Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,639
- Medium5,592
- Low549
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6393—18.8%
——6——CVE-2026-398797.1 HIG18.8%
——6Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.841dCVE-2025-23384—18.8%
——6——CVE-2024-53589—18.8%
——6——CVE-2021-33074—18.8%
——6——CVE-2026-92128.0 HIG18.8%
——6Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain configurations.41dCVE-2026-706055.9 MED18.8%
——6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.27dCVE-2023-48778—18.8%
——6——CVE-2023-2497—18.8%
——6——CVE-2023-49821—18.8%
——6——CVE-2026-51292—18.8%
——6Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.33dCVE-2026-9267—18.8%
——6——CVE-2012-3500—18.8%
——6——CVE-2024-43189—18.8%
——6——CVE-2025-55268—18.8%
——6——CVE-2026-347179.9 CRI18.8%
——6OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/reporting/lib/report/operator.rb:177 embeds user input directly into SQL WHERE clauses without parameterization. This issue has been patched in version 17.2.3.40dCVE-2025-682547.1 HIG18.8%
——6In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
The Extended Supported Rates (ESR) IE handling in OnBeacon accessed
*(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these
offsets lie within the received frame buffer. A malformed beacon with
an ESR IE positioned at the end of the buffer could cause an
out-of-bounds read, potentially triggering a kernel panic.
Add a boundary check to ensure that the ESR IE body and the subsequent
bytes are within the limits of the frame before attempting to access
them.
This prevents OOB reads caused by malformed beacon frames.34dCVE-2024-13721—18.8%
——6——CVE-2025-1450—18.8%
——6——CVE-2025-15344—18.8%
——6——CVE-2020-6295—18.8%
——6——CVE-2008-5182—18.8%
——6——CVE-2025-12391—18.8%
——6——CVE-2026-45399—18.8%
——6——CVE-2026-201558.0 HIG18.8%
——6A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.
This vulnerability is due to improper authorization checks on a REST API endpoint of an affected device. An attacker could exploit this vulnerability by querying the affected endpoint. A successful exploit could allow the attacker to view session information of active Cisco EPNM users, including users with administrative privileges, which could result in the affected device being compromised.62dCVE-2026-97496.5 MED18.8%
——6This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buffer (that is, many results are routed to the same consumer), the server reaches the code path where a full per-consumer buffer is detected but the internal "high watermark" for that key range is not updated as intended.41dCVE-2025-12093—18.8%
——6——CVE-2023-47230—18.8%
——6——CVE-2025-29004—18.8%
——6——CVE-2025-9987—18.8%
——6——CVE-2024-49667—18.8%
——6——CVE-2023-47542—18.8%
——6——CVE-2021-34986—18.8%
——6——CVE-2019-4591—18.8%
——6——CVE-2024-9736—18.8%
——6——CVE-2025-8992—18.8%
——6——CVE-2023-49759—18.8%
——6——CVE-2022-49711—18.8%
——6——CVE-2022-46490—18.8%
——6——CVE-2024-26753—18.8%
——6——