Vulnerabilities exploitable today
368,587in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,204
- High7,824
- Medium5,620
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-134753.5 LOW19.4%
——6In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing.
This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy.57dCVE-2024-21253—19.4%
——6——CVE-2025-15451—19.4%
——6——CVE-2026-769287.5 HIG19.4%
——6X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service4dCVE-2024-37433—19.4%
——6——CVE-2016-6156—19.4%
——6——CVE-2021-1755—19.4%
——6——CVE-2025-30719—19.4%
——6——CVE-2025-63068—19.4%
——6——CVE-2023-1032—19.4%
——6——CVE-2022-44937—19.4%
——6——CVE-2014-3940—19.4%
——6——CVE-2026-24440—19.4%
——6——CVE-2025-607307.6 HIG19.4%
——6PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function61dCVE-2026-31464—19.4%
——6——CVE-2024-44060—19.4%
——6——CVE-2026-44407—19.4%
——6——CVE-2026-468347.5 HIG19.4%
——6Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).45dCVE-2026-453776.5 MED19.4%
——6Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without authentication by anyone who obtains it. This is because Decidim::DownloadYourDataController#download_file authenticates the export owner but redirects to a signed Active Storage blob URL that is no longer bound to the owner session. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.34dCVE-2025-46861—19.4%
——6——CVE-2026-481457.5 HIG19.4%
——6Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.38dCVE-2026-733909.8 CRI19.4%
——6Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.15dCVE-2026-34944.3 MED19.4%
——6In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.52dCVE-2025-46879—19.4%
——6——CVE-2026-743408.1 HIG19.4%
——6In the Linux kernel, the following vulnerability has been resolved:
wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
The firmware-controlled rsp->count field is used as the loop bound for
indexing into the flexible rsp->regs[] array without validation against
the message length. A count exceeding the actual data causes out-of-
bounds reads from the heap-allocated message buffer.
Add a check that count fits within the received message.18dCVE-2025-46866—19.4%
——6——CVE-2014-125128—19.4%
——6——CVE-2026-6562—19.4%
——6——CVE-2025-46876—19.4%
——6——CVE-2026-22203—19.4%
——6——CVE-2026-25925—19.4%
——6——CVE-2023-45898—19.4%
——6——CVE-2024-23831—19.4%
——6——CVE-2026-592875.9 MED19.4%
——6Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.3.0 - 1.3.92dCVE-2024-48843—19.4%
——6——CVE-2025-46878—19.4%
——6——CVE-2023-41072—19.4%
——6——CVE-2025-46862—19.4%
——6——CVE-2024-47136—19.4%
——6——CVE-2025-48067—19.4%
——6——