Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,289
- High9,343
- Medium5,276
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-46876—16.3%
——5——CVE-2026-481449.1 CRI16.3%
——5Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.33dCVE-2026-2101—16.3%
——5——CVE-2024-44178—16.3%
——5——CVE-2026-429847.0 HIG16.3%
——5Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.38dCVE-2025-46846—16.3%
——5——CVE-2025-26962—16.3%
——5——CVE-2021-47387—16.3%
——5——CVE-2018-11864—16.3%
——5——CVE-2017-18309—16.3%
——5——CVE-2021-47542—16.3%
——5——CVE-2023-1838—16.3%
——5——CVE-2025-43806—16.3%
——5——CVE-2022-4102—16.3%
——5——CVE-2025-26912—16.3%
——5——CVE-2018-7946—16.3%
——5——CVE-2019-25448—16.3%
——5——CVE-2026-733014.3 MED16.3%
——5Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and default-group flags. The disclosure exposes the tenant access-control structure to users who are not builders or administrators. This issue is fixed in version 3.39.25.15dCVE-2025-46438—16.3%
——5——CVE-2025-46861—16.3%
——5——CVE-2024-45552—16.3%
——5——CVE-2025-26939—16.3%
——5——CVE-2023-37520—16.3%
——5——CVE-2018-11820—16.3%
——5——CVE-2025-3228—16.3%
——5——CVE-2023-30641—16.3%
——5——CVE-2025-46479—16.3%
——5——CVE-2026-166125.3 MED16.3%
——5The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.6dCVE-2026-40762—16.3%
——5——CVE-2024-13779—16.3%
——5——CVE-2025-59021—16.3%
——5——CVE-2023-52730—16.3%
——5——CVE-2023-6533—16.3%
——5——CVE-2026-476658.7 HIG16.3%
——5Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any team member who can comment on a shared file can embed HTML such as an image error handler or script that executes in the browser of every other collaborator. The attack is passive: any user who opens the comments panel on the affected file triggers script execution on the Penpot origin, allowing theft of session cookies, actions performed as the victim, and access to their files and projects. This issue is fixed in version 2.15.3.2dCVE-2026-605756.3 MED16.3%
——5Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).22dCVE-2026-451214.3 MED16.3%
——5MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in calendar.php perform permission checks against an invalid calendar context before returning calendar titles. The uniquely identifying implementation details include titles of inaccessible calendars, and invalid calendar permission context. This issue is fixed in version 1.8.40.11dCVE-2021-4212—16.3%
——5——CVE-2025-46864—16.3%
——5——CVE-2023-22357.8 HIG16.3%
——5A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation.
The perf_group_detach function did not check the event's siblings' attach_state before calling add_event_to_groups(), but remove_on_exec made it possible to call list_del_event() on before detaching from their group, making it possible to use a dangling pointer causing a use-after-free vulnerability.
We recommend upgrading past commit fd0815f632c24878e325821943edccc7fde947a2.22dCVE-2025-36589—16.3%
——5——