Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,666
- Medium7,455
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-93703.7 LOW10.3%
——3A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.21dCVE-2026-6003—10.3%
——3——CVE-2026-33045—10.3%
——3——CVE-2018-11897—10.3%
——3——CVE-2025-121503.1 LOW10.3%
——3A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.3dCVE-2025-31463—10.3%
——3——CVE-2018-11851—10.3%
——3——CVE-2025-26762—10.3%
——3——CVE-2026-35418—10.3%
——3——CVE-2023-51525—10.3%
——3——CVE-2026-4980—10.3%
——3——CVE-2024-49779—10.3%
——3——CVE-2024-58051—10.3%
——3——CVE-2025-50055—10.3%
——3——CVE-2025-2867—10.3%
——3——CVE-2025-34237—10.3%
——3——CVE-2025-8961—10.3%
——3——CVE-2025-5642—10.3%
——3——CVE-2025-21427—10.3%
——3——CVE-2024-23107—10.3%
——3——CVE-2025-31437—10.3%
——3——CVE-2025-219397.8 HIG10.3%
——3In the Linux kernel, the following vulnerability has been resolved:
drm/xe/hmm: Don't dereference struct page pointers without notifier lock
The pnfs that we obtain from hmm_range_fault() point to pages that
we don't have a reference on, and the guarantee that they are still
in the cpu page-tables is that the notifier lock must be held and the
notifier seqno is still valid.
So while building the sg table and marking the pages accesses / dirty
we need to hold this lock with a validated seqno.
However, the lock is reclaim tainted which makes
sg_alloc_table_from_pages_segment() unusable, since it internally
allocates memory.
Instead build the sg-table manually. For the non-iommu case
this might lead to fewer coalesces, but if that's a problem it can
be fixed up later in the resource cursor code. For the iommu case,
the whole sg-table may still be coalesced to a single contigous
device va region.
This avoids marking pages that we don't own dirty and accessed, and
it also avoid dereferencing struct pages that we don't own.
v2:
- Use assert to check whether hmm pfns are valid (Matthew Auld)
- Take into account that large pages may cross range boundaries
(Matthew Auld)
v3:
- Don't unnecessarily check for a non-freed sg-table. (Matthew Auld)
- Add a missing up_read() in an error path. (Matthew Auld)
(cherry picked from commit ea3e66d280ce2576664a862693d1da8fd324c317)14dCVE-2025-13672—10.3%
——3——CVE-2026-409864.8 MED10.3%
——3Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.
Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.21dCVE-2022-41176—10.3%
——3——CVE-2026-111858.1 HIG10.3%
——3Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)21dCVE-2026-604344.3 MED10.3%
——3Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).10dCVE-2025-31605—10.3%
——3——CVE-2024-49941—10.3%
——3——CVE-2026-33373—10.3%
——3——CVE-2021-47470—10.3%
——3——CVE-2024-2819—10.3%
——3——CVE-2024-37127—10.3%
——3——CVE-2024-0429—10.3%
——3——CVE-2023-42564—10.3%
——3——CVE-2022-48852—10.3%
——3——CVE-2025-22496—10.3%
——3——CVE-2024-33683—10.3%
——3——CVE-2022-41174—10.3%
——3——CVE-2025-9332—10.3%
——3——