Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24874—25.2%
——8——CVE-2025-68384—25.2%
——8——CVE-2026-470234.9 MED25.2%
——8Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).50dCVE-2023-30527—25.2%
——8——CVE-2024-23586—25.2%
——8——CVE-2003-0517—25.2%
——8——CVE-2025-61152—25.1%
——8——CVE-2026-44651—25.2%
——8SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends:
res.status(500).send('Error occurred while trying to proxy to: ' + url + ' ' + error). The url value is attacker-controlled (req.params.url) and is not HTML-escaped before rendering. This vulnerability is fixed in 1.18.0.55dCVE-2024-31294—25.2%
——8——CVE-2024-1575—25.2%
——8——CVE-2025-48493—25.2%
——8——CVE-2023-29950—25.2%
——8——CVE-2019-16543—25.2%
——8——CVE-2026-607487.6 HIG25.2%
——8Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).21dCVE-2024-28684—25.2%
——8——CVE-2026-875496.5 MED25.2%
——8Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2019-25473—25.2%
——8——CVE-2025-43782—25.2%
——8——CVE-2024-28112—25.2%
——8——CVE-2025-50031—25.2%
——8——CVE-2025-30993—25.2%
——8——CVE-2026-579558.5 HIG25.2%
——8SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery.63dCVE-2026-147235.3 MED25.2%
——8A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed locally. The pull request to fix this issue awaits acceptance.71dCVE-2003-0844—25.2%
——8——CVE-2026-592153.1 LOW25.2%
——8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message from another private or DM channel and disclose thread context across channels. This issue is fixed in version 0.10.0.64dCVE-2026-53933—25.2%
——8Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string placeholder key was mistakenly registered into the flat static route checklist. An attacker scanning endpoints could intentionally pass the literal template syntax (e.g., `GET /api/v1/users/{id}`) to force an unexpected match against the static map. Because the dynamic tree engine was bypassed, no arguments were captured. This forced modern PHP 8+ versions to throw a native `ArgumentCountError`, resulting in a 500 Internal Server Error instead of a uniform 404 Not Found. By tracking which fuzz patterns exploded into a 500 error, a malicious actor could programmatically profile and map out internal route parameter names and controller schemas. Version 10.73.1 contains a patch. As a workaround, mitigate this side-channel leak by implementing a defensive check in a global middleware. This will reject any literal brace patterns before they reach the router engine.5dCVE-2024-22129—25.2%
——8——CVE-2024-3966—25.2%
——8——CVE-2024-13457—25.1%
——8——CVE-2024-30517—25.2%
——8——CVE-2022-33177—25.2%
——8——CVE-2026-21998—25.2%
——8——CVE-2024-22130—25.2%
——8——CVE-2024-34435—25.2%
——8——CVE-2018-4387—25.2%
——8——CVE-2007-1072—25.2%
——8——CVE-2024-30537—25.2%
——8——CVE-2026-34293—25.2%
——8——CVE-2024-25391—25.2%
——8——CVE-2024-43702—25.2%
——8——