Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-50174—25.2%
——8——CVE-2026-27749—25.2%
——8——CVE-2021-43575—25.2%
——8——CVE-2024-30517—25.2%
——8——CVE-2024-13457—25.1%
——8——CVE-2022-33177—25.2%
——8——CVE-2026-21998—25.2%
——8——CVE-2024-8121—25.2%
——8——CVE-2025-13847—25.2%
——8——CVE-2020-14111—25.2%
——8——CVE-2026-22002—25.2%
——8——CVE-2023-41781—25.2%
——8——CVE-2024-49504—25.2%
——8——CVE-2007-1072—25.2%
——8——CVE-2024-34435—25.2%
——8——CVE-2026-601565.3 MED25.2%
——8Vulnerability in Oracle APEX (component: General). Supported versions that are affected are 24.1, 24.2 and 26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle APEX. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle APEX accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).40dCVE-2026-34293—25.2%
——8——CVE-2024-22130—25.2%
——8——CVE-2024-30537—25.2%
——8——CVE-2018-4387—25.2%
——8——CVE-2024-31267—25.2%
——8——CVE-2024-43702—25.2%
——8——CVE-2026-53933—25.2%
——8Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string placeholder key was mistakenly registered into the flat static route checklist. An attacker scanning endpoints could intentionally pass the literal template syntax (e.g., `GET /api/v1/users/{id}`) to force an unexpected match against the static map. Because the dynamic tree engine was bypassed, no arguments were captured. This forced modern PHP 8+ versions to throw a native `ArgumentCountError`, resulting in a 500 Internal Server Error instead of a uniform 404 Not Found. By tracking which fuzz patterns exploded into a 500 error, a malicious actor could programmatically profile and map out internal route parameter names and controller schemas. Version 10.73.1 contains a patch. As a workaround, mitigate this side-channel leak by implementing a defensive check in a global middleware. This will reject any literal brace patterns before they reach the router engine.5dCVE-2024-25391—25.2%
——8——CVE-2025-59202—25.2%
——8——CVE-2026-43570—25.2%
——8——CVE-2012-3737—25.2%
——8——CVE-2026-22005—25.2%
——8——CVE-2026-592153.1 LOW25.2%
——8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message from another private or DM channel and disclose thread context across channels. This issue is fixed in version 0.10.0.64dCVE-2003-0844—25.2%
——8——CVE-2024-22129—25.2%
——8——CVE-2024-3966—25.2%
——8——CVE-2024-35724—25.2%
——8——CVE-2026-32817—25.2%
——8——CVE-2026-328827.1 HIG25.2%
——8libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.62dCVE-2025-33254—25.2%
——8——CVE-2024-25388—25.2%
——8——CVE-2024-13589—25.2%
——8——CVE-2023-45633—25.2%
——8——CVE-2026-34304—25.2%
——8——