Vulnerabilities exploitable today
369,271in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,152
- High7,655
- Medium5,617
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-25804—20.1%
——6——CVE-2026-417105.9 MED20.1%
——6An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail.
Affected versions:
Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.2dCVE-2024-42342—20.1%
——6——CVE-2026-12580—20.1%
——6——CVE-2025-49240—20.1%
——6——CVE-2024-45601—20.1%
——6——CVE-2022-50848—20.1%
——6——CVE-2018-11748—20.1%
——6——CVE-2024-1803—20.1%
——6——CVE-2022-49713—20.1%
——6——CVE-2024-37350—20.1%
——6——CVE-2025-25082—20.1%
——6——CVE-2025-7789—20.1%
——6——CVE-2026-164419.6 CRI20.1%
——6In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.19dCVE-2022-50840—20.1%
——6——CVE-1999-1425—20.1%
——6——CVE-2025-30269—20.1%
——6——CVE-2021-1386—20.1%
——6——CVE-2024-8437—20.1%
——6——CVE-2025-3487—20.1%
——6——CVE-2026-480742.7 LOW20.1%
——6OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table by email. The `email` clause has no `tenantId` predicate. Any pending invite in any tenant that shares the deleted staff's email is removed. A TENANT_ADMIN of tenant A who deletes a staff record with email `victim[@]example[.]com` also deletes the pending invite for `victim[@]example[.]com` in tenant B, even though they have no relationship to tenant B. The user-side delete is correctly scoped (`eq(user.id, staffId), eq(user.tenantId, tenantId)`), and the pending-invite-only delete path (when `staffId` is itself an invite ID) is also tenant-scoped. The bug is specifically in the invite cleanup that runs as a side effect of deleting an existing staff user. Version 1.0.6 patches the issue.30dCVE-2024-6198—20.1%
——6——CVE-2025-11959—20.1%
——6——CVE-2025-48379—20.1%
——6——CVE-2025-25079—20.1%
——6——CVE-2025-25097—20.1%
——6——CVE-2023-45909—20.1%
——6——CVE-2022-49412—20.1%
——6——CVE-2023-26980—20.1%
——6——CVE-2025-63664—20.1%
——6——CVE-2025-46256—20.1%
——6——CVE-2022-49707—20.1%
——6——CVE-2025-27792—20.1%
——6——CVE-2026-62315—20.1%
——6Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into individual field names. An authenticated caller can exploit this type confusion to mass-assign protected fields through the client endpoint. No released fixed version is available as of this review.17dCVE-2026-748816.5 MED20.1%
——6openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.20dCVE-2025-47094—20.1%
——6——CVE-2025-62040—20.1%
——6——CVE-2008-4990—20.1%
——6——CVE-2025-25076—20.1%
——6——CVE-2024-9626—20.1%
——6——