Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,290
- High9,402
- Medium5,304
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1396—16.2%
——5——CVE-2026-1005—16.2%
——5——CVE-2025-134797.5 HIG16.2%
——5Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers.
This issue affects QR Menu: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.37dCVE-2025-66124—16.2%
——5——CVE-2025-61539—16.2%
——5——CVE-2023-53841—16.2%
——5——CVE-2023-338545.3 MED16.2%
——5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.60dCVE-2025-15052—16.2%
——5——CVE-2026-331676.1 MED16.2%
——5Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.17dCVE-2023-48751—16.2%
——5——CVE-2026-164069.1 CRI16.2%
——5Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.38dCVE-2023-528377.8 HIG16.2%
——5In the Linux kernel, the following vulnerability has been resolved:
nbd: fix uaf in nbd_open
Commit 4af5f2e03013 ("nbd: use blk_mq_alloc_disk and
blk_cleanup_disk") cleans up disk by blk_cleanup_disk() and it won't set
disk->private_data as NULL as before. UAF may be triggered in nbd_open()
if someone tries to open nbd device right after nbd_put() since nbd has
been free in nbd_dev_remove().
Fix this by implementing ->free_disk and free private data in it.25dCVE-2018-25175—16.2%
——5——CVE-2024-26694—16.2%
——5——CVE-2023-25003—16.2%
——5——CVE-2025-55266—16.2%
——5——CVE-2026-23887—16.2%
——5——CVE-2025-42975—16.2%
——5——CVE-2024-4225—16.2%
——5——CVE-2021-20500—16.2%
——5——CVE-2023-32415—16.2%
——5——CVE-2025-6509—16.2%
——5——CVE-2018-11994—16.2%
——5——CVE-2026-606886.3 MED16.2%
——5Vulnerability in the Oracle Scheduler product of Oracle E-Business Suite (component: Rules UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scheduler. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Scheduler accessible data as well as unauthorized read access to a subset of Oracle Scheduler accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scheduler. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).23dCVE-2024-26884—16.2%
——5——CVE-2025-14194—16.2%
——5——CVE-2026-6310—16.2%
——5——CVE-2007-4304—16.2%
——5——CVE-2025-66133—16.2%
——5——CVE-2024-40070—16.2%
——5——CVE-2026-171117.6 HIG16.2%
——5IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.12dCVE-2022-32826—16.2%
——5——CVE-2025-64632—16.2%
——5——CVE-2022-488648.8 HIG16.2%
——5In the Linux kernel, the following vulnerability has been resolved:
vdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command
When control vq receives a VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command
request from the driver, presently there is no validation against the
number of queue pairs to configure, or even if multiqueue had been
negotiated or not is unverified. This may lead to kernel panic due to
uninitialized resource for the queues were there any bogus request
sent down by untrusted driver. Tie up the loose ends there.25dCVE-2024-39436—16.2%
——5——CVE-2024-46805—16.2%
——5——CVE-2008-2418—16.2%
——5——CVE-2026-3056—16.2%
——5——CVE-2026-711036.3 MED16.2%
——5Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).9dCVE-2026-605736.3 MED16.2%
——5Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Partner Dashboard). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Partner Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Partner Management accessible data as well as unauthorized read access to a subset of Oracle Partner Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Partner Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).22d