Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-890126.5 MED27.0%
——8Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.4dCVE-2019-3866—27.0%
——8——CVE-2021-23002—27.0%
——8——CVE-2023-38654—27.0%
——8——CVE-2024-29140—27.0%
——8——CVE-2020-8690—27.0%
——8——CVE-2016-6480—27.0%
——8——CVE-2012-3215—27.0%
——8——CVE-2024-30553—27.0%
——8——CVE-2021-44149—27.0%
——8——CVE-2016-8660—27.0%
——8——CVE-2011-0441—27.0%
——8——CVE-2024-32834—27.0%
——8——CVE-2024-31102—27.0%
——8——CVE-2026-572305.4 MED27.0%
——8OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions that took input without escaping, allowing an authenticated member to read any ClickHouse table through blind boolean and time-based exfiltration and to break the project's session search for all viewers until the stored key is removed. This issue is fixed in version 1.27.0.65dCVE-2022-4017—27.0%
——8——CVE-2014-4442—27.0%
——8——CVE-2025-30347—27.0%
——8——CVE-2026-32610—27.0%
——8——CVE-2025-1666—27.0%
——8——CVE-2026-183067.8 HIG27.0%
——8GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of SGI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29396.14dCVE-2025-15332—27.0%
——8——CVE-2025-47479—27.0%
——8——CVE-2026-2018—27.0%
——8——CVE-2024-32801—27.0%
——8——CVE-2023-44344—27.0%
——8——CVE-2021-44021—27.0%
——8——CVE-2020-8692—27.0%
——8——CVE-2024-32722—27.0%
——8——CVE-2026-2057—27.0%
——8——CVE-2026-1688—27.0%
——8——CVE-2023-43620—27.0%
——8——CVE-2020-37080—27.0%
——8——CVE-2024-29105—27.0%
——8——CVE-2001-0474—27.0%
——8——CVE-2026-29924—27.0%
——8——CVE-2018-19608—27.0%
——8——CVE-2024-32707—27.0%
——8——CVE-2020-16128—27.0%
——8——CVE-2021-475208.8 HIG27.0%
——8In the Linux kernel, the following vulnerability has been resolved:
can: pch_can: pch_can_rx_normal: fix use after free
After calling netif_receive_skb(skb), dereferencing skb is unsafe.
Especially, the can_frame cf which aliases skb memory is dereferenced
just after the call netif_receive_skb(skb).
Reordering the lines solves the issue.43d