Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,243
- Medium6,230
- Low613
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-4619—24.1%
——7——CVE-2026-848417.3 HIG24.1%
——7A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.7dCVE-2025-65779—24.1%
——7——CVE-2025-45317—24.1%
——7——CVE-2016-0674—24.1%
——7——CVE-2020-11924—24.1%
——7——CVE-2026-6612—24.1%
——7——CVE-2020-37083—24.1%
——7——CVE-2019-25328—24.1%
——7——CVE-2026-59982—24.1%
——7——CVE-2025-14122—24.1%
——7——CVE-2023-27520—24.1%
——7——CVE-2025-54300—24.1%
——7——CVE-2023-51497—24.0%
——7——CVE-2025-56380—24.0%
——7——CVE-2025-6595—24.0%
——7——CVE-2025-11638—24.0%
——7——CVE-2023-3428—24.0%
——7——CVE-2025-7754—24.0%
——7——CVE-2026-65758—24.0%
——7Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.51dCVE-2026-169247.5 HIG24.0%
——7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.19dCVE-2012-6348—24.0%
——7——CVE-2025-6594—24.0%
——7——CVE-2024-580998.6 HIG24.0%
——7In the Linux kernel, the following vulnerability has been resolved:
vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
Andrew and Nikolay reported connectivity issues with Cilium's service
load-balancing in case of vmxnet3.
If a BPF program for native XDP adds an encapsulation header such as
IPIP and transmits the packet out the same interface, then in case
of vmxnet3 a corrupted packet is being sent and subsequently dropped
on the path.
vmxnet3_xdp_xmit_frame() which is called e.g. via vmxnet3_run_xdp()
through vmxnet3_xdp_xmit_back() calculates an incorrect DMA address:
page = virt_to_page(xdpf->data);
tbi->dma_addr = page_pool_get_dma_addr(page) +
VMXNET3_XDP_HEADROOM;
dma_sync_single_for_device(&adapter->pdev->dev,
tbi->dma_addr, buf_size,
DMA_TO_DEVICE);
The above assumes a fixed offset (VMXNET3_XDP_HEADROOM), but the XDP
BPF program could have moved xdp->data. While the passed buf_size is
correct (xdpf->len), the dma_addr needs to have a dynamic offset which
can be calculated as xdpf->data - (void *)xdpf, that is, xdp->data -
xdp->data_hard_start.39dCVE-2023-40395—24.0%
——7——CVE-2026-136987.5 HIG24.0%
——7A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service65dCVE-2026-624905.3 MED24.0%
——7Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).47dCVE-2019-4275—24.0%
——7——CVE-2018-12989—24.0%
——7——CVE-2025-22244—24.0%
——7——CVE-2026-49277—24.0%
——7——CVE-2024-511114.1 MED24.0%
——7Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of the victim's browser.69dCVE-2023-3200—24.0%
——7——CVE-2022-47089—24.0%
——7——CVE-2024-5191—24.0%
——7——CVE-2021-3700—24.0%
——7——CVE-2025-56381—24.0%
——7——CVE-2026-555447.6 HIG24.0%
——7NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that restricts normal users to campaigns they created, but multiple MCP campaign handlers ignore the authenticated user ID and query or mutate campaigns only by object ID. As a result, a low-privileged authenticated user with a valid MCP API token can enumerate all campaigns, read campaign details, update or delete campaigns owned by other users, modify campaign templates and steps, and potentially trigger or pause campaign delivery. Version 0.12.2 fixes the issue.52dCVE-2026-45757—24.0%
——7——CVE-2025-28962—24.0%
——7——