Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,112
- High7,546
- Medium5,584
- Low536
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-55223—20.6%
——6c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them as "properties" assumed safe while they actually call into JDBC drivers. Attackers can thus craft malicious DataSource objects whose property lookups invoke vulnerable drivers, then smuggle them in serialized form to where an application deserializes and auto-resolves bean properties — triggering the attack. This requires a susceptible DataSource/ConnectionPoolDataSource and JDBC driver on the CLASSPATH, plus a carrier that auto-looks-up JavaBean properties on = deserialization, most commonly a collection paired with an Apache commons-beanutils Comparator that sorts by bean properties. c3p0 supplied that susceptible DataSource/ConnectionPoolDataSource, which was an essential component of the trigger. This issue has been fixed in version 0.14.0.66dCVE-2025-0678—20.6%
——6——CVE-2025-13970—20.6%
——6——CVE-2026-122734.3 MED20.6%
——6The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and stores the comment pre-approved, allowing authenticated users with subscriber-level access and above to post auto-approved comments containing arbitrary HTML and links on any content across the site, bypassing the comment moderation queue.55dCVE-2021-28692—20.6%
——6——CVE-2026-8032—20.6%
——6——CVE-2025-69654—20.6%
——6——CVE-2026-109816.5 MED20.6%
——6Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted video file. (Chromium security severity: High)46dCVE-2026-2484—20.6%
——6——CVE-2007-3931—20.6%
——6——CVE-2024-21617—20.6%
——6——CVE-2025-24967—20.6%
——6——CVE-2023-45863—20.6%
——6——CVE-2025-59968—20.6%
——6——CVE-2024-44117—20.5%
——6——CVE-2024-46239—20.6%
——6——CVE-2021-46759—20.6%
——6——CVE-2025-6574—20.6%
——6——CVE-2017-13094—20.6%
——6——CVE-2024-24939—20.6%
——6——CVE-1999-0483—20.6%
——6——CVE-2025-43556—20.6%
——6——CVE-2017-18777—20.6%
——6——CVE-2025-55574—20.6%
——6——CVE-2026-41250—20.6%
——6——CVE-2026-26269—20.6%
——6——CVE-2026-394104.8 MED20.6%
——6Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.44dCVE-2023-40419—20.6%
——6——CVE-2026-21684—20.6%
——6——CVE-2020-59537.5 HIG20.6%
——6A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).26dCVE-2026-191179.8 CRI20.6%
——6Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
that user. This issue affects on-premises deployments only.3dCVE-2023-37210—20.6%
——6——CVE-2023-28497—20.6%
——6——CVE-2025-24452—20.6%
——6——CVE-2026-30269—20.6%
——6——CVE-2026-26887—20.6%
——6——CVE-2024-369787.8 HIG20.6%
——6In the Linux kernel, the following vulnerability has been resolved:
net: sched: sch_multiq: fix possible OOB write in multiq_tune()
q->bands will be assigned to qopt->bands to execute subsequent code logic
after kmalloc. So the old q->bands should not be used in kmalloc.
Otherwise, an out-of-bounds write will occur.33dCVE-2024-40903—20.6%
——6——CVE-2022-50664—20.6%
——6——CVE-2023-5846—20.6%
——6——