Vulnerabilities exploitable today
360,749in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,492
- High11,026
- Medium7,022
- Low631
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-130734.3 MED11.8%
——4An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine selection inconsistency triggered by a specific combination of aggregation options.24dCVE-2025-13577—11.8%
——4——CVE-2025-1068—11.8%
——4——CVE-2020-3638—11.8%
——4——CVE-2024-27004—11.8%
——4——CVE-2025-6236—11.8%
——4——CVE-2026-35039—11.8%
——4——CVE-2025-27349—11.8%
——4——CVE-2026-534337.5 HIG11.8%
——4fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service.
This issue was fixed in version 0.73.1.45dCVE-2024-52938—11.8%
——4——CVE-2026-3240—11.8%
——4——CVE-2025-27341—11.8%
——4——CVE-2024-1362—11.8%
——4——CVE-2025-20062—11.8%
——4——CVE-2025-43402—11.8%
——4——CVE-2024-38270—11.8%
——4——CVE-2021-44513—11.8%
——4——CVE-2025-21130—11.8%
——4——CVE-2024-47094—11.8%
——4——CVE-2025-60799—11.8%
——4——CVE-2026-42525—11.8%
——4——CVE-2025-27330—11.8%
——4——CVE-2026-6486—11.8%
——4——CVE-2025-21132—11.8%
——4——CVE-2026-58061—11.8%
——4In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).12dCVE-2025-27351—11.8%
——4——CVE-2026-118676.5 MED11.8%
——4The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated users with low privileges (such as Subscribers) to create, rename, and delete arbitrary taxonomy terms.17dCVE-2024-36967—11.8%
——4——CVE-2025-1441—11.8%
——4——CVE-2025-36891—11.8%
——4——CVE-2026-603533.1 LOW11.8%
——4Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).16dCVE-2025-65111—11.8%
——4——CVE-2025-24176—11.8%
——4——CVE-2026-477095.5 MED11.8%
——4libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.20dCVE-2026-187046.5 MED11.8%
——4An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.5dCVE-2024-6029—11.8%
——4——CVE-2023-3950—11.8%
——4——CVE-2025-27325—11.8%
——4——CVE-2025-24267—11.8%
——4——CVE-2024-44971—11.8%
——4——