Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-7269—26.0%
——8——CVE-2015-2107—26.0%
——8——CVE-2025-23017—26.0%
——8——CVE-2025-1164—26.0%
——8——CVE-2024-2220—26.0%
——8——CVE-2021-33459—26.0%
——8——CVE-2020-25653—26.0%
——8——CVE-2024-51471—26.0%
——8——CVE-2026-897098.1 HIG26.0%
——8In the Linux kernel, the following vulnerability has been resolved:
lockd, nfsd: RCU-protect nlmsvc_ops dispatch
nlmsvc_ops is published by nfsd_lockd_init() and cleared by
nfsd_lockd_shutdown() with plain stores, while lockd dereferences
it unguarded from dispatch sites in fs/lockd/svcsubs.c. The pointer
targets nfsd's .rodata and the fopen/fclose callbacks live in nfsd's
.text, so a stale load after rmmod nfsd results in either a NULL
deref or a module-text use-after-free.
Declare nlmsvc_ops as __rcu, publish via rcu_assign_pointer(), clear
via RCU_INIT_POINTER() + synchronize_rcu(). Add a struct module
*owner field to nlmsvc_binding and pin the module across indirect
calls with try_module_get/module_put. When the binding is torn down,
fall back to fput() to avoid leaking struct file references.3dCVE-2026-25179—26.0%
——8——CVE-2023-26244—26.0%
——8——CVE-2024-422145.3 MED25.9%
——8HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.60dCVE-2011-4356—26.0%
——8——CVE-2020-27146—26.0%
——8——CVE-2019-8545—26.0%
——8——CVE-2002-2203—26.0%
——8——CVE-2019-4349—26.0%
——8——CVE-2026-57588—26.0%
——8——CVE-2025-68911—26.0%
——8——CVE-2022-35282—26.0%
——8——CVE-2021-471608.1 HIG26.0%
——8In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but
was not reset when it is disabled, which may cause traffic leaks:
ip link add br0 type bridge vlan_filtering 1
ip link add br1 type bridge vlan_filtering 1
ip link set swp0 master br0
ip link set swp1 master br1
ip link set br0 type bridge vlan_filtering 0
ip link set br1 type bridge vlan_filtering 0
# traffic in br0 and br1 will start leaking to each other
As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the
PCR_MATRIX write from mt7530_port_set_vlan_aware.42dCVE-2026-610669.9 CRI26.0%
——8Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via RMI to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).22dCVE-2019-0004—26.0%
——8——CVE-2026-654745.3 MED26.0%
——8Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.54dCVE-2024-47819—26.0%
——8——CVE-2021-0364—26.0%
——8——CVE-2014-3038—26.0%
——8——CVE-2025-6699—26.0%
——8——CVE-2026-655055.3 MED25.9%
——8Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.54dCVE-2026-619765.3 MED26.0%
——8Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.64dCVE-2026-2162—26.0%
——8——CVE-2024-46340—26.0%
——8——CVE-2025-6698—26.0%
——8——CVE-2015-1115—26.0%
——8——CVE-2025-10229—26.0%
——8——CVE-2019-20808—26.0%
——8——CVE-2025-6695—26.0%
——8——CVE-2025-52618—26.0%
——8——CVE-2015-7267—26.0%
——8——CVE-2024-55631—26.0%
——8——