Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,171
- High7,801
- Medium5,697
- Low540
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58222—19.7%
——6——CVE-2023-48653—19.7%
——6——CVE-2026-41219—19.7%
——6——CVE-2023-32240—19.7%
——6——CVE-2024-54113—19.7%
——6——CVE-2021-34577—19.7%
——6——CVE-2025-8879—19.7%
——6——CVE-2026-763436.5 MED19.7%
——6In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute attacker-chosen Structured Query Language (SQL) queries through the Data Orchestration jobs endpoint, allowing for access to substantially all data stored by Data Orchestration, including jobs owned by other users and stored connection credentials. The vulnerability is possible because Data Orchestration builds a database query from user-controlled job filter values without using parameterized queries. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.15dCVE-2021-33096—19.7%
——6——CVE-2015-10147—19.7%
——6——CVE-2026-848884.3 MED19.7%
——6A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory allocation. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-20691—19.7%
——6——CVE-2025-32056—19.7%
——6——CVE-2026-44732—19.7%
——6——CVE-2026-3621—19.7%
——6——CVE-2026-801955.4 MED19.7%
——6Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can submit a malformed members payload; although Kimai returns a validation error, the existing membership rows have already been deleted. This bypasses the dedicated member-removal endpoint's protection against removing teamleaders and can leave a team with no members or teamleaders, disrupting team-based access control.2dCVE-2020-28209—19.7%
——6——CVE-2022-49395—19.7%
——6——CVE-2024-27593—19.7%
——6——CVE-2023-29569—19.7%
——6——CVE-2026-102696.3 MED19.7%
——6A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 0.4.1 is capable of addressing this issue. The identifier of the patch is 428e2c045cb9c0eb8080e8b580471a9c2eaa95ca. Upgrading the affected component is recommended.45dCVE-2009-2135—19.7%
——6——CVE-2025-66116—19.7%
——6——CVE-2022-39948—19.7%
——6——CVE-2026-25418—19.7%
——6——CVE-2025-9947—19.7%
——6——CVE-2024-28781—19.7%
——6——CVE-2022-47155—19.7%
——6——CVE-2026-101144.3 MED19.7%
——6A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. To fix this issue, it is recommended to deploy a patch.45dCVE-2026-4738—19.7%
——6——CVE-2021-27243—19.7%
——6——CVE-2026-53726—19.7%
——6——CVE-2025-14941—19.7%
——6——CVE-2010-0769—19.7%
——6——CVE-2024-44051—19.7%
——6——CVE-2024-37176—19.7%
——6——CVE-2026-7708—19.7%
——6——CVE-2026-481085.3 MED19.7%
——6Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-banner lines from clients, and the reader did not enforce a bounded number of pre-banner lines. For a library server built on russh, this could allow a remote peer to hold connection setup resources in the cleartext pre-authentication phase with malformed identification input that should have been rejected early. This issue has been patched in version 0.61.0.44dCVE-2023-48651—19.7%
——6——CVE-2024-45289—19.7%
——6——