Vulnerabilities exploitable today
363,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,896
- High12,359
- Medium7,619
- Low720
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-612408.2 HIG12.7%
——4Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise FIN Common Objects Argentina executes to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).20dCVE-2025-65187—12.7%
——4——CVE-2025-69185—12.7%
——4——CVE-2025-52712—12.7%
——4——CVE-2026-21975—12.7%
——4——CVE-2025-31417—12.7%
——4——CVE-2026-97966.5 MED12.7%
——4A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.1dCVE-2022-50839—12.7%
——4——CVE-2025-14345—12.7%
——4——CVE-2026-728166.5 MED12.7%
——4go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.6dCVE-2025-31376—12.7%
——4——CVE-2025-27435—12.7%
——4——CVE-2024-422997.8 HIG12.7%
——4In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Update log->page_{mask,bits} if log->page_size changed
If an NTFS file system is mounted to another system with different
PAGE_SIZE from the original system, log->page_size will change in
log_replay(), but log->page_{mask,bits} don't change correspondingly.
This will cause a panic because "u32 bytes = log->page_size - page_off"
will get a negative value in the later read_log_page().16dCVE-2024-58130—12.7%
——4——CVE-2022-487177.1 HIG12.7%
——4In the Linux kernel, the following vulnerability has been resolved:
ASoC: max9759: fix underflow in speaker_gain_control_put()
Check for negative values of "priv->gain" to prevent an out of bounds
access. The concern is that these might come from the user via:
-> snd_ctl_elem_write_user()
-> snd_ctl_elem_write()
-> kctl->put()16dCVE-2022-48926—12.7%
——4——CVE-2024-56448—12.7%
——4——CVE-2025-11873—12.7%
——4——CVE-2024-499567.8 HIG12.7%
——4In the Linux kernel, the following vulnerability has been resolved:
gfs2: fix double destroy_workqueue error
When gfs2_fill_super() fails, destroy_workqueue() is called within
gfs2_gl_hash_clear(), and the subsequent code path calls
destroy_workqueue() on the same work queue again.
This issue can be fixed by setting the work queue pointer to NULL after
the first destroy_workqueue() call and checking for a NULL pointer
before attempting to destroy the work queue again.16dCVE-2024-449787.8 HIG12.7%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Free job before xe_exec_queue_put
Free job depends on job->vm being valid, the last xe_exec_queue_put can
destroy the VM. Prevent UAF by freeing job before xe_exec_queue_put.
(cherry picked from commit 32a42c93b74c8ca6d0915ea3eba21bceff53042f)16dCVE-2026-341615.4 MED12.7%
——4Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious HTML file containing JavaScript via the /api/social_post_attachments endpoint. The uploaded file is served back from the application at the generated contentUrl without sanitization, content type restrictions, or a Content-Disposition: attachment header, causing the JavaScript to execute in the browser within the application's origin. Because the payload is stored server-side and runs in the trusted origin, an attacker can perform session hijacking, account takeover, privilege escalation (if an admin views the link), and arbitrary actions on behalf of the victim. This issue has been fixed in version 2.0.0-RC.3.27dCVE-2025-10138—12.7%
——4——CVE-2026-4586—12.7%
——4——CVE-2025-10132—12.7%
——4——CVE-2024-5249—12.7%
——4——CVE-2024-57978—12.7%
——4——CVE-2025-21742—12.7%
——4——CVE-2020-12292—12.6%
——4——CVE-2023-54057—12.6%
——4——CVE-2026-165956.5 MED12.6%
——4The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.10dCVE-2020-12288—12.6%
——4——CVE-2026-20434—12.6%
——4——CVE-2023-34402—12.6%
——4——CVE-2024-51451—12.6%
——4——CVE-2025-66423—12.6%
——4——CVE-2022-32900—12.6%
——4——CVE-2024-50064—12.6%
——4——CVE-2020-12294—12.6%
——4——CVE-2025-11587—12.6%
——4——CVE-2022-50858—12.6%
——4——