Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,113
- High7,551
- Medium5,585
- Low536
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-200314.0 MED20.5%
——6A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic error that occurs when an SSL/TLS certificate that is under load is accessed when it is initiating an SSL connection. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a high rate of SSL/TLS connection requests to be inspected by the Snort 3 detection engine on an affected device. A successful exploit could allow the attacker to cause the Snort 3 detection engine to reload, resulting in either a bypass or a denial of service (DoS) condition, depending on device configuration. The Snort detection engine will restart automatically. No manual intervention is required.26dCVE-2024-45799—20.5%
——6——CVE-2025-67913—20.5%
——6——CVE-2021-21545—20.5%
——6——CVE-2026-449174.9 MED20.5%
——6OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.46dCVE-2025-14059—20.5%
——6——CVE-2025-23038—20.5%
——6——CVE-2025-9805—20.5%
——6——CVE-2025-363334.3 MED20.5%
——6IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actions due to the improper enforcement of behavioral workflow.62dCVE-2026-5187—20.5%
——6——CVE-2025-5715—20.5%
——6——CVE-2025-3744—20.5%
——6——CVE-2025-91897.8 HIG20.5%
——6There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.3dCVE-2022-21298—20.5%
——6——CVE-2023-28619—20.5%
——6——CVE-2024-42022—20.5%
——6——CVE-2026-4755—20.5%
——6——CVE-2025-63681—20.5%
——6——CVE-2026-584347.5 HIG20.5%
——6Private Repository Metadata Remains Accessible After Access Revocation11dCVE-2025-23110—20.5%
——6——CVE-2024-53046—20.5%
——6——CVE-2026-468229.9 CRI20.5%
——6Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iAssets. While the vulnerability is in Oracle iAssets, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iAssets. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).47dCVE-2026-726067.5 HIG20.5%
——6A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.9dCVE-2024-1630—20.5%
——6——CVE-2025-69319—20.5%
——6——CVE-2022-43995—20.5%
——6——CVE-2026-150795.4 MED20.5%
——6Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This issue affects Login Disable versions: from 0.0.0 to 2.1.4.31dCVE-2023-52553—20.5%
——6——CVE-2026-49780—20.5%
——6——CVE-2026-618928.8 HIG20.5%
——6Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.38dCVE-2026-760738.8 HIG20.5%
——6Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and label_studio/core/permissions.py registers every permission with rules.is_authenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with project__organization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file.13dCVE-2019-16149—20.5%
——6——CVE-2024-34129—20.5%
——6——CVE-2025-23031—20.5%
——6——CVE-2026-30231—20.5%
——6——CVE-2025-1891—20.5%
——6——CVE-2026-138286.5 MED20.5%
——6Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)67dCVE-2025-22614—20.5%
——6——CVE-2026-42239—20.5%
——6——CVE-2024-37661—20.5%
——6——