Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45857—23.0%
——7——CVE-2026-470215.3 MED23.0%
——7Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).29dCVE-2025-5151—23.0%
——7——CVE-2026-44996—23.0%
——7——CVE-2008-5312—23.0%
——7——CVE-2026-11877—23.0%
——7——CVE-2024-11750—23.0%
——7——CVE-2026-671946.5 MED23.0%
——7Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with alloc_search_andlist() and alloc_search_notkey(), with no depth limit. Courier IMAP has no overall command line length limit, making exploitation trivial. A single IMAP command with ~2500 nested parentheses overflows the 8MB default stack, causing SIGSEGV.42dCVE-2024-6322—23.0%
——7——CVE-2025-57755—23.0%
——7——CVE-2026-48835—23.0%
——7——CVE-2025-53507—23.0%
——7——CVE-2025-2715—23.0%
——7——CVE-2026-26233—23.0%
——7——CVE-2025-48704—23.0%
——7——CVE-2023-0870—23.0%
——7——CVE-2025-27705—23.0%
——7——CVE-2024-51019—23.0%
——7——CVE-2024-51007—23.0%
——7——CVE-2026-129817.5 HIG23.0%
——7The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.48dCVE-2024-51022—23.0%
——7——CVE-2024-51014—23.0%
——7——CVE-2024-5890—23.0%
——7——CVE-2026-463445.3 MED22.9%
——7liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT stateful signature verification code. When the verification function is called with a correctly-sized signature buffer for the declared algorithm but a public key whose OID bytes (pk[0..3]) reference a different XMSS parameter set with a larger sig_bytes, the implementation re-parses the OID from the public key inside xmss_sign_open / xmssmt_sign_open and uses the resulting (larger) sig_bytes to index the caller-supplied signature buffer. As with CVE-2026-44518, the out-of-bounds bytes are consumed only as input to an internal hash computation and are not returned to the caller, so no oracle exists to leak their contents to an attacker. The primary observable effect is a possible crash (denial of service) of the verifying process if the read crosses into an unmapped memory page. This vulnerability is fixed in 0.16.0.51dCVE-2024-10606—23.0%
——7——CVE-2024-45238—23.0%
——7——CVE-2026-142156.5 MED23.0%
——7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.7dCVE-2026-693164.7 MED23.0%
——7Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.2dCVE-2025-612207.5 HIG23.0%
——7The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other users and gain unauthorized access to their personal information.68dCVE-2025-39574—23.0%
——7——CVE-2024-51018—23.0%
——7——CVE-2024-49273—23.0%
——7——CVE-2026-11401—23.0%
——7——CVE-2024-31402—23.0%
——7——CVE-2025-6353—23.0%
——7——CVE-2025-11957—23.0%
——7——CVE-2025-39585—23.0%
——7——CVE-2025-39573—23.0%
——7——CVE-2024-51017—23.0%
——7——CVE-2025-1691—23.0%
——7——