174—28.3%
——9——CVE-2023-44112—28.3%
——9——CVE-2025-54070—28.3%
——9——CVE-2023-52716—28.3%
——9——CVE-2024-57426—28.3%
——9——CVE-2026-34455—28.3%
——9——CVE-2023-52715—28.3%
——9——CVE-2026-851469.8 CRI28.3%
——9SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.8dCVE-2025-55109—28.3%
——9——CVE-2024-3474—28.3%
——9——CVE-2025-2816—28.3%
——9——CVE-2024-11410—28.3%
——9——CVE-2025-58736—28.3%
——9——CVE-2024-54241—28.3%
——9——CVE-2024-1638—28.3%
——9——CVE-2016-3992—28.3%
——9——CVE-2005-2750—28.3%
——9——CVE-2026-728717.5 HIG28.3%
——9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the state parameter and calls createGithub in packages/server/src/services/github.ts, allowing an attacker to insert a GitHub App provider containing client_secret, webhook_secret, and PEM private key material into another organization. This issue is fixed in version 0.29.13.8dCVE-2026-762538.8 HIG28.3%
——9In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/create-alerts/create-scheduled-alerts), Set up alert actions (https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.3/configure-alert-actions/set-up-alert-actions), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Configuration file precedence (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/administer-splunk-enterprise-with-configuration-files/configuration-file-precedence) in the Splunk documentation.20dCVE-2026-749889.8 CRI28.3%
——9Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.15dCVE-2026-33711—28.3%
——9——CVE-2026-42843—28.3%
——9——CVE-2025-64349—28.3%
——9——CVE-2025-63604—28.3%
——9——CVE-2023-5197—28.3%
——9——CVE-2020-9226—28.3%
——8——CVE-2023-52344—28.3%
——8——CVE-2008-3928—28.3%
——8——CVE-2023-45766—28.3%
——8——CVE-2026-3709—28.3%
——8——CVE-2025-10566—28.3%
——8——CVE-2026-212974.3 MED28.3%
——8Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.20dCVE-2024-4417—28.3%
——8——CVE-2025-22319—28.3%
——8——CVE-2025-5688—28.3%
——8——CVE-2026-1725—28.3%
——8——