Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,666
- Medium7,455
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8136—10.3%
——3——CVE-2022-50096—10.3%
——3——CVE-2024-50107—10.3%
——3——CVE-2024-56772—10.3%
——3——CVE-2023-536267.8 HIG10.3%
——3In the Linux kernel, the following vulnerability has been resolved:
ext4: fix possible double unlock when moving a directory9dCVE-2020-11205—10.3%
——3——CVE-2025-20046—10.3%
——3——CVE-2023-44218—10.3%
——3——CVE-2026-82552.4 LOW10.3%
——3A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2023-42570—10.3%
——3——CVE-2022-48292—10.3%
——3——CVE-2022-49966—10.3%
——3——CVE-2022-50175—10.3%
——3——CVE-2026-72972.4 LOW10.3%
——3A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.20dCVE-2025-24934—10.3%
——3——CVE-2022-50177—10.3%
——3——CVE-2026-6003—10.3%
——3——CVE-2025-220447.1 HIG10.3%
——3In the Linux kernel, the following vulnerability has been resolved:
acpi: nfit: fix narrowing conversion in acpi_nfit_ctl
Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary
bus families can be translated". This warning is emited if the argument
is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first
verifies that a user-provided value call_pkg->nd_family of type u64 is
not equal to 0. Then the value is converted to int, and only after that
is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid
argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while
the lower 32 bits are zero.
Furthermore, it is best to return EINVAL immediately upon seeing the
invalid user input. The WARNING is insufficient to prevent further
undefined behavior based on other invalid user input.
All checks of the input value should be applied to the original variable
call_pkg->nd_family.
[iweiny: update commit message]14dCVE-2023-27932—10.3%
——3——CVE-2022-50110—10.3%
——3——CVE-2026-93703.7 LOW10.3%
——3A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.21dCVE-2019-256708.4 HIG10.3%
——3River Past Video Cleaner 7.6.3 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll field. Attackers can craft a payload with 280 bytes of padding, a next structured exception handler override, and shellcode to trigger code execution when the application processes the input.20dCVE-2025-64171—10.3%
——3——CVE-2025-12519—10.3%
——3——CVE-2017-17436—10.3%
——3——CVE-2026-41361—10.3%
——3——CVE-2022-49989—10.3%
——3——CVE-2026-82212.4 LOW10.3%
——3A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.20dCVE-2022-48984—10.3%
——3——CVE-2022-50546—10.3%
——3——CVE-2026-3956—10.3%
——3——CVE-2024-46808—10.3%
——3——CVE-2026-5839—10.3%
——3——CVE-2026-4169—10.3%
——3——CVE-2025-55276—10.3%
——3——CVE-2022-50931—10.3%
——3——CVE-2026-609877.1 HIG10.3%
——3Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).13dCVE-2026-167347.5 HIG10.3%
——3The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 then updates server-side through the Stripe API with the store's secret key. An ownership check added in 8.5.0 was applied to only one payment-intent handler, leaving the pricing-recalculation and payment-intent-update actions unprotected against amount manipulation.7dCVE-2026-131847.5 HIG10.3%
——3In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.7dCVE-2026-34475—10.3%
——3——