Vulnerabilities exploitable today
360,723in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,498
- High11,044
- Medium7,061
- Low637
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-33305—11.7%
——4——CVE-2026-482255.4 MED11.7%
——4Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value through the _type POST parameter directly into an HTML form hidden input value attribute. Attackers can craft a malicious request containing a JavaScript payload that executes in the victim's browser when the response is rendered.24dCVE-2025-58669—11.7%
——4——CVE-2025-9695—11.7%
——4——CVE-2024-8157—11.7%
——4——CVE-2026-456796.5 MED11.7%
——4OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0.25dCVE-2025-48019—11.7%
——4——CVE-2025-34521—11.7%
——4——CVE-2026-143816.5 MED11.7%
——4Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-1153—11.7%
——4——CVE-2021-33086—11.7%
——4——CVE-2022-49840—11.7%
——4——CVE-2022-49842—11.7%
——4——CVE-2021-46926—11.7%
——4——CVE-2025-43787—11.7%
——4——CVE-2025-27909—11.7%
——4——CVE-2025-0656—11.7%
——4——CVE-2026-112568.3 HIG11.7%
——4Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)24dCVE-2001-0103—11.7%
——4——CVE-2026-4877210.0 CRI11.7%
——4ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is `UNKNOWN`, the receiver MUST ignore any address fields that follow it, because the proxy has declared it cannot determine the client identity. ProxySQL parses those address fields anyway via `sscanf` and writes the spoofed source address into the session's `addr.addr` field. From there it flows directly into the query-rule matcher, where the `client_addr` predicate decides routing and ACL. When `mysql-proxy_protocol_networks = '*'` (the default), any TCP peer can send a PP1 frame and choose any source IP claim. With that, any `mysql_query_rules` row pinned to a `client_addr` value is forgeable: the attacker writes the address they want to match into the PP1 line, and ProxySQL routes their query as if it came from that address. In practice this is a routing and ACL bypass. Real deployments use `client_addr` for read-write splitting (internal apps go to the primary, public traffic to read replicas), per-app schema pinning, and query-filter rules (DDL allowed only from admin CIDR, public queries blocked from dangerous patterns). An attacker that can reach the frontend port can forge their way into any of those routes. Version 3.0.9 patches this issue.6dCVE-2024-39586—11.7%
——4——CVE-2025-32547—11.7%
——4——CVE-2026-470615.6 MED11.7%
——4Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).10dCVE-2026-663165.4 MED11.7%
——4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.10dCVE-2021-26329—11.7%
——4——CVE-2025-40042—11.7%
——4——CVE-2025-1884—11.7%
——4——CVE-2024-5155—11.7%
——4——CVE-2026-11364—11.7%
——4——CVE-2026-57667—11.7%
——4——CVE-2026-625626.5 MED11.7%
——4Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).20dCVE-2023-54230—11.7%
——4——CVE-2025-32247—11.7%
——4——CVE-2025-20328—11.7%
——4——CVE-2026-92038.5 HIG11.7%
——4A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.10dCVE-2025-32249—11.7%
——4——CVE-2025-65000—11.7%
——4——CVE-2024-29068—11.7%
——4——CVE-2021-26378—11.7%
——4——CVE-2025-9389—11.7%
——4——