Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,458
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-79673—15.5%
——5——CVE-2026-594998.6 HIG15.5%
——5: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)..
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions).: All versions without Priwall v3.16hCVE-2026-673034.3 MED15.5%
——5FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_process_irp_device_control() in channels/serial/client/serial_main.c. When serial device redirection is enabled and a server-controlled IRP_MJ_DEVICE_CONTROL request specifies an unsupported IOCTL with a non-zero OutputBufferLength, CommDeviceIoControl() can fail with BytesReturned = 0, causing the mismatch to trigger the assertion and abort the client process (denial of service).25dCVE-2026-638668.8 HIG15.5%
——5In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()
Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link
routine.33dCVE-2026-733847.5 HIG15.5%
——5Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.9dCVE-2026-343166.1 MED15.5%
——5Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).21dCVE-2026-438317.5 HIG15.5%
——5Full details and mitigation steps are currently restricted and will be published at a later date.3dCVE-2024-499685.5 MED15.5%
——5In the Linux kernel, the following vulnerability has been resolved:
ext4: filesystems without casefold feature cannot be mounted with siphash
When mounting the ext4 filesystem, if the default hash version is set to
DX_HASH_SIPHASH but the casefold feature is not set, exit the mounting.46dCVE-2024-45280—15.5%
——5——CVE-2021-46906—15.5%
——5——CVE-2026-5109—15.5%
——5——CVE-2026-24762—15.5%
——5——CVE-2026-33751—15.5%
——5——CVE-2020-1794—15.5%
——5——CVE-2025-24554—15.5%
——5——CVE-2025-24616—15.5%
——5——CVE-2024-51685—15.5%
——5——CVE-2025-47759—15.5%
——5——CVE-2023-42840—15.5%
——5——CVE-2026-182597.5 HIG15.5%
——5Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.16hCVE-2016-5253—15.5%
——5——CVE-2025-22486—15.5%
——5——CVE-2026-612545.4 MED15.5%
——5Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Republic of Korea) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Republic of Korea) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).36dCVE-2026-491877.5 HIG15.5%
——5The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.37dCVE-2025-21858—15.5%
——5——CVE-2026-657557.5 HIG15.5%
——5Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.32dCVE-2025-0274—15.5%
——5——CVE-2026-5818—15.5%
——5——CVE-2026-426737.5 HIG15.5%
——5Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data.
This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.38dCVE-2025-24564—15.5%
——5——CVE-2026-12706—15.5%
——5——CVE-2026-40903—15.5%
——5——CVE-2025-14830—15.5%
——5——CVE-2024-8860—15.5%
——5——CVE-2024-39291—15.5%
——5——CVE-2026-178426.5 MED15.5%
——5Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)26dCVE-2025-63208—15.5%
——5——CVE-2025-30279—15.5%
——5——CVE-2025-66065—15.5%
——5——CVE-2025-23853—15.5%
——5——