Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,373
- High8,570
- Medium6,941
- Low785
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3529—34.3%
——10——CVE-2025-20274—34.3%
——10——CVE-2023-37573—34.3%
——10——CVE-2021-46663—34.3%
——10——CVE-2026-12094—34.3%
——10——CVE-2026-46885—34.3%
——10——CVE-2018-25329—34.3%
——10——CVE-2024-33955—34.3%
——10——CVE-2025-49041—34.3%
——10——CVE-2025-24567—34.3%
——10——CVE-2026-601758.8 HIG34.3%
——10Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).48dCVE-2023-37574—34.3%
——10——CVE-2024-41675—34.3%
——10——CVE-2008-4966—34.3%
——10——CVE-2019-0105—34.3%
——10——CVE-2025-50635—34.3%
——10——CVE-2025-66473—34.3%
——10——CVE-2022-25946—34.3%
——10——CVE-2025-15521—34.3%
——10——CVE-2025-50170—34.3%
——10——CVE-2026-7617—34.3%
——10——CVE-2023-37577—34.3%
——10——CVE-2021-46661—34.3%
——10——CVE-2026-556857.5 HIG34.3%
——10React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.51dCVE-2022-36887—34.3%
——10——CVE-2025-53886—34.3%
——10——CVE-2026-370666.5 MED34.3%
——10Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.21dCVE-2022-36886—34.3%
——10——CVE-2010-5254—34.3%
——10——CVE-2024-54137—34.3%
——10——CVE-2024-7300—34.3%
——10——CVE-2026-608798.8 HIG34.3%
——10Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Configuration Manager). Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).33dCVE-2025-24693—34.3%
——10——CVE-2020-22181—34.3%
——10——CVE-2026-33662—34.3%
——10——CVE-2012-0548—34.3%
——10——CVE-2000-0852—34.3%
——10——CVE-2008-4967—34.3%
——10——CVE-2026-44380—34.3%
——10——CVE-2006-14714.6 NO 34.3%
——10Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.4h