Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,158
- High7,687
- Medium5,628
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20205—19.9%
——6——CVE-2019-14477—19.9%
——6——CVE-2024-36406—19.9%
——6——CVE-2024-52998—19.9%
——6——CVE-2020-10636—19.9%
——6——CVE-2025-49419—19.9%
——6——CVE-2026-139316.5 MED19.9%
——6Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)66dCVE-2024-39242—19.9%
——6——CVE-2026-709075.3 MED19.9%
——6Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).16dCVE-2024-52919—19.9%
——6——CVE-2025-65296—19.9%
——6——CVE-2025-15578—19.9%
——6——CVE-2018-11861—19.9%
——6——CVE-2026-47182—19.9%
——6——CVE-2019-3588—19.9%
——6——CVE-2023-41980—19.9%
——6——CVE-2025-24443—19.9%
——6——CVE-2026-471307.1 HIG19.9%
——6NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user has ownership of the specific resource being modified. This allows any authenticated user (even with a standard `member` role) to arbitrarily modify sensitive CRM contacts and targets belonging to other users or organizations (cross-tenant data tampering). Version 0.12.0 fixes the issue.45dCVE-2022-34893—19.9%
——6——CVE-2026-32326—19.9%
——6——CVE-2022-49546—19.9%
——6——CVE-2026-637614.3 MED19.9%
——6SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384 without any error, warning, or log message. Users who supply the correct P-521 key for ES512 experience authentication handshake failures due to the curve mismatch with ES384 (which expects P-384), and tokens are rejected by external systems expecting genuine ES512 signatures. The flaw cannot be used to forge tokens or compromise data confidentiality or integrity, as ES384 remains cryptographically strong.45dCVE-2026-281118.8 HIG19.9%
——6Contributor Privilege Escalation in Forminator <= 1.56.0 versions.24dCVE-2025-10748—19.9%
——6——CVE-2018-4051—19.9%
——6——CVE-2026-28827—19.9%
——6——CVE-2020-1836—19.9%
——6——CVE-2010-1973—19.9%
——6——CVE-2026-392756.1 MED19.9%
——6Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components5dCVE-2026-163658.8 HIG19.9%
——6Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.4dCVE-2025-57731—19.9%
——6——CVE-2026-607588.5 HIG19.9%
——6Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions that are affected are 25.12-26.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Artificial Intelligence. While the vulnerability is in Siebel Artificial Intelligence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel Artificial Intelligence accessible data as well as unauthorized update, insert or delete access to some of Siebel Artificial Intelligence accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).1dCVE-2024-26283—19.9%
——6——CVE-2025-5480—19.9%
——6——CVE-2026-44975—19.9%
——6——CVE-2024-39585—19.9%
——6——CVE-2025-14201—19.9%
——6——CVE-2025-7106—19.9%
——6——CVE-2023-32538—19.9%
——6——CVE-2026-646238.6 HIG19.9%
——6Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.44d