Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,227
- High8,212
- Medium6,219
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6160—23.4%
——7——CVE-2011-4202—23.4%
——7——CVE-2026-507385.3 MED23.4%
——7A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to influence worker start, stop, and restart timing through permitted pglogical operations. In the typical case the condition crashes replication workers, causing an availability impact. In the worst case a use-after-free in a PostgreSQL backend can be leveraged as a remote code execution primitive at the privilege of that backend.19dCVE-2024-9542—23.4%
——7——CVE-2002-1550—23.4%
——7——CVE-2026-455016.5 MED23.4%
——7Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.46dCVE-2023-22001—23.4%
——7——CVE-2022-47662—23.4%
——7——CVE-2023-47583—23.4%
——7——CVE-2016-2949—23.4%
——7——CVE-2026-45808—23.4%
——7OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in another tenant via the legacy, undocumented `sys/revoke` and `sys/renew` endpoints. This is fixed in OpenBao v2.5.4.3dCVE-2025-58458—23.4%
——7——CVE-2026-660645.3 MED23.4%
——7goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.44dCVE-2025-13732—23.4%
——7——CVE-2024-50448—23.4%
——7——CVE-2026-17593—23.4%
——7An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.11dCVE-2016-6774—23.4%
——7——CVE-2025-23568—23.4%
——7——CVE-2023-0685—23.4%
——7——CVE-2019-20652—23.4%
——7——CVE-2024-10667—23.4%
——7——CVE-2023-22875—23.4%
——7——CVE-2024-33985—23.4%
——7——CVE-2023-0724—23.4%
——7——CVE-2024-47369—23.4%
——7——CVE-2019-2227—23.4%
——7——CVE-2023-31981—23.4%
——7——CVE-2026-610219.9 CRI23.4%
——7Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).22dCVE-2026-43378—23.4%
——7——CVE-2025-23742—23.4%
——7——CVE-2024-33988—23.4%
——7——CVE-2024-4174—23.4%
——7——CVE-2025-39590—23.4%
——7——CVE-2018-20941—23.4%
——7——CVE-2025-7891—23.4%
——7——CVE-2024-23559—23.4%
——7——CVE-2023-25364—23.4%
——7——CVE-2026-73448.8 HIG23.4%
——7Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)50dCVE-2011-4922—23.4%
——7——CVE-2025-23657—23.4%
——7——