Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,152
- High7,669
- Medium5,612
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32110—19.9%
——6——CVE-2026-490924.3 MED19.9%
——6Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.30dCVE-2023-41815—19.9%
——6——CVE-2023-23530—19.9%
——6——CVE-2026-584406.8 MED19.9%
——6Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)10dCVE-2026-645988.8 HIG19.9%
——6In the Linux kernel, the following vulnerability has been resolved:
smb/client: Fix error code in smb2_aead_req_alloc()
The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work.
We would have to do something similar to the previous line where it's
cast to int and then long. However, it's simpler to store the return in
an int ret variable.
This bug would eventually result in a crash when dereference the invalid
error pointer.20dCVE-2025-4086—19.9%
——6——CVE-2025-9834—19.9%
——6——CVE-2024-34558—19.9%
——6——CVE-2026-632624.3 MED19.9%
——6Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.33dCVE-2026-606147.1 HIG19.9%
——6Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Person Data). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H).36dCVE-2023-0484—19.9%
——6——CVE-2026-72870—19.9%
——6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in packages/server/src/utils/providers/docker.ts interpolates the application-controlled dockerImage value directly into a docker pull shell command. An authenticated user with project access can set a crafted dockerImage through application.update and trigger application.deploy, causing execAsync() to execute arbitrary operating-system commands as the Dokploy server process. This issue is fixed in version 0.29.13.25dCVE-2025-63229—19.9%
——6——CVE-2025-29430—19.9%
——6——CVE-2023-1763—19.9%
——6——CVE-2026-351403.0 LOW19.9%
——6HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic and capture sensitive cookies, session tokens, or credentials sent in cleartext over unencrypted channels.50dCVE-2026-72879—19.9%
——6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/cluster/upload.ts interpolates registry.password and registry.registryUrl directly into a shell command without escaping. An authenticated user with project access can configure malicious registry credentials and trigger a swarm deployment to execute arbitrary OS commands on the Dokploy server, read or modify host files, and access other containers through Docker. This issue is fixed in version 0.29.8.25dCVE-2026-32877—19.9%
——6——CVE-2019-25280—19.9%
——6——CVE-2024-43985—19.9%
——6——CVE-2024-11610—19.9%
——6——CVE-2026-41354—19.9%
——6——CVE-2026-21694—19.9%
——6——CVE-2026-785907.3 HIG19.9%
——6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged resources such as user accounts and other organizational assets. Exploitation requires an administrator to interact with the affected Fleet interface.2dCVE-2025-22774—19.9%
——6——CVE-2025-9233—19.9%
——6——CVE-2025-13314—19.9%
——6——CVE-2026-2460—19.9%
——6——CVE-2021-47334—19.9%
——6——CVE-2025-49732—19.9%
——6——CVE-2025-8917—19.9%
——6——CVE-2023-0761—19.9%
——6——CVE-2026-26935—19.9%
——6——CVE-2023-0763—19.9%
——6——CVE-2023-0762—19.9%
——6——CVE-2025-9235—19.9%
——6——CVE-2025-3885—19.9%
——6——CVE-2024-45745—19.9%
——6——CVE-2023-43777—19.9%
——6——