Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,361
- High8,537
- Medium6,928
- Low785
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-35311—34.3%
——10——CVE-2025-56264—34.3%
——10——CVE-2026-601185.3 MED34.3%
——10Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can enumerate sequential hidden ticket IDs from visible ones and submit order creation requests referencing those IDs to purchase VIP, invite-only, or discounted tickets intentionally withheld from public sale.70dCVE-2026-605659.9 CRI34.3%
——10Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).54dCVE-2026-43067—34.3%
——10——CVE-2019-12532—34.3%
——10——CVE-2025-15521—34.3%
——10——CVE-2025-50170—34.3%
——10——CVE-2022-25946—34.3%
——10——CVE-2023-37577—34.3%
——10——CVE-2026-7617—34.3%
——10——CVE-2023-37573—34.3%
——10——CVE-2025-14917—34.3%
——10——CVE-2025-3529—34.3%
——10——CVE-2025-14866—34.3%
——10——CVE-2022-3609—34.3%
——10——CVE-2024-29183—34.3%
——10——CVE-2023-22479—34.3%
——10——CVE-2024-43201—34.3%
——10——CVE-2026-607309.9 CRI34.3%
——10Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).34dCVE-2026-607029.9 CRI34.3%
——10Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).33dCVE-2024-33819—34.3%
——10——CVE-2025-2841—34.3%
——10——CVE-2024-32317—34.3%
——10——CVE-2026-42035—34.3%
——10——CVE-2010-5269—34.3%
——10——CVE-2025-54605—34.3%
——10——CVE-2025-47564—34.3%
——10——CVE-2024-8713—34.3%
——10——CVE-2026-46852—34.3%
——10——CVE-2020-8028—34.3%
——10——CVE-2010-5272—34.3%
——10——CVE-2023-5073—34.3%
——10——CVE-2026-12094—34.3%
——10——CVE-2021-46663—34.3%
——10——CVE-2025-0875—34.3%
——10——CVE-2026-8737—34.3%
——10——CVE-2025-67731—34.3%
——10——CVE-2024-23168—34.3%
——10——CVE-2025-20274—34.3%
——10——