Vulnerabilities exploitable today
355,177in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,498
- High9,083
- Medium7,310
- Low690
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68367—6.8%
——2——CVE-2024-23275—6.8%
——2——CVE-2022-35719—6.8%
——2——CVE-2025-33187—6.8%
——2——CVE-2025-68366—6.8%
——2——CVE-2026-7950—6.8%
——2——CVE-2021-47739—6.8%
——2——CVE-2026-20017—6.8%
——2——CVE-2025-66084—6.8%
——2——CVE-2026-40960—6.8%
——2——CVE-2023-54314—6.8%
——2——CVE-2026-54319—6.8%
——2——CVE-2024-31890—6.8%
——2——CVE-2023-5671—6.8%
——2——CVE-2023-53361—6.8%
——2——CVE-2026-398797.1 HIG6.8%
——2Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured.
Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.811dCVE-2024-31946—6.8%
——2——CVE-2023-54021—6.8%
——2——CVE-2020-36953—6.8%
——2——CVE-2019-2053—6.8%
——2——CVE-2026-612206.1 MED6.8%
——2Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Configuration). The supported version that is affected is 14.5.0.16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Origination, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).11dCVE-2026-139775.4 MED6.8%
——2Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)32dCVE-2026-140016.1 MED6.8%
——2Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2026-140006.1 MED6.8%
——2Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)33dCVE-2025-68325—6.8%
——2——CVE-2025-54867—6.8%
——2——CVE-2022-4129—6.8%
——2——CVE-2025-66106—6.8%
——2——CVE-2025-68734—6.8%
——2——CVE-2026-343166.1 MED6.8%
——2Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Service Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Service Center accessible data as well as unauthorized read access to a subset of Oracle Commerce Service Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).11dCVE-2026-417156.1 MED6.8%
——2In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Affected versions:
Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.12dCVE-2025-68733—6.8%
——2——CVE-2026-567425.9 MED6.8%
——2Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters using Gateway API allow users with permissions to create or update namespaced HTTPRoutes to mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mechanism. Gateway API functionality is disabled by default. This issue is fixed in versions 1.17.17, 1.18.11, and 1.19.5.17dCVE-2025-36056—6.8%
——2——CVE-2024-52560—6.8%
——2——CVE-2025-65840—6.8%
——2——CVE-2026-22358—6.8%
——2——CVE-2025-52555—6.8%
——2——CVE-2025-4321—6.8%
——2——CVE-2023-52952—6.8%
——2——