Vulnerabilities exploitable today
359,665in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,517
- High11,192
- Medium7,126
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-56774—10.9%
——3——CVE-2026-683418.8 HIG10.9%
——3In the Linux kernel, the following vulnerability has been resolved:
ovpn: fix use after free in unlock_ovpn()
unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().
If this drops the last reference, the peer is eventually freed. However,
llist_for_each_entry() reads peer->release_entry.next in the loop advance
expression, which runs after the body. By that time the peer may have
already been freed, resulting in a use after free when advancing to the
next list entry.
Fix this by using llist_for_each_entry_safe(), which caches the next
pointer before executing the loop body.1dCVE-2026-16956.1 MED10.9%
——3An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id).
This vulnerability only affects the error page of the OAuth server.36dCVE-2026-54006—10.9%
——3——CVE-2025-1108—10.9%
——3——CVE-2025-53063—10.9%
——3——CVE-2023-40430—10.9%
——3——CVE-2025-61828—10.9%
——3——CVE-2024-53154—10.9%
——3——CVE-2025-26500—10.9%
——3——CVE-2025-30321—10.9%
——3——CVE-2025-47756—10.9%
——3——CVE-2024-6224—10.9%
——3——CVE-2023-45821—10.9%
——3——CVE-2026-27511—10.9%
——3——CVE-2024-55881—10.9%
——3——CVE-2025-4415—10.9%
——3——CVE-2024-56776—10.9%
——3——CVE-2026-572305.4 MED10.9%
——3OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions that took input without escaping, allowing an authenticated member to read any ClickHouse table through blind boolean and time-based exfiltration and to break the project's session search for all viewers until the stored key is removed. This issue is fixed in version 1.27.0.32dCVE-2025-47755—10.9%
——3——CVE-2023-41095—10.9%
——3——CVE-2025-47753—10.9%
——3——CVE-2025-22054—10.9%
——3——CVE-2026-144179.6 CRI10.9%
——3Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)43dCVE-2024-34580—10.9%
——3——CVE-2026-72536.0 MED10.9%
——3IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.22dCVE-2023-26248—10.9%
——3——CVE-2023-50827—10.9%
——3——CVE-2025-31269—10.9%
——3——CVE-2024-49910—10.9%
——3——CVE-2024-48883—10.9%
——3——CVE-2025-47752—10.9%
——3——CVE-2025-52363—10.9%
——3——CVE-2024-56622—10.9%
——3——CVE-2025-23284—10.9%
——3——CVE-2026-704328.8 HIG10.9%
——3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.9dCVE-2025-36161—10.9%
——3——CVE-2024-56787—10.9%
——3——CVE-2024-53129—10.9%
——3——CVE-2024-53128—10.9%
——3——