Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-21732—21.0%
——6——CVE-2026-25875—21.0%
——6——CVE-2026-561166.5 MED21.0%
——6dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash.55dCVE-2026-782027.3 HIG21.0%
——6A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.14dCVE-2024-21263—21.0%
——6——CVE-2023-36623—21.0%
——6——CVE-2024-41728—21.0%
——6——CVE-2022-23700—21.0%
——6——CVE-2025-27417—21.0%
——6——CVE-2025-27499—21.0%
——6——CVE-2018-3691—21.0%
——6——CVE-2025-30187—21.0%
——6——CVE-2026-31626—21.0%
——6——CVE-2026-40905—21.0%
——6——CVE-2026-13023—21.0%
——6——CVE-2024-11757—21.0%
——6——CVE-2024-11781—21.0%
——6——CVE-2026-64964—21.0%
——6ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable values related to user registration, an attacker who knows or can predict these values can guess valid account activation tokens. This allows an attacker to activate an unconfirmed account without access to the victim's email inbox.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.10dCVE-2025-3942—21.0%
——6——CVE-2025-4947—21.0%
——6——CVE-2025-30607—21.0%
——6——CVE-2022-49377—21.0%
——6——CVE-2022-49426—21.0%
——6——CVE-2026-608707.1 HIG21.0%
——6Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).40dCVE-2023-43065—21.0%
——6——CVE-2026-139695.3 MED21.0%
——6Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)68dCVE-2026-27567—21.0%
——6——CVE-2025-48534—21.0%
——6——CVE-2022-49444—21.0%
——6——CVE-2026-53476—21.0%
——6——CVE-2026-847528.8 HIG21.0%
——6Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.4dCVE-2025-62289—21.0%
——6——CVE-2026-172644.3 MED21.0%
——6Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.31dCVE-2022-49509—21.0%
——6——CVE-2025-31420—21.0%
——6——CVE-2025-31468—21.0%
——6——CVE-2023-26840—21.0%
——6——CVE-2013-1945—21.0%
——6——CVE-2024-45770—21.0%
——6——CVE-2026-153514.9 MED21.0%
——6The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to generic SQL Injection via the 'status' parameter in all versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The sanitize_text_field callback strips HTML but leaves SQL metacharacters intact, and wp_magic_quotes slash protection does not apply because WP_REST_Server::serve_request() calls wp_unslash() on GET parameters before the sanitize callback executes.18d