Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-6239—22.0%
——7——CVE-2024-37172—22.0%
——7——CVE-2024-32715—22.0%
——7——CVE-2023-39387—22.0%
——7——CVE-2020-12333—22.0%
——7——CVE-2014-4248—22.0%
——7——CVE-2024-11623—22.0%
——7——CVE-2026-46593—22.0%
——7A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.12dCVE-2025-26748—22.0%
——7——CVE-2025-385339.8 CRI22.0%
——7In the Linux kernel, the following vulnerability has been resolved:
net: libwx: fix the using of Rx buffer DMA
The wx_rx_buffer structure contained two DMA address fields: 'dma' and
'page_dma'. However, only 'page_dma' was actually initialized and used
to program the Rx descriptor. But 'dma' was uninitialized and used in
some paths.
This could lead to undefined behavior, including DMA errors or
use-after-free, if the uninitialized 'dma' was used. Althrough such
error has not yet occurred, it is worth fixing in the code.41dCVE-2024-51909—22.0%
——7——CVE-2024-51890—22.0%
——7——CVE-2022-35114—22.0%
——7——CVE-2026-470854.0 MED22.0%
——7An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)53dCVE-2026-592133.5 LOW22.0%
——7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permission-filtered per-user model lists to share a static cache entry and exposing one user’s model list to another caller during the TTL window. This issue is fixed in version 0.10.0.60dCVE-2025-46270—22.0%
——7——CVE-2024-10151—22.0%
——7——CVE-2024-30560—22.0%
——7——CVE-2021-3236—22.0%
——7——CVE-2024-51868—22.0%
——7——CVE-2026-243306.5 MED22.0%
——7A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This could lead to further exploitation, such as arbitrary file read vulnerabilities.25dCVE-2026-32852—22.0%
——7——CVE-2024-11596—22.0%
——7——CVE-2024-33804—22.0%
——7——CVE-2024-13074—22.0%
——7——CVE-2025-27853—22.0%
——7——CVE-2025-0362—22.0%
——7——CVE-2022-35106—22.0%
——7——CVE-2025-54157—22.0%
——7——CVE-2023-36482—22.0%
——7——CVE-2026-48896—22.0%
——7——CVE-2024-4154—22.0%
——7——CVE-2025-25514—22.0%
——7——CVE-2021-3461—22.0%
——7——CVE-2024-51889—22.0%
——7——CVE-2026-482428.1 HIG22.0%
——7Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.48dCVE-2026-237473.7 LOW22.0%
——7Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in Payload Utils. The golioth_payload_as_int() and golioth_payload_as_float() helpers copy network-supplied payload data into fixed-size stack buffers using memcpy() with a length derived from payload_size. The only length checks are guarded by assert(); in release builds, the asserts are compiled out and memcpy() may copy an unbounded payload_size. Payloads larger than 12 bytes (int) or 32 bytes (float) can overflow the stack, resulting in a crash/denial of service. This is reachable via LightDB State on_payload with a malicious server or MITM.57dCVE-2017-7372—22.0%
——7——CVE-2024-9073—22.0%
——7——CVE-2012-1995—22.0%
——7——