Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,231
- High8,251
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-385907.1 HIG24.0%
——7In the Linux kernel, the following vulnerability has been resolved:
RDMA/hns: Modify the print level of CQE error
Too much print may lead to a panic in kernel. Change ibdev_err() to
ibdev_err_ratelimited(), and change the printing level of cqe dump
to debug level.39dCVE-2016-4748—24.0%
——7——CVE-2025-7662—24.0%
——7——CVE-2026-101107.3 HIG24.0%
——7A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.52dCVE-2025-48272—24.0%
——7——CVE-2024-24776—24.0%
——7——CVE-2010-3359—24.0%
——7——CVE-2026-733649.8 CRI24.0%
——7Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.23dCVE-2011-2693—24.0%
——7——CVE-2026-171777.5 HIG24.0%
——7IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.23dCVE-2007-3851—24.0%
——7——CVE-2025-24852—24.0%
——7——CVE-2026-739249.1 CRI24.0%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).15dCVE-2026-6182—24.0%
——7——CVE-2024-35748—24.0%
——7——CVE-2025-66454—24.0%
——7——CVE-2024-54446—24.0%
——7——CVE-2026-42085—24.0%
——7——CVE-2024-23488—24.0%
——7——CVE-2008-0216—24.0%
——7——CVE-2026-35231—24.0%
——7——CVE-2023-45128—24.0%
——7——CVE-2022-28735—24.0%
——7——CVE-2017-13305—24.0%
——7——CVE-2024-30459—24.0%
——7——CVE-2016-3155—24.0%
——7——CVE-2024-12646—24.0%
——7——CVE-2024-31359—24.0%
——7——CVE-2025-39357—24.0%
——7——CVE-2007-3719—24.0%
——7——CVE-2025-60236—24.0%
——7——CVE-2026-22612—24.0%
——7——CVE-2025-20230—24.0%
——7——CVE-2025-13159—24.0%
——7——CVE-2024-54501—24.0%
——7——CVE-2016-0910—24.0%
——7——CVE-2024-9115—24.0%
——7——CVE-2008-1946—24.0%
——7——CVE-2026-18677—24.0%
——7In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.12dCVE-2026-822269.8 CRI24.0%
——7Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.11d