Vulnerabilities exploitable today
369,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,150
- High7,652
- Medium5,617
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-541297.0 HIG20.0%
——6Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.45dCVE-2024-56349—20.0%
——6——CVE-2025-70797—20.0%
——6——CVE-2026-43506—20.0%
——6——CVE-2026-19869—20.0%
——6@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. When both a type-level @authentication (on Query/Mutation) and a field-level @authentication (on a root custom-resolver field within that type) are declared, only the type-level rule is evaluated and the field-level rule is silently discarded. As a result a stricter per-field requirement — such as an admin-role JWT claim (jwt: { roles_INCLUDES: "admin" }) — is never checked, and any client that satisfies the coarser type-level requirement can invoke the more-restricted field. No token forgery is involved: a legitimately issued, correctly signed non-admin token (e.g. roles: ["user"]) is sufficient.18dCVE-2026-503597.0 HIG20.0%
——6Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.45dCVE-2025-9799—20.0%
——6——CVE-2026-164079.8 CRI20.0%
——6Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.43dCVE-2026-503587.0 HIG20.0%
——6Use after free in Windows Media allows an authorized attacker to elevate privileges locally.45dCVE-2024-511126.1 MED20.0%
——6Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script63dCVE-2026-504907.0 HIG20.0%
——6Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.45dCVE-2026-549897.0 HIG20.0%
——6Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.45dCVE-2025-13738—20.0%
——6——CVE-2026-32322—20.0%
——6——CVE-2026-561877.0 HIG20.0%
——6Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.45dCVE-2026-394667.6 HIG20.0%
——6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.43dCVE-2019-17343—20.0%
——6——CVE-2025-23024—20.0%
——6——CVE-2025-8507—20.0%
——6——CVE-2026-6445—20.0%
——6A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.45dCVE-2025-5244—20.0%
——6——CVE-2023-52930—20.0%
——6——CVE-2026-6444—20.0%
——6A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.45dCVE-2025-65109—20.0%
——6——CVE-2026-34874—20.0%
——6——CVE-2026-1985—20.0%
——6——CVE-2024-52917—20.0%
——6——CVE-2026-708097.1 HIG20.0%
——6Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scripting. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).9dCVE-2024-26988—20.0%
——6——CVE-2024-50441—20.0%
——6——CVE-2026-663116.2 MED20.0%
——6Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.30dCVE-2022-47935—20.0%
——6——CVE-2022-50937—20.0%
——6——CVE-2025-7871—20.0%
——6——CVE-2026-6561—20.0%
——6——CVE-2026-32711—20.0%
——6——CVE-2026-41416—20.0%
——6——CVE-2026-570937.0 HIG20.0%
——6Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.45dCVE-2025-5245—20.0%
——6——CVE-2026-504917.0 HIG20.0%
——6Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.45d