Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-499766.5 MED26.8%
——8Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. app/Importer/UserImporter.php applies the canEditAuthFields gate by unsetting username, email, password, and activated on the model, but app/Importer/ItemImporter.php sanitizeItemForUpdating() rebuilds the update array from the raw CSV row in $this->item, restoring the unauthorized values. The app/Http/Controllers/ImportController.php import path checks import permission but does not require users.edit. This issue is fixed in version 8.6.1.6dCVE-2026-115948.5 HIG26.8%
——8IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.75dCVE-2026-603945.3 MED26.8%
——8Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).46dCVE-2024-27897—26.8%
——8——CVE-2023-51692—26.8%
——8——CVE-2025-10760—26.8%
——8——CVE-2026-90460—26.8%
——8An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.1dCVE-2024-20766—26.8%
——8——CVE-2024-37443—26.8%
——8——CVE-2025-8083—26.8%
——8——CVE-2023-35647—26.8%
——8——CVE-2024-501258.0 HIG26.8%
——8In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: SCO: Fix UAF on sco_sock_timeout
conn->sk maybe have been unlinked/freed while waiting for sco_conn_lock
so this checks if the conn->sk is still valid by checking if it part of
sco_sk_list.27dCVE-2023-52376—26.8%
——8——CVE-2011-0796—26.8%
——8——CVE-2010-2522—26.8%
——8——CVE-2024-32148—26.8%
——8——CVE-2023-34461—26.8%
——8——CVE-2023-35648—26.8%
——8——CVE-2025-11278—26.8%
——8——CVE-2024-43427—26.8%
——8——CVE-2025-48941—26.8%
——8——CVE-2016-7032—26.8%
——8——CVE-2022-39189—26.8%
——8——CVE-2023-52549—26.8%
——8——CVE-2025-11946—26.8%
——8——CVE-2023-50939—26.8%
——8——CVE-2025-53251—26.8%
——8——CVE-2026-34518—26.8%
——8——CVE-2024-5383—26.8%
——8——CVE-2026-606115.3 MED26.8%
——8Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).46dCVE-2019-14613—26.8%
——8——CVE-2024-3027—26.8%
——8——CVE-2023-0320—26.8%
——8——CVE-2026-590967.5 HIG26.8%
——8Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour public cache lifetime. A remote unauthenticated attacker can poison the discovery document so relying parties performing dynamic (unpinned) discovery fetch the JWKS from an attacker-controlled server, causing attacker-signed JWTs to be accepted. Exploitation requires the OIDC server enabled without a configured jwt-issuer or oidc-allowed-hosts.63dCVE-2025-4670—26.8%
——8——CVE-2025-59253—26.8%
——8——CVE-2023-30452—26.8%
——8——CVE-2024-20770—26.8%
——8——CVE-2024-3826—26.8%
——8——CVE-2025-53213—26.8%
——8——