Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,668
- Medium5,756
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12852—21.6%
——6——CVE-2024-50414—21.6%
——6——CVE-2026-763666.5 MED21.6%
——6In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.18dCVE-2026-64968—21.6%
——6ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, or local files via file:// if the PHP
environment permits URL wrappers.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.11dCVE-2023-38071—21.6%
——6——CVE-2025-57807—21.6%
——6——CVE-2026-33913—21.6%
——6——CVE-2025-37858—21.6%
——6——CVE-2023-31441—21.6%
——6——CVE-2026-31719—21.6%
——6——CVE-2024-3635—21.6%
——6——CVE-2025-4051—21.6%
——6——CVE-2025-30904—21.6%
——6——CVE-2025-0706—21.6%
——6——CVE-2025-50067—21.6%
——6——CVE-2025-53026—21.6%
——6——CVE-2014-5648—21.6%
——6——CVE-2025-11545—21.6%
——6——CVE-2024-29141—21.6%
——6——CVE-2020-4918—21.6%
——6——CVE-2020-7310—21.6%
——6——CVE-2024-13143—21.6%
——6——CVE-2026-628349.3 CRI21.6%
——6Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.15dCVE-2024-52486—21.6%
——6——CVE-2025-26408—21.6%
——6——CVE-2025-27927—21.6%
——6——CVE-2025-24600—21.6%
——6——CVE-2025-15086—21.6%
——6——CVE-2020-24366—21.6%
——6——CVE-2024-0554—21.6%
——6——CVE-2026-416497.7 HIG21.6%
——6Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure direct object reference.. When both `collectionId` and `documentId` are provided in the request, the authorization logic only checks access to the collection, completely ignoring the document. This allows an authenticated attacker to generate a valid public share link for any document on the platform, including documents belonging to other workspaces. The full document contents can then be retrieved via the `documents.info` endpoint. Version 1.7.0 contains a patch.46dCVE-2014-5894—21.6%
——6——CVE-2026-47735—21.6%
——6Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family — `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`, `read_blob`, `glob`, `parquet_metadata`, `parquet_schema`, `read_xlsx`, etc. — was not blocked. RBAC table-reference extraction inspected only `FROM`/`JOIN` clauses, so scalar table functions in the `SELECT` list slipped past both layers. This is fixed in 2026.06.1 via a structural sandbox at the DuckDB layer. After lockdown, DuckDB refuses to open any file outside the allowlist and refuses further `INSTALL`/`LOAD`. Already-loaded extensions remain callable. Some workarounds are available. Restrict API access to known-trusted networks via firewall rules or, as a temporary mitigation, add `read_csv*`/`read_json*`/`glob` etc. to `dangerousSQLPattern` in `internal/api/query.go`.14dCVE-2024-35690—21.6%
——6——CVE-2025-27929—21.6%
——6——CVE-2026-156634.9 MED21.6%
——6The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' Key in all versions up to, and including, 3.14.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerable keys originate from the 'settings' object in an attacker-controlled import file processed via file_get_contents() or base64-decoded/JSON-decoded blobs, bypassing wp_magic_quotes protections entirely; two distinct sinks are affected — _save_setting() in Model.php and insert_form_meta() in ImportForm.php — as only the value side is escaped while the key side receives no sanitization or parameterization at any point in the call chain.46dCVE-2026-22541—21.6%
——6——CVE-2014-6006—21.6%
——6——CVE-2023-30639—21.6%
——6——CVE-2024-270177.8 HIG21.6%
——6In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: walk over current view on netlink dump
The generation mask can be updated while netlink dump is in progress.
The pipapo set backend walk iterator cannot rely on it to infer what
view of the datastructure is to be used. Add notation to specify if user
wants to read/update the set.
Based on patch from Florian Westphal.35d