Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,639
- Medium5,592
- Low549
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-97526.5 MED18.8%
——6An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.
Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.41dCVE-2026-44957—18.8%
——6——CVE-2026-26940—18.8%
——6——CVE-2026-607446.8 MED18.8%
——6Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).36dCVE-2025-66070—18.8%
——6——CVE-2025-32383—18.8%
——6——CVE-2026-39324—18.8%
——6——CVE-2022-49556—18.8%
——6——CVE-2022-45386—18.8%
——6——CVE-2024-12592—18.8%
——6——CVE-2026-34913—18.8%
——6——CVE-2025-11999—18.8%
——6——CVE-2024-23794—18.8%
——6——CVE-2026-97466.5 MED18.8%
——6When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user must be logged in to issue the statement.41dCVE-2025-12157—18.8%
——6——CVE-2023-37644—18.8%
——6——CVE-2022-42861—18.8%
——6——CVE-2024-8682—18.8%
——6——CVE-2022-49236—18.8%
——6——CVE-2026-97476.5 MED18.8%
——6Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.41dCVE-2022-49249—18.8%
——6——CVE-2025-64277—18.8%
——6——CVE-2022-43481—18.8%
——6——CVE-2025-53880—18.8%
——6——CVE-2026-490946.5 MED18.8%
——6Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint. Kibana will consume excessive CPU and memory resources while processing the request. This results in Kibana becoming unavailable to all users until the service is manually recovered.43dCVE-2023-40696—18.8%
——6——CVE-2023-49163—18.8%
——6——CVE-2022-32587—18.8%
——6——CVE-2022-49182—18.8%
——6——CVE-2020-4874—18.8%
——6——CVE-2025-13386—18.8%
——6——CVE-2025-0955—18.8%
——6——CVE-2025-68036—18.8%
——6——CVE-2026-491347.1 HIG18.8%
——6CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell payload into it, and executes it with administrator privileges via bash, allowing a same-user local process to rewrite the installer body before the administrator prompt is approved, causing attacker-controlled commands to run as root.42dCVE-2025-11269—18.8%
——6——CVE-2024-11764—18.8%
——6——CVE-2025-14977—18.8%
——6——CVE-2024-8847—18.8%
——6——CVE-2023-52200—18.8%
——6——CVE-2017-18224—18.8%
——6——