Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,666
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22309—21.7%
——7——CVE-2026-626678.1 HIG21.7%
——7Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete identity. AbstractApiController::requirePermission() consequently evaluates the full user ACL, so a key issued for a read-only scope can perform every write, delete, and administrative operation available to the owner. This issue is fixed in version 1.0.6.15dCVE-2025-55684—21.7%
——7——CVE-2026-138508.8 HIG21.7%
——7Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)64dCVE-2026-610483.1 LOW21.7%
——7Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Inventory Optimization. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Inventory Optimization. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).33dCVE-2024-10635—21.7%
——7——CVE-2013-1173—21.7%
——7——CVE-2026-786817.5 HIG21.7%
——7NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.7dCVE-2026-177824.3 MED21.7%
——7Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)35dCVE-2026-736449.6 CRI21.7%
——7OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an authenticated account holding PROXIED_AUTH assume any resolvable non-root identity outside the identities permitted by its proxy ACI. The fix returns INVALID_CREDENTIALS (49) before password verification when the target authorization identity is not permitted. This issue is fixed in version 5.1.2.22dCVE-2024-43161—21.7%
——7——CVE-2026-739187.3 HIG21.7%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).11dCVE-2024-10690—21.7%
——7——CVE-2026-102877.3 HIG21.7%
——7A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.48dCVE-2026-273995.3 MED21.7%
——7Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.47dCVE-2025-61589—21.7%
——7——CVE-2025-37872—21.7%
——7——CVE-2019-4588—21.7%
——7——CVE-2026-655065.3 MED21.7%
——7Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.47dCVE-2026-703547.8 HIG21.7%
——7Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.22dCVE-2019-0148—21.7%
——7——CVE-2026-86104.3 MED21.7%
——7The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the plugin's site-wide font settings, including the typesquare_auth option (fontThemeUseType), show_post_form, and typesquare_fonttheme, by submitting a POST request to any wp-admin page. For fontThemeUseType values 1 and 3, no nonce verification is performed either, meaning those branches are additionally exploitable via cross-site request forgery.47dCVE-2020-0563—21.7%
——7——CVE-2024-1052—21.7%
——7——CVE-2026-57660—21.7%
——7——CVE-2024-33627—21.7%
——7——CVE-2025-66837—21.7%
——7——CVE-2026-274185.3 MED21.7%
——7Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.47dCVE-2022-490547.1 HIG21.7%
——7In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Deactivate sysctl_record_panic_msg by default in isolated guests
hv_panic_page might contain guest-sensitive information, do not dump it
over to Hyper-V by default in isolated guests.
While at it, update some comments in hyperv_{panic,die}_event().35dCVE-2024-42325—21.7%
——7——CVE-2024-43125—21.7%
——7——CVE-2023-41129—21.7%
——7——CVE-2023-47670—21.7%
——7——CVE-2026-274225.3 MED21.7%
——7Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.47dCVE-2020-0562—21.7%
——7——CVE-2023-47667—21.7%
——7——CVE-2025-42970—21.7%
——7——CVE-2024-46505—21.7%
——7——CVE-2013-5710—21.7%
——7——CVE-2022-31617—21.7%
——7——