Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-510777.5 HIG23.6%
——7SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component45dCVE-2026-25501—23.6%
——7——CVE-2026-146827.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.14dCVE-2022-35234—23.6%
——7——CVE-2024-9388—23.6%
——7——CVE-2026-4568—23.6%
——7——CVE-2026-18673—23.6%
——7When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication.
An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.11dCVE-2024-5942—23.6%
——7——CVE-2025-53814—23.6%
——7——CVE-2016-0380—23.6%
——7——CVE-2024-9444—23.6%
——7——CVE-2026-596457.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcutil-fips 2.0.7 (2.0.X series) and 2.1.7 (2.1.X series).14dCVE-2017-12549—23.6%
——7——CVE-2026-82564—23.6%
——7Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table.
In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression rather than a literal, so a caller can send {"public_ref": {"not_eq": "<own-ref>"}} and, combined with Ash.Query.limit(1) and Ash.bulk_update!/Ash.bulk_destroy!, retarget the write at a record it never identified; an omitted key yields an IS NULL filter that matches an arbitrary row. The fix casts each identity value to the field type, rejecting non-scalar inputs.
This issue affects ash_ai: from 0.6.0 before 1.0.0.10dCVE-2020-36901—23.6%
——7——CVE-2026-182588.8 HIG23.6%
——7Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset24dCVE-2021-22539—23.6%
——7——CVE-2026-128527.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.14dCVE-2024-21128—23.6%
——7——CVE-2019-25450—23.6%
——7——CVE-2026-6708—23.6%
——7——CVE-2024-41565—23.6%
——7——CVE-2026-110118.1 HIG23.6%
——7Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)51dCVE-2026-2555—23.6%
——7——CVE-2026-596497.5 HIG23.6%
——7In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).9dCVE-2025-62037—23.6%
——7——CVE-2026-46489—23.6%
——7——CVE-2024-8987—23.6%
——7——CVE-2025-52868—23.6%
——7——CVE-2026-108427.5 HIG23.6%
——7IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.37dCVE-2023-7228—23.6%
——7——CVE-2022-1671—23.6%
——7——CVE-2026-6361—23.6%
——7——CVE-2025-3318—23.6%
——7——CVE-2024-47298—23.6%
——7——CVE-2026-10716—23.6%
——7Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.14dCVE-2026-47136—23.6%
——7——CVE-2026-770978.2 HIG23.6%
——7Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.7hCVE-2023-52338—23.6%
——7——CVE-2023-42782—23.6%
——7——