Vulnerabilities exploitable today
355,177in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,498
- High9,083
- Medium7,310
- Low690
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11998—6.8%
——2——CVE-2025-39974—6.8%
——2——CVE-2019-10515—6.8%
——2——CVE-2025-42706—6.8%
——2——CVE-2025-54088—6.8%
——2——CVE-2025-14817—6.8%
——2——CVE-2025-40098—6.8%
——2In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state()
Return value of a function acpi_evaluate_dsm() is dereferenced without
checking for NULL, but it is usually checked for this function.
acpi_evaluate_dsm() may return NULL, when acpi_evaluate_object() returns
acpi_status other than ACPI_SUCCESS, so add a check to prevent the crach.
Found by Linux Verification Center (linuxtesting.org) with SVACE.18hCVE-2025-31236—6.8%
——2——CVE-2024-49866—6.8%
——2——CVE-2023-47845—6.8%
——2——CVE-2023-46708—6.8%
——2——CVE-2026-393472.7 LOW6.8%
——2OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability is fixed in 5.8.1.10dCVE-2026-655925.4 MED6.8%
——2n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow creation/editing privileges can craft a workflow with a malicious (e.g., javascript:) scheme in cachedResultUrl; when a victim opens the crafted workflow and interacts with external links, the payload executes in the victim's browser.7dCVE-2021-37672—6.8%
——2——CVE-2023-28088—6.8%
——2——CVE-2024-9588—6.8%
——2——CVE-2026-447596.1 MED6.8%
——2SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.20dCVE-2024-3185—6.8%
——2——CVE-2025-51734—6.8%
——2——CVE-2026-48518—6.8%
——2——CVE-2026-7953—6.8%
——2——CVE-2026-22269—6.8%
——2——CVE-2025-33249—6.8%
——2——CVE-2024-31890—6.8%
——2——CVE-2024-22428—6.8%
——2——CVE-2026-398797.1 HIG6.8%
——2Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.812dCVE-2023-54021—6.8%
——2——CVE-2023-5671—6.8%
——2——CVE-2026-54319—6.8%
——2——CVE-2023-53361—6.8%
——2——CVE-2020-36953—6.8%
——2——CVE-2019-2053—6.8%
——2——CVE-2026-20017—6.8%
——2——CVE-2026-7950—6.8%
——2——CVE-2021-47739—6.8%
——2——CVE-2025-66084—6.8%
——2——CVE-2025-21615—6.8%
——2——CVE-2022-35719—6.8%
——2——CVE-2025-33187—6.8%
——2——CVE-2025-68366—6.8%
——2——