Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,221
- High7,891
- Medium6,409
- Low710
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-753259.8 CRI27.9%
——8DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.7dCVE-2026-6853—27.9%
——8——CVE-2023-43191—27.9%
——8——CVE-2026-2374—27.9%
——8——CVE-2021-3349—27.9%
——8——CVE-2019-8510—27.9%
——8——CVE-2026-646117.5 HIG27.9%
——8A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.28dCVE-2024-9270—27.9%
——8——CVE-2026-492187.5 HIG27.9%
——8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.55dCVE-2026-34287—27.9%
——8——CVE-2026-46617—27.9%
——8——CVE-2025-41349—27.9%
——8——CVE-2024-44233—27.9%
——8——CVE-2022-312315.9 MED27.9%
——8Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.55dCVE-2023-48926—27.9%
——8——CVE-2026-40890—27.8%
——8——CVE-2026-789706.5 MED27.8%
——8JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization.8dCVE-2026-1197—27.8%
——8——CVE-2026-738966.5 MED27.8%
——8Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).19dCVE-2026-35417—27.8%
——8——CVE-2026-535288.8 HIG27.8%
——8LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local files, such as the application database, to become downloadable as page assets. Users should update to version 0.10.1 or greater. As an additional mitigation, operators should ensure that the LeafWiki process runs with the least privileges necessary and does not have filesystem access to sensitive files outside the application’s required directories. Until a patch is applied, operators may reduce risk by restricting editor access to trusted users only and by limiting the filesystem permissions of the LeafWiki process.7dCVE-2021-29118—27.8%
——8——CVE-2025-23392—27.8%
——8——CVE-2015-5945—27.8%
——8——CVE-2021-29112—27.8%
——8——CVE-2016-3846—27.8%
——8——CVE-2023-5001—27.8%
——8——CVE-2023-45777—27.8%
——8——CVE-2026-34476—27.8%
——8——CVE-2026-875248.3 HIG27.8%
——8Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)6dCVE-2025-31475—27.8%
——8——CVE-2023-25879—27.8%
——8——CVE-2022-36851—27.8%
——8——CVE-2024-12186—27.8%
——8——CVE-2024-8823—27.8%
——8——CVE-2025-50983—27.8%
——8——CVE-2023-25881—27.8%
——8——CVE-2004-0015—27.8%
——8——CVE-1999-1536—27.8%
——8——CVE-2022-36488—27.8%
——8——