Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,385
- High9,631
- Medium5,583
- Low549
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-0055—18.8%
——6——CVE-2012-3500—18.8%
——6——CVE-2024-43189—18.8%
——6——CVE-2022-46489—18.8%
——6——CVE-2026-0484—18.8%
——6——CVE-2022-496437.1 HIG18.8%
——6In the Linux kernel, the following vulnerability has been resolved:
ima: Fix a potential integer overflow in ima_appraise_measurement
When the ima-modsig is enabled, the rc passed to evm_verifyxattr() may be
negative, which may cause the integer overflow problem.29dCVE-2026-347179.9 CRI18.8%
——6OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has been patched in version 17.2.3.40dCVE-2025-55268—18.8%
——6——CVE-2026-212694.6 MED18.8%
——6is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.6dCVE-2026-610136.6 MED18.8%
——6Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).30dCVE-2023-23586—18.8%
——6——CVE-2023-2497—18.8%
——6——CVE-2026-56073—18.8%
——6——CVE-2026-51292—18.8%
——6Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.33dCVE-2023-48778—18.8%
——6——CVE-2026-9267—18.8%
——6——CVE-2023-51545—18.8%
——6——CVE-2025-15235—18.8%
——6——CVE-2026-660278.3 HIG18.8%
——6Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's session queue, causing the background drainer to forward malicious messages to the victim's running AI agent with the victim's credentials and permissions.34dCVE-2026-27935—18.8%
——6——CVE-2024-57240—18.8%
——6——CVE-2022-27855—18.8%
——6——CVE-2024-26741—18.8%
——6——CVE-2026-92128.0 HIG18.8%
——6Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.41dCVE-2023-49821—18.8%
——6——CVE-2026-706055.9 MED18.8%
——6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.27dCVE-2026-44714—18.8%
——6——CVE-2025-62483—18.8%
——6——CVE-2024-52478—18.8%
——6——CVE-2024-9744—18.8%
——6——CVE-2025-5198—18.8%
——6——CVE-2026-490946.5 MED18.8%
——6Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume excessive CPU and memory resources while processing the request. This results in Kibana becoming unavailable to all users until the service is manually recovered.43dCVE-2022-49249—18.8%
——6——CVE-2023-40696—18.8%
——6——CVE-2025-68036—18.8%
——6——CVE-2025-53880—18.8%
——6——CVE-2026-97476.5 MED18.8%
——6Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.41dCVE-2025-64277—18.8%
——6——CVE-2022-43481—18.8%
——6——CVE-2025-14977—18.8%
——6——