Vulnerabilities exploitable today
363,850in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,906
- High11,924
- Medium7,262
- Low683
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-593186.5 MED—
———In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation.
Affected versions:
Spring AI: 2.0.0
Spring AI: 1.1.0 through 1.1.8
Spring AI: 1.0.0 through 1.0.94hCVE-2023-7336——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2hCVE-2026-556227.7 HIG—
———Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access. Version 7.2.0 patches the issue.3hCVE-2023-7344——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2hCVE-2026-11427——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2hCVE-2026-556217.7 HIG—
———Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not authorized to access. Version 7.2.0 patches the issue.2hCVE-2026-9012——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2hCVE-2026-502786.5 MED—
———iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.4hCVE-2026-11830——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2hCVE-2026-11902——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.2h