Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,361
- High8,537
- Medium6,928
- Low785
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-27335—34.4%
——10——CVE-2018-1091—34.4%
——10——CVE-2026-28094—34.4%
——10——CVE-2025-59460—34.4%
——10——CVE-2025-32977—34.4%
——10——CVE-2026-394125.3 MED34.4%
——10LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural filter bypasses the ownPropertyOnly security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on ownPropertyOnly: true as a security boundary (e.g., multi-tenant template systems) are exposed to information disclosure of sensitive prototype properties such as API keys and tokens. This vulnerability is fixed in 10.25.4.61dCVE-2026-25458—34.4%
——10——CVE-2026-28107—34.4%
——10——CVE-2026-28098—34.4%
——10——CVE-2024-48892—34.4%
——10——CVE-2026-28093—34.4%
——10——CVE-2026-27075—34.4%
——10——CVE-2026-27994—34.4%
——10——CVE-2026-27986—34.4%
——10——CVE-2026-27989—34.4%
——10——CVE-2011-3536—34.4%
——10——CVE-2025-8432—34.4%
——10——CVE-2026-22476—34.4%
——10——CVE-2025-9011—34.4%
——10——CVE-2026-25379—34.4%
——10——CVE-2025-61944—34.4%
——10——CVE-2026-28024—34.4%
——10——CVE-2026-25017—34.4%
——10——CVE-2025-49181—34.3%
——10——CVE-2025-22484—34.3%
——10——CVE-2024-5802—34.3%
——10——CVE-2025-25298—34.3%
——10——CVE-2026-612848.8 HIG34.3%
——10Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).33dCVE-2018-25329—34.3%
——10——CVE-2026-46885—34.3%
——10——CVE-2024-41675—34.3%
——10——CVE-2024-33955—34.3%
——10——CVE-2024-56408—34.3%
——10——CVE-2023-37574—34.3%
——10——CVE-2025-49041—34.3%
——10——CVE-2019-20795—34.3%
——10——CVE-2025-24567—34.3%
——10——CVE-2026-601758.8 HIG34.3%
——10Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).48dCVE-2022-45809—34.3%
——10——CVE-2026-630806.5 MED34.3%
——10Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Attackers can supply malicious values through EventName, CountryCode, OsName, DeviceModel, AppVersion, or SessionId parameters to inject a UNION ALL statement that bypasses the app_id tenant isolation filter across thirteen of the fifteen stats API endpoints.62d