Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-8933—21.4%
——6——CVE-2025-11442—21.4%
——6——CVE-2024-31160—21.4%
——6——CVE-2023-24754—21.4%
——6——CVE-2026-54445—21.4%
——6——CVE-2025-52583—21.4%
——6——CVE-2026-478755.6 MED21.4%
——6Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets.
Spring Batch 6.0.0 - 6.0.4
Spring Batch 5.2.0 - 5.2.66dCVE-2023-52069—21.4%
——6——CVE-2021-39919—21.4%
——6——CVE-2024-8328—21.4%
——6——CVE-2025-48274—21.4%
——6——CVE-2023-24752—21.4%
——6——CVE-2014-7008—21.4%
——6——CVE-2026-34225—21.4%
——6——CVE-2026-79991—21.4%
——6Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely — an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.5dCVE-2024-13378—21.4%
——6——CVE-2024-48897—21.4%
——6——CVE-2025-5180—21.4%
——6——CVE-2014-6902—21.4%
——6——CVE-2025-713816.5 MED21.4%
——6Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker can supply arbitrary Vary values that are reflected into the response, potentially causing cache key pollution and inconsistent CORS enforcement in environments that rely on shared caches or proxies.68dCVE-2023-24755—21.4%
——6——CVE-2014-6932—21.4%
——6——CVE-2024-25801—21.4%
——6——CVE-2017-1760—21.4%
——6——CVE-2014-6845—21.4%
——6——CVE-2014-7050—21.4%
——6——CVE-2014-7010—21.4%
——6——CVE-2026-491919.8 CRI21.4%
——6The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.48dCVE-2024-270737.8 HIG21.4%
——6In the Linux kernel, the following vulnerability has been resolved:
media: ttpci: fix two memleaks in budget_av_attach
When saa7146_register_device and saa7146_vv_init fails, budget_av_attach
should free the resources it allocates, like the error-handling of
ttpci_budget_init does. Besides, there are two fixme comment refers to
such deallocations.35dCVE-2014-6896—21.4%
——6——CVE-2025-0971—21.4%
——6——CVE-2021-33294—21.4%
——6——CVE-2014-6832—21.4%
——6——CVE-2025-14806—21.4%
——6——CVE-2014-7011—21.4%
——6——CVE-2025-61312—21.4%
——6——CVE-2026-135936.5 MED21.4%
——6CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away.
The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and whitespace.70dCVE-2025-69431—21.4%
——6——CVE-2025-32260—21.4%
——6——CVE-2024-39326—21.4%
——6——