Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,706
- High11,663
- Medium7,433
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-53722—9.7%
——3——CVE-2024-38598—9.7%
——3——CVE-2025-34263—9.7%
——3——CVE-2026-352048.6 HIG9.7%
——3Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not include a version: field containing POSIX dot-dot path separators ie. "/../". This vulnerability is fixed in 4.1.4.29dCVE-2024-21777—9.7%
——3——CVE-2024-21809—9.7%
——3——CVE-2022-26699—9.7%
——3——CVE-2024-26629—9.7%
——3——CVE-2025-30529—9.7%
——3——CVE-2024-31279—9.7%
——3——CVE-2025-54085—9.7%
——3——CVE-2026-99443.1 LOW9.7%
——3Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)23dCVE-2020-9112—9.7%
——3——CVE-2026-712457.1 HIG9.7%
——3Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with InputHelper::clean (which HTML-entity-encodes quotes and angle brackets but does not restrict other characters), and passes it into LeadRepository::buildQueryForGetLeadsByFieldValue where it is concatenated directly as a raw SQL column identifier ( = 'l.'.) rather than being validated against a whitelist of real column names or passed as a bound parameter.3dCVE-2025-30557—9.7%
——3——CVE-2026-32153—9.7%
——3——CVE-2025-30531—9.7%
——3——CVE-2024-50212—9.7%
——3——CVE-2025-14804—9.7%
——3——CVE-2025-58234—9.7%
——3——CVE-2026-13426—9.7%
——3——CVE-2026-606283.7 LOW9.7%
——3Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).6dCVE-2024-21151—9.7%
——3——CVE-2024-6657—9.7%
——3——CVE-2025-34264—9.7%
——3——CVE-2025-40153—9.7%
——3——CVE-2021-3740—9.7%
——3——CVE-2025-39546—9.7%
——3——CVE-2025-46531—9.7%
——3——CVE-2021-47906—9.7%
——3——CVE-2018-11259—9.7%
——3——CVE-2025-15019—9.7%
——3——CVE-2025-8285—9.7%
——3——CVE-2023-53716—9.7%
——3——CVE-2025-10458—9.7%
——3——CVE-2023-3379—9.7%
——3——CVE-2025-382538.8 HIG9.7%
——3In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: fix crash in wacom_aes_battery_handler()
Commit fd2a9b29dc9c ("HID: wacom: Remove AES power_supply after extended
inactivity") introduced wacom_aes_battery_handler() which is scheduled
as a delayed work (aes_battery_work).
In wacom_remove(), aes_battery_work is not canceled. Consequently, if
the device is removed while aes_battery_work is still pending, then hard
crashes or "Oops: general protection fault..." are experienced when
wacom_aes_battery_handler() is finally called. E.g., this happens with
built-in USB devices after resume from hibernate when aes_battery_work
was still pending at the time of hibernation.
So, take care to cancel aes_battery_work in wacom_remove().14dCVE-2024-31263—9.7%
——3——CVE-2025-40200—9.7%
——3——CVE-2026-706055.9 MED9.7%
——3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are only affected if they make net requests to attacker-influenced URLs with redirects followed and expose the response body. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.6d