Vulnerabilities exploitable today
372,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,271
- High8,382
- Medium6,462
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-169617.6 HIG23.5%
——7IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.25dCVE-2023-46001—23.5%
——7——CVE-2024-7249—23.5%
——7——CVE-2026-304637.7 HIG23.5%
——7Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.68dCVE-2025-23072—23.5%
——7——CVE-2024-41701—23.5%
——7——CVE-2018-9353—23.5%
——7——CVE-2026-812724.9 MED23.5%
——7Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.14dCVE-2025-30447—23.5%
——7——CVE-2026-7898—23.5%
——7——CVE-2025-42961—23.5%
——7——CVE-2023-36857—23.5%
——7——CVE-2024-13412—23.5%
——7——CVE-2024-12309—23.5%
——7——CVE-2025-43329—23.5%
——7——CVE-2024-11727—23.4%
——7——CVE-2026-278776.5 MED23.5%
——7When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.59dCVE-2023-22405—23.5%
——7——CVE-2023-22947—23.5%
——7——CVE-2026-8349—23.5%
——7——CVE-2019-0381—23.5%
——7——CVE-2025-50405—23.5%
——7——CVE-2026-40262—23.5%
——7——CVE-2026-861778.8 HIG23.5%
——7Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.3dCVE-2025-30726—23.5%
——7——CVE-2024-42389—23.5%
——7——CVE-2020-14416—23.5%
——7——CVE-2026-7644—23.5%
——7——CVE-2026-13406—23.5%
——7——CVE-2024-579867.1 HIG23.5%
——7In the Linux kernel, the following vulnerability has been resolved:
HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections
A report in 2019 by the syzbot fuzzer was found to be connected to two
errors in the HID core associated with Resolution Multipliers. One of
the errors was fixed by commit ea427a222d8b ("HID: core: Fix deadloop
in hid_apply_multiplier."), but the other has not been fixed.
This error arises because hid_apply_multipler() assumes that every
Resolution Multiplier control is contained in a Logical Collection,
i.e., there's no way the routine can ever set multiplier_collection to
NULL. This is in spite of the fact that the function starts with a
big comment saying:
* "The Resolution Multiplier control must be contained in the same
* Logical Collection as the control(s) to which it is to be applied.
...
* If no Logical Collection is
* defined, the Resolution Multiplier is associated with all
* controls in the report."
* HID Usage Table, v1.12, Section 4.3.1, p30
*
* Thus, search from the current collection upwards until we find a
* logical collection...
The comment and the code overlook the possibility that none of the
collections found may be a Logical Collection.
The fix is to set the multiplier_collection pointer to NULL if the
collection found isn't a Logical Collection.38dCVE-2024-20409—23.5%
——7——CVE-2026-581017.5 HIG23.5%
——7Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference.
X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. basicC, ia5string, and auth_att dereference its result without a NULL check. keyid_data also dereferences akid->keyid, which is NULL for an empty AKI SEQUENCE (DER 30 00) even when the parse succeeds.
A caller invoking an affected helper on an extension from an untrusted certificate triggers a SIGSEGV that crashes the Perl process.32dCVE-2024-41954—23.5%
——7——CVE-2014-5423—23.5%
——7——CVE-2023-6904—23.5%
——7——CVE-2025-68855—23.4%
——7——CVE-2019-19339—23.5%
——7——CVE-2023-22414—23.5%
——7——CVE-2024-13673—23.5%
——7——CVE-2026-204316.5 MED23.5%
——7In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.49d