Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-805887.5 HIG27.0%
——8In the Linux kernel, the following vulnerability has been resolved:
mptcp: reclaim forward-allocated memory on RX path errors
After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"),
errors in the receive path prior to queueing skbs into the receive
queue do not trigger forward-allocated memory reclaiming.
Prevent forward memory from growing unboundedly in pathological drop
scenarios by explicitly reclaiming memory when skbs are dropped.20dCVE-2026-22256—27.0%
——8——CVE-2025-27936—27.0%
——8——CVE-2014-2597—27.0%
——8——CVE-2026-719807.5 HIG27.0%
——8Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundaries by sending a zero-length comfort-noise RTP payload. A zero-length payload causes an integer underflow in the uint8_t filter order calculation, which wraps to 255 and is clamped to 10, causing the function to unconditionally read 11 bytes from a zero-byte buffer, resulting in media process termination or silent consumption of adjacent heap memory as reflection coefficients.30dCVE-2025-36202—27.0%
——8——CVE-2022-38237—27.0%
——8——CVE-2022-38236—27.0%
——8——CVE-2026-707977.2 HIG27.0%
——8Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).20dCVE-2022-36143—27.0%
——8——CVE-2025-54967—27.0%
——8——CVE-2024-52493—27.0%
——8——CVE-2026-708347.2 HIG27.0%
——8Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).23dCVE-2025-52773—27.0%
——8——CVE-2009-2201—27.0%
——8——CVE-2024-1901—27.0%
——8——CVE-2024-47191—27.0%
——8——CVE-2020-36827—27.0%
——8——CVE-2023-43502—27.0%
——8——CVE-2023-48786—27.0%
——8——CVE-2026-765819.8 CRI27.0%
——8The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.18dCVE-2026-3318—27.0%
——8——CVE-2025-22139—27.0%
——8——CVE-2006-2442—27.0%
——8——CVE-2013-6335—27.0%
——8——CVE-2013-5874—27.0%
——8——CVE-2025-32574—27.0%
——8——CVE-2026-773847.5 HIG27.0%
——8libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9.6dCVE-2018-10405—27.0%
——8——CVE-2026-46976—27.0%
——8——CVE-2024-0689—27.0%
——8——CVE-2026-46953—27.0%
——8——CVE-2018-25169—27.0%
——8——CVE-2024-39368—27.0%
——8——CVE-2023-31235—27.0%
——8——CVE-2025-48089—27.0%
——8——CVE-2026-196435.3 MED27.0%
——8An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input.
To remediate this issue, users should upgrade to version 1.11.862.29dCVE-2024-9726—27.0%
——8——CVE-2025-70059—27.0%
——8——CVE-2021-28250—27.0%
——8——