Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,243
- Medium6,230
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9443—24.1%
——7——CVE-2026-183228.8 HIG24.1%
——7The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.31dCVE-2024-9597—24.1%
——7——CVE-2026-605287.6 HIG24.1%
——7Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N).43dCVE-2026-122085.3 MED24.1%
——7A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2020-27936—24.1%
——7——CVE-2026-474717.5 HIG24.1%
——7NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service.59dCVE-2025-710007.5 HIG24.1%
——7An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.69dCVE-2025-1363—24.1%
——7——CVE-2026-505777.4 HIG24.1%
——7ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration leaves request_counter unchanged in app/vau/VAUProtokoll.py while constructing VAU messages. The frozen client request counter causes the server side to reuse AES-GCM nonce and key combinations across responses. A network attacker who collects repeated ciphertexts can recover the XOR of plaintexts and use predictable inner HTTP headers and JSON fields to recover sensitive data, including patient health records. Repeated nonces can also enable recovery of the GHASH authentication key through the Joux forbidden attack, allowing forged AES-GCM messages and injection of malicious responses. The response-counter check also fails to maintain last_response_counter, weakening replay and ordering validation. This issue is fixed in version 1.3.0.4dCVE-2026-122095.3 MED24.1%
——7A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown function of the file src/filters/index.js of the component Template Filter Handler. Such manipulation leads to improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.50dCVE-2025-27980—24.1%
——7——CVE-2023-35050—24.1%
——7——CVE-2024-23170—24.1%
——7——CVE-2024-10306—24.1%
——7——CVE-2024-46394—24.1%
——7——CVE-2025-24731—24.1%
——7——CVE-2022-22652—24.1%
——7——CVE-2013-3786—24.1%
——7——CVE-2023-4920—24.1%
——7——CVE-2024-43326—24.1%
——7——CVE-2014-2906—24.1%
——7——CVE-2024-5426—24.1%
——7——CVE-2025-49089—24.1%
——7——CVE-2026-2786—24.1%
——7——CVE-2024-6283—24.1%
——7——CVE-2024-45800—24.1%
——7——CVE-2026-44368—24.1%
——7——CVE-2019-25330—24.1%
——7——CVE-2019-11089—24.1%
——7——CVE-2024-10055—24.1%
——7——CVE-2024-12475—24.1%
——7——CVE-2024-55635—24.1%
——7——CVE-2025-6101—24.1%
——7——CVE-2022-45176—24.1%
——7——CVE-2026-399086.5 MED24.1%
——7OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application attempts to load proxies from the UNC path, triggering an SMB authentication attempt that discloses the NTLMv2 hash, which can then be relayed or cracked offline.51dCVE-2024-5152—24.1%
——7——CVE-2025-3613—24.1%
——7——CVE-2024-32797—24.1%
——7——CVE-2022-34560—24.1%
——7——