Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,101
- Medium4,995
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-27430—15.0%
——5——CVE-2026-2653—15.0%
——5——CVE-2021-22525—15.0%
——5——CVE-2025-0640—15.0%
——5——CVE-2026-470157.1 HIG15.0%
——5Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). The supported version that is affected is 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).27dCVE-2025-12279—15.0%
——5——CVE-2024-52339—15.0%
——5——CVE-2025-5753—15.0%
——5——CVE-2024-51936—15.0%
——5——CVE-2024-52340—15.0%
——5——CVE-2026-163968.8 HIG15.0%
——5Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.34dCVE-2025-4422—15.0%
——5——CVE-2024-52341—15.0%
——5——CVE-2024-476767.8 HIG15.0%
——5In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb.c: fix UAF of vma in hugetlb fault pathway
Syzbot reports a UAF in hugetlb_fault(). This happens because
vmf_anon_prepare() could drop the per-VMA lock and allow the current VMA
to be freed before hugetlb_vma_unlock_read() is called.
We can fix this by using a modified version of vmf_anon_prepare() that
doesn't release the VMA lock on failure, and then release it ourselves
after hugetlb_vma_unlock_read().24dCVE-2020-4891—15.0%
——5——CVE-2023-38747—15.0%
——5——CVE-2026-52784—15.0%
——5——CVE-2025-7748—15.0%
——5——CVE-2026-181577.8 HIG15.0%
——5A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.24dCVE-2021-41201—15.0%
——5——CVE-2025-8053—15.0%
——5——CVE-2025-48340—15.0%
——5——CVE-2025-14483—15.0%
——5——CVE-2026-58694.3 MED15.0%
——5Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)35dCVE-2025-65495—15.0%
——5——CVE-2025-44109—15.0%
——5——CVE-2024-5681—15.0%
——5——CVE-2024-47046—15.0%
——5——CVE-2024-36667—15.0%
——5——CVE-2026-30568—15.0%
——5——CVE-2025-0923—15.0%
——5——CVE-2024-36281—15.0%
——5——CVE-2026-464818.3 HIG15.0%
——5OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.password and the ingestion bot JWT in openMetadataServerConnection.securityConfig.jwtToken. The leaked ingestion-bot token can then be reused as Authorization: Bearer <jwt> to access sensitive service APIs with bot-level privileges. This issue has been patched in version 1.12.4.36dCVE-2026-160814.3 MED15.0%
——5A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.38dCVE-2026-40603—15.0%
——5——CVE-2026-44002—15.0%
——5——CVE-2026-25731—15.0%
——5——CVE-2024-47643—15.0%
——5——CVE-2024-1214—15.0%
——5——CVE-2024-25578—15.0%
——5——