Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-31411—33.7%
——10——CVE-2026-479958.1 HIG33.7%
——10Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.26dCVE-2026-442219.0 CRI33.7%
——10ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestAccessOnFile treated as allow-all; (2) ArcadeDBServer.createDatabase() omitted factory.setSecurity(...) so any database created via POST /api/v1/server {"command":"create database X"} had its entire record-level authorization system silently disabled. In combination, record-level and database-level authorization could be bypassed by any authenticated principal. This vulnerability is fixed in 26.4.2.50dCVE-2025-32808—33.7%
——10——CVE-2024-27952—33.7%
——10——CVE-2018-5073—33.7%
——10——CVE-2026-39951—33.7%
——10——CVE-2026-31283—33.7%
——10——CVE-2026-711077.5 HIG33.7%
——10Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).29dCVE-2013-4143—33.7%
——10——CVE-2026-879227.3 HIG33.7%
——10A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.12dCVE-2023-35878—33.7%
——10——CVE-2025-6332—33.7%
——10——CVE-2005-4279—33.7%
——10——CVE-2024-32149—33.7%
——10——CVE-2004-0887—33.7%
——10——CVE-1999-0462—33.7%
——10——CVE-2020-22809—33.7%
——10——CVE-2024-30128—33.7%
——10——CVE-2017-18030—33.7%
——10——CVE-2023-38520—33.7%
——10——CVE-2024-56313—33.7%
——10——CVE-2018-1565—33.7%
——10——CVE-2026-50052—33.7%
——10In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync
attack (request smuggling), which in turn can be used for cache poisoning,
authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the
feature parameter to contain +http2. HTTP/2 support is disabled by
default.62dCVE-2024-39828—33.7%
——10——CVE-2024-56314—33.7%
——10——CVE-2018-16098—33.7%
——10——CVE-2023-7268—33.7%
——10——CVE-2024-56312—33.7%
——10——CVE-2026-789696.5 MED33.7%
——10Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2026-693085.5 MED33.7%
——10Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.14dCVE-2023-36679—33.7%
——10——CVE-2017-16996—33.7%
——10——CVE-2026-32367—33.7%
——10——CVE-2025-5784—33.7%
——10——CVE-2021-29757—33.7%
——10——CVE-2025-52732—33.7%
——10——CVE-2010-4655—33.7%
——10——CVE-2020-5632—33.7%
——10——CVE-2026-693455.5 MED33.7%
——10Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.14d