Vulnerabilities exploitable today
369,447in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,103
- High7,551
- Medium5,627
- Low543
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-11785—21.0%
——6——CVE-2022-20915—21.0%
——6——CVE-2025-30611—21.0%
——6——CVE-2026-34445—21.0%
——6——CVE-2025-62109—21.0%
——6——CVE-2025-31573—21.0%
——6——CVE-2025-440898.8 HIG21.0%
——6An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.45dCVE-2014-3426—21.0%
——6——CVE-2020-4889—21.0%
——6——CVE-2026-22834.9 MED21.0%
——6The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable on multisite installations.18dCVE-2026-609087.1 HIG21.0%
——6Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Installed Base accessible data as well as unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).25dCVE-2026-193058.6 HIG21.0%
——6IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.3dCVE-2020-18464—21.0%
——6——CVE-2025-31536—21.0%
——6——CVE-2026-13030—21.0%
——6——CVE-2024-21108—21.0%
——6——CVE-2025-31467—21.0%
——6——CVE-2026-53508—21.0%
——6——CVE-2025-31582—21.0%
——6——CVE-2025-71006—21.0%
——6——CVE-2014-3425—21.0%
——6——CVE-2026-32097—21.0%
——6——CVE-2026-32046—21.0%
——6——CVE-2026-139705.3 MED21.0%
——6Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)68dCVE-2023-29182—21.0%
——6——CVE-2026-2393—21.0%
——6——CVE-2026-411154.3 MED21.0%
——6An improper authorization vulnerability has been identified in Apache Kafka.
The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata.
The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.47dCVE-2023-31974—21.0%
——6——CVE-2022-49696—21.0%
——6——CVE-2024-40812—21.0%
——6——CVE-2021-34692—21.0%
——6——CVE-2024-49529—21.0%
——6——CVE-2025-30858—21.0%
——6——CVE-2024-9964—21.0%
——6——CVE-2025-8521—21.0%
——6——CVE-2025-31626—21.0%
——6——CVE-2026-0109—21.0%
——6——CVE-2018-10098—21.0%
——6——CVE-2025-4085—21.0%
——6——CVE-2024-11882—21.0%
——6——