Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3597—26.2%
——8——CVE-2006-0584—26.2%
——8——CVE-2010-1768—26.2%
——8——CVE-2026-32293—26.2%
——8——CVE-2026-2094—26.2%
——8——CVE-2025-11409—26.2%
——8——CVE-2026-28282—26.2%
——8——CVE-2026-606677.4 HIG26.2%
——8Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise HCM Human Resources. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).43dCVE-2026-154944.7 MED26.2%
——8A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.64dCVE-2026-693506.7 MED26.2%
——8Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.6dCVE-2025-59040—26.2%
——8——CVE-2019-2102—26.2%
——8——CVE-2021-30703—26.2%
——8——CVE-2024-4606—26.2%
——8——CVE-2025-7943—26.2%
——8——CVE-2026-202817.5 HIG26.2%
——8A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition.
Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.13dCVE-2026-608608.7 HIG26.2%
——8Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).25dCVE-2019-18409—26.2%
——8——CVE-2023-43267—26.2%
——8——CVE-2026-20671—26.2%
——8——CVE-2025-54137—26.2%
——8——CVE-2025-11358—26.2%
——8——CVE-2024-3973—26.2%
——8——CVE-2026-493678.0 HIG26.2%
——8In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account56dCVE-2023-2439—26.2%
——8——CVE-2026-713396.7 MED26.2%
——8Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.9hCVE-2026-667227.2 HIG26.2%
——8Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack.
A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check only confirms the caller is a Domain Admin, without verifying whether the target project belongs to their domain or subdomain. This allows a malicious Domain Admin to tamper with project roles and permissions across unrelated domains.
This issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.
Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.19dCVE-2023-51415—26.2%
——8——CVE-2026-6728—26.2%
——8——CVE-2025-10110—26.2%
——8——CVE-2021-28713—26.2%
——8——CVE-2021-28711—26.2%
——8——CVE-2024-40598—26.2%
——8——CVE-2026-127894.7 MED26.2%
——8A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Tracking. Such manipulation of the argument troup_table_nav leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. This issue was independently identified and fixed internally by the vendor's own security team ahead of this report.62dCVE-2026-28226—26.2%
——8——CVE-2024-36905—26.2%
——8——CVE-2009-1962—26.2%
——8——CVE-2022-4548—26.2%
——8——CVE-2026-861238.7 HIG26.2%
——8SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.7dCVE-2022-208266.4 MED26.2%
——8A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality.
This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.35d