Vulnerabilities exploitable today
356,768in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,533
- High10,540
- Medium6,708
- Low668
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-6763—8.9%
——3——CVE-2023-53730—8.9%
——3——CVE-2026-418375.3 MED8.9%
——3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.18dCVE-2025-49917—8.9%
——3——CVE-2026-33982—8.9%
——3——CVE-2025-52779—8.9%
——3——CVE-2021-37687—8.9%
——3——CVE-2026-396095.3 MED8.9%
——3Missing Authorization vulnerability in Wava.co Wava Payment wava-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wava Payment: from n/a through <= 0.3.7.16dCVE-2026-395355.3 MED8.9%
——3Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.16dCVE-2026-32410—8.9%
——3——CVE-2024-1747—8.9%
——3——CVE-2022-48308—8.9%
——3——CVE-2021-320869.8 CRI8.9%
——3An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.6dCVE-2026-57340—8.9%
——3——CVE-2022-4574—8.9%
——3——CVE-2024-41902—8.9%
——3——CVE-2026-396575.3 MED8.9%
——3Missing Authorization vulnerability in leadlovers leadlovers forms leadlovers-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects leadlovers forms: from n/a through <= 1.0.2.16dCVE-2024-23808—8.9%
——3——CVE-2025-7029—8.9%
——3——CVE-2026-32397—8.9%
——3——CVE-2024-12740—8.9%
——3——CVE-2026-100186.5 MED8.9%
——3Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)20dCVE-2023-40212—8.9%
——3——CVE-2026-712767.1 HIG8.9%
——3Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf() in both the PostgreSQL reader (readers/postgres/messages.go: `fmt.Sprintf("SELECT * FROM %s WHERE %s ...", format, cond)`) and the TimescaleDB reader (readers/timescale/messages.go, same pattern), enabling SQL injection by any authenticated user able to query channel messages.4dCVE-2017-8190—8.9%
——3——CVE-2022-26519—8.9%
——3——CVE-2025-68115—8.9%
——3——CVE-2026-38528—8.9%
——3——CVE-2023-2961—8.9%
——3——CVE-2026-0588—8.9%
——3——CVE-2026-57334—8.9%
——3——CVE-2025-0836—8.9%
——3——CVE-2025-21815—8.9%
——3——CVE-2020-3610—8.9%
——3——CVE-2022-30747—8.9%
——3——CVE-2026-395615.3 MED8.9%
——3Missing Authorization vulnerability in WP Chill Revive.so revive-so allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive.so: from n/a through <= 2.0.7.16dCVE-2025-39407—8.9%
——3——CVE-2025-22066—8.9%
——3——CVE-2024-274087.8 HIG8.9%
——3In the Linux kernel, the following vulnerability has been resolved:
dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup
The Linked list element and pointer are not stored in the same memory as
the eDMA controller register. If the doorbell register is toggled before
the full write of the linked list a race condition error will occur.
In remote setup we can only use a readl to the memory to assure the full
write has occurred.6dCVE-2023-35799—8.9%
——3——