Vulnerabilities exploitable today
361,121in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,666
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,677
- High11,555
- Medium7,184
- Low660
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-747999.3 CRI—
——0SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.1dCVE-2026-748778.8 HIG—
——0openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.9hCVE-2026-33181——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a duplicate of CVE-2026-33942. Notes: All CVE users should reference CVE-2026-33942 instead of this candidate.12dCVE-2026-748797.5 HIG—
——0openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.1dCVE-2023-54375——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.13dCVE-2026-28549—0.0%
——0——CVE-2026-285863.3 LOW0.0%
——0In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.27dCVE-2026-58407——
——0Rejected reason: Please submit CVE requests for each vulnerability.36dCVE-2026-748809.8 CRI—
——0openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.1dCVE-2026-28999——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-748827.5 HIG—
——0openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.9hCVE-2026-68575——
——0Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly reserved and linked through OSIM when the flaw is worked.18dCVE-2025-45764—0.0%
——0——CVE-2026-68869——
——0Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a security vulnerability and does not require a CVE record.15dCVE-2026-28184——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.5dCVE-2026-51243——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.18dCVE-2026-24438——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-23765——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-23692——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-51229——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.18dCVE-2026-23691——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-748816.5 MED—
——0openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.1dCVE-2026-00947.8 HIG0.0%
——0In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.27dCVE-2026-73188——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.5dCVE-2026-748759.8 CRI—
——0openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.1dCVE-2023-54376——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.13dCVE-2026-14278——
——0Rejected reason: After further coordination, CVE was determined to not be warranted.40dCVE-2026-68948——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a duplicate of CVE-2026-67318. Notes: All CVE users should reference CVE-2026-67318 instead of this candidate.12dCVE-2026-32317—0.0%
——0——CVE-2026-43636——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.32dCVE-2023-54377——
——0Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.13dCVE-2026-51386——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate of CVE-2026-46409. Notes: All CVE users should reference CVE-2026-46409 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.29dCVE-2026-0392—0.0%
——0eParakstītājs 3.0 for Windows before version
1.10.0 retrieves and executes its automatic updates over a channel that is not
authenticated or integrity-protected. On each launch the application fetches an
update descriptor (XML) over TLS but accepts any TLS certificate (a permissive
TrustManager and a HostnameVerifier that always returns true), does not verify
any digital signature on the update descriptor, and does not verify the
Authenticode signature or a checksum of the downloaded installer before running
it. A man-in-the-middle attacker able to redirect www.eparaksts.lv can serve a
crafted update descriptor pointing to an attacker-controlled executable, which
the client downloads and executes, resulting in arbitrary code execution on the
victim host.14dCVE-2026-3883——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.5dCVE-2026-51285——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.18dCVE-2026-62180——
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61440. Reason: This candidate is a duplicate of CVE-2026-61440. Notes: All CVE users should reference CVE-2026-61440 instead of this candidate.34dCVE-2025-62310—0.0%
——0——CVE-2026-23677——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-213685.3 MED0.0%
——0Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.42dCVE-2026-26349——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8d