Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,235
- High8,293
- Medium6,321
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-187016.5 MED22.7%
——7An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.13dCVE-2026-817747.5 HIG22.7%
——7Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.8dCVE-2024-55025—22.7%
——7——CVE-2024-13302—22.7%
——7——CVE-2025-65803—22.7%
——7——CVE-2024-12524—22.7%
——7——CVE-2025-9096—22.7%
——7——CVE-2026-50819.1 CRI22.7%
——7Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure.
Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session id. The UNIQUE_ID variable is set by the Apache mod_unique_id plugin, which generates unique ids for the request. The id is based on the IPv4 address, the process id, the epoch time, a 16-bit counter and a thread index, with no obfuscation.
The server IP is often available to the public, and if not available, can be guessed from previous session ids being issued. The process ids may also be guessed from previous session ids. The timestamp is easily guessed (and leaked in the HTTP Date response header).
The purpose of mod_unique_id is to assign a unique id to requests so that events can be correlated in different logs. The id is not designed, nor is it suitable for security purposes.58dCVE-2018-3697—22.7%
——7——CVE-2024-13290—22.7%
——7——CVE-2019-3610—22.7%
——7——CVE-2025-42983—22.7%
——7——CVE-2025-31581—22.7%
——7——CVE-2024-13312—22.7%
——7——CVE-2025-52268—22.7%
——7——CVE-2025-401418.0 HIG22.7%
——7In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix possible UAF on iso_conn_free
This attempt to fix similar issue to sco_conn_free where if the
conn->sk is not set to NULL may lead to UAF on iso_conn_free.42dCVE-2026-30523—22.7%
——7——CVE-2022-22621—22.7%
——7——CVE-2022-38382—22.7%
——7——CVE-2000-0080—22.7%
——7——CVE-2021-1055—22.7%
——7——CVE-2026-138567.5 HIG22.7%
——7Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)70dCVE-2026-122939.8 CRI22.7%
——7Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.58dCVE-2024-37994—22.7%
——7——CVE-2021-22184—22.7%
——7——CVE-2008-4640—22.7%
——7——CVE-2023-1490—22.7%
——7——CVE-2025-60858—22.7%
——7——CVE-2020-37103—22.7%
——7——CVE-2026-106947.3 HIG22.7%
——7A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.50dCVE-2022-487828.8 HIG22.7%
——7In the Linux kernel, the following vulnerability has been resolved:
mctp: fix use after free
Clang static analysis reports this problem
route.c:425:4: warning: Use of memory after it is freed
trace_mctp_key_acquire(key);
^~~~~~~~~~~~~~~~~~~~~~~~~~~
When mctp_key_add() fails, key is freed but then is later
used in trace_mctp_key_acquire(). Add an else statement
to use the key only when mctp_key_add() is successful.37dCVE-2020-4602—22.7%
——7——CVE-2026-27370—22.7%
——7——CVE-2026-54187.3 HIG22.7%
——7A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java of the component Dashboard. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.99 is recommended to address this issue. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.48dCVE-2025-69416—22.7%
——7——CVE-2024-40543—22.7%
——7——CVE-2025-69417—22.7%
——7——CVE-2025-3869—22.7%
——7——CVE-2025-21450—22.7%
——7——CVE-2020-0183—22.7%
——7——