Vulnerabilities exploitable today
358,897in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,708
- High11,665
- Medium7,438
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-30823—9.7%
——3——CVE-2026-45435—9.7%
——3——CVE-2025-30822—9.7%
——3——CVE-2025-31808—9.7%
——3——CVE-2026-24544—9.7%
——3——CVE-2025-30546—9.7%
——3——CVE-2023-42930—9.7%
——3——CVE-2021-0458—9.7%
——3——CVE-2025-377977.8 HIG9.7%
——3In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a UAF vulnerability in class handling
This patch fixes a Use-After-Free vulnerability in the HFSC qdisc class
handling. The issue occurs due to a time-of-check/time-of-use condition
in hfsc_change_class() when working with certain child qdiscs like netem
or codel.
The vulnerability works as follows:
1. hfsc_change_class() checks if a class has packets (q.qlen != 0)
2. It then calls qdisc_peek_len(), which for certain qdiscs (e.g.,
codel, netem) might drop packets and empty the queue
3. The code continues assuming the queue is still non-empty, adding
the class to vttree
4. This breaks HFSC scheduler assumptions that only non-empty classes
are in vttree
5. Later, when the class is destroyed, this can lead to a Use-After-Free
The fix adds a second queue length check after qdisc_peek_len() to verify
the queue wasn't emptied.14dCVE-2025-31807—9.7%
——3——CVE-2026-24965—9.7%
——3——CVE-2026-666784.3 MED9.7%
——3Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.4hCVE-2025-39517—9.7%
——3——CVE-2025-31784—9.7%
——3——CVE-2025-31840—9.7%
——3——CVE-2025-31763—9.7%
——3——CVE-2019-9456—9.7%
——3——CVE-2025-30842—9.7%
——3——CVE-2024-31434—9.7%
——3——CVE-2026-542496.8 MED9.7%
——3Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or cloud-storage account. While file URL parts are validated against a scheme allowlist, UploadedFile references — which point to a file by provider file ID or cloud-storage URI (e.g. s3://…, gs://…) — were forwarded without validation. Because the provider resolves an UploadedFile using the server-side identity (IAM role, service account, or provider API key) rather than the client's, an attacker can craft message history to make the server read objects from its own account or other tenants, given a referenceable identifier. Exploitation requires a valid file identifier, which is not always unguessable depending on how the application names objects. This issue has been fixed in versions 1.106.0 and 2.0.0b6.8dCVE-2025-31756—9.7%
——3——CVE-2026-126244.3 MED9.7%
——3Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.1dCVE-2025-30862—9.7%
——3——CVE-2018-253467.1 HIG9.7%
——3WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.20dCVE-2026-609075.0 MED9.7%
——3Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).19dCVE-2025-30872—9.7%
——3——CVE-2025-30815—9.7%
——3——CVE-2026-62875.4 MED9.7%
——3The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.21dCVE-2023-28378—9.7%
——3——CVE-2023-38402—9.7%
——3——CVE-2025-9294—9.7%
——3——CVE-2025-30811—9.7%
——3——CVE-2025-30556—9.7%
——3——CVE-2023-52937—9.7%
——3——CVE-2022-50723—9.7%
——3——CVE-2024-57903—9.7%
——3——CVE-2024-54518—9.7%
——3——CVE-2025-30322—9.7%
——3——CVE-2026-88567.7 HIG9.7%
——3IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.21dCVE-2025-30534—9.7%
——3——