Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,322
- High9,974
- Medium4,913
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-7990—14.5%
——4——CVE-2026-7045—14.5%
——4——CVE-2019-3837—14.5%
——4——CVE-2018-1141—14.5%
——4——CVE-2023-41051—14.5%
——4——CVE-2025-24330—14.5%
——4——CVE-2021-34388—14.5%
——4——CVE-2025-12361—14.5%
——4——CVE-2024-420687.8 HIG14.5%
——4In the Linux kernel, the following vulnerability has been resolved:
bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
set_memory_ro() can fail, leaving memory unprotected.
Check its return and take it into account as an error.23dCVE-2025-53309—14.5%
——4——CVE-2024-268247.8 HIG14.5%
——4In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_hash - Remove bogus SGL free on zero-length error path
When a zero-length message is hashed by algif_hash, and an error
is triggered, it tries to free an SG list that was never allocated
in the first place. Fix this by not freeing the SG list on the
zero-length error path.23dCVE-2024-27799—14.5%
——4——CVE-2024-46802—14.5%
——4——CVE-2026-25149—14.5%
——4——CVE-2023-3438—14.5%
——4——CVE-2025-9325—14.5%
——4——CVE-2023-0058—14.5%
——4——CVE-2024-30140—14.5%
——4——CVE-2025-9323—14.5%
——4——CVE-2026-738715.3 MED14.5%
——4Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).3dCVE-2026-1539—14.5%
——4——CVE-2025-58055—14.5%
——4——CVE-2022-27089—14.5%
——4——CVE-2022-50238—14.5%
——4——CVE-2026-199326.3 MED14.5%
——4A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The manipulation results in code injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project confirms, that "it’s being processed".7dCVE-2026-7494—14.5%
——4Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.43dCVE-2025-30615—14.5%
——4——CVE-2024-49888—14.5%
——4——CVE-2025-20324—14.5%
——4——CVE-2023-21419—14.5%
——4——CVE-2023-1855—14.5%
——4——CVE-2026-739005.3 MED14.5%
——4Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).6dCVE-2026-260586.1 MED14.5%
——4Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user can read into the uploads directory during import. This issue has been patched in version 11.6.34dCVE-2022-30696—14.5%
——4——CVE-2024-49923—14.5%
——4——CVE-2022-49024—14.5%
——4——CVE-2023-52931—14.5%
——4——CVE-2018-7911—14.5%
——4——CVE-2025-43346—14.5%
——4——CVE-2025-0510—14.5%
——4——