Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6338—16.5%
——5——CVE-2024-34828—16.5%
——5——CVE-2026-7407—16.5%
——5——CVE-2026-77780—16.5%
——5Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus
Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting
creation permissions to disclose another company's bank account name, bank name and card
last four digits via a bank_account_id or bank_card_id belonging to that company in POST
/transaction/save, which is persisted and rendered without any company ownership check.8dCVE-2022-4013—16.5%
——5——CVE-2026-4449—16.5%
——5——CVE-2026-4451—16.5%
——5——CVE-2025-379738.1 HIG16.5%
——5In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
Currently during the multi-link element defragmentation process, the
multi-link element length added to the total IEs length when calculating
the length of remaining IEs after the multi-link element in
cfg80211_defrag_mle(). This could lead to out-of-bounds access if the
multi-link element or its corresponding fragment elements are the last
elements in the IEs buffer.
To address this issue, correctly calculate the remaining IEs length by
deducting the multi-link element end offset from total IEs end offset.31dCVE-2024-2496—16.5%
——5——CVE-2026-44425—16.5%
——5——CVE-2026-1727—16.5%
——5——CVE-2025-10943—16.5%
——5——CVE-2026-93347.3 HIG16.5%
——5Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled.
decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV (old_value)) != SVt_PVAV`, which evaluates SvRV(old_value) before establishing that old_value is a reference. When the existing value is a plain scalar rather than an array reference, a non-reference scalar is dereferenced as a reference.
A caller decoding untrusted JSON with dupkeys_as_arrayref enabled is crashed, and the incompatible access follows a pointer taken from attacker controlled scalar contents.39dCVE-2026-30404—16.5%
——5——CVE-2026-657996.7 MED16.5%
——5Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.12dCVE-2026-47346—16.5%
——5Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.38dCVE-2020-12903—16.5%
——5——CVE-2022-4139—16.5%
——5——CVE-2022-341097.1 HIG16.5%
——5An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.52dCVE-2026-601884.4 MED16.5%
——5Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).33dCVE-2025-9459—16.5%
——5——CVE-2026-624337.3 HIG16.5%
——5Parts of the DM_OP handling code assumes the caller has provided the
required number of buffers for the given operation without any checking
being done. As a result, certain operations might access stack
rubble as structures are possibly uninitialized.32dCVE-2026-32516—16.5%
——5——CVE-2026-4454—16.5%
——5——CVE-2026-632318.1 HIG16.5%
——5A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.30dCVE-2026-673545.9 MED16.5%
——5guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value.26dCVE-2023-4389—16.5%
——5——CVE-2025-3905—16.5%
——5——CVE-2025-54235—16.4%
——5——CVE-2025-47053—16.4%
——5——CVE-2026-26165—16.5%
——5——CVE-2025-13558—16.5%
——5——CVE-2024-53168—16.5%
——5——CVE-2025-13741—16.5%
——5——CVE-2025-51818—16.5%
——5——CVE-2022-49128—16.5%
——5——CVE-2020-37003—16.5%
——5——CVE-2024-26754—16.5%
——5——CVE-2023-27933—16.5%
——5——CVE-2025-9522—16.5%
——5——