Vulnerabilities exploitable today
379,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,385
- High8,590
- Medium7,035
- Low793
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-82356——
——0Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.2hCVE-2026-82368——
——0Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed access to transmit commands to connected Fabric OS switches under the security context of the SANnav management user.2hCVE-2026-862477.4 HIG—
——0Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected.
Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue.2hCVE-2026-847917.1 HIG—
——0ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.3hCVE-2026-937738.5 HIG—
——0Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.2hCVE-2026-123707.6 HIG—
——0ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.3hCVE-2026-937747.1 HIG—
——0Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.2hCVE-2020-37258——
——0Rejected reason: This CVE ID has been rejected.43dCVE-2026-944878.1 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.2hCVE-2026-76819——
——0Rejected reason: Further research determined the issue results from a dependency.1dCVE-2026-955276.5 MED—
——0Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.2hCVE-2026-35028——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.44dCVE-2023-39931——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2023-32648——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2023-40157——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2023-23905——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2023-37395—0.0%
——0——CVE-2023-22446——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused28dCVE-2023-39940——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2026-89155——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.4dCVE-2026-90839——
——0Rejected reason: this is rejected3dCVE-2023-38578——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2026-51232——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54dCVE-2026-89019——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.1dCVE-2026-46535——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.34dCVE-2026-16552——
——0Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.62dCVE-2026-11874——
——0Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.6dCVE-2026-10145——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8dCVE-2026-5695——
——0Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.7hCVE-2023-47176——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27dCVE-2026-51243——
——0Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.54dCVE-2026-5696——
——0Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.7hCVE-2026-78253——
——0Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.6hCVE-2026-866838.1 HIG—
——0ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.3hCVE-2026-735917.5 HIG—
——0Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.4hCVE-2026-181806.5 MED—
——0IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.3hCVE-2026-185055.4 MED—
——0IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.3hCVE-2025-25275——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused42dCVE-2026-190874.4 MED—
——0IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.3hCVE-2023-31201——
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused27d