Vulnerabilities exploitable today
363,850in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,926
- High12,038
- Medium7,391
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-23429.3 CRI12.9%
——4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS.
This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.43dCVE-2025-66140—12.9%
——4——CVE-2021-33093—12.9%
——4——CVE-2024-40863—12.9%
——4——CVE-2023-27519—12.9%
——4——CVE-2024-42609—12.9%
——4——CVE-2021-38989—12.9%
——4——CVE-2025-7564—12.8%
——4——CVE-2020-1861—12.8%
——4——CVE-2025-7231—12.8%
——4——CVE-2025-7308—12.8%
——4——CVE-2025-7241—12.8%
——4——CVE-2025-9275—12.8%
——4——CVE-2025-7281—12.8%
——4——CVE-2026-26883—12.8%
——4——CVE-2024-35771—12.8%
——4——CVE-2025-7253—12.8%
——4——CVE-2025-7269—12.8%
——4——CVE-2026-28418—12.8%
——4——CVE-2025-7270—12.8%
——4——CVE-2025-21812—12.8%
——4——CVE-2026-10733—12.8%
——4——CVE-2025-7279—12.8%
——4——CVE-2025-34450—12.8%
——4——CVE-2025-7977—12.8%
——4——CVE-2026-181089.8 CRI12.8%
——4Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature.
_verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object. An SP's encryption certificate is published in its SAML metadata so the IdP can encrypt to it, so any party can encrypt an unsigned assertion to that certificate, wrap it in a samlp:Response, and post it to the assertion consumer service.
Any caller that configures a decryption key_file, and so accepts EncryptedAssertions, takes identity fields from an assertion that no trust anchor covers, and an unauthenticated party can authenticate as an arbitrary user. Callers with no key_file configured do not decrypt and are unaffected.15dCVE-2024-31113—12.8%
——4——CVE-2025-26555—12.8%
——4——CVE-2025-50011—12.8%
——4——CVE-2025-7248—12.8%
——4——CVE-2025-52599—12.8%
——4——CVE-2019-10607—12.8%
——4——CVE-2019-10605—12.8%
——4——CVE-2025-7273—12.8%
——4——CVE-2025-7261—12.8%
——4——CVE-2019-10603—12.8%
——4——CVE-2025-7271—12.8%
——4——CVE-2025-43581—12.8%
——4——CVE-2026-411876.5 MED12.8%
——4Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped policy resources can bulk-delete policies in tiers they otherwise have no rights on, breaking the tier authorization boundary.14dCVE-2026-41002—12.8%
——4——