Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-50544—33.6%
——10——CVE-2024-5730—33.6%
——10——CVE-2026-276110.0 CRI33.6%
——10Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.70dCVE-2024-204315.8 MED33.6%
——10A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy.
This vulnerability is due to improper assignment of geolocation data. An attacker could exploit this vulnerability by sending traffic through an affected device. A successful exploit could allow the attacker to bypass a geolocation-based access control policy and successfully send traffic to a protected device.42dCVE-2026-189379.0 CRI33.6%
——10The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.34dCVE-2023-39067—33.6%
——10——CVE-2019-17668—33.6%
——10——CVE-2024-51601—33.6%
——10——CVE-2024-9177—33.6%
——10——CVE-2026-33679—33.6%
——10——CVE-2024-25428—33.6%
——10——CVE-2024-50524—33.6%
——10——CVE-2015-4856—33.6%
——10——CVE-2024-21023—33.6%
——10——CVE-2023-51323—33.6%
——10——CVE-2023-46609—33.6%
——10——CVE-2024-49297—33.6%
——10——CVE-2026-122898.8 HIG33.6%
——10Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.69dCVE-2026-608809.8 CRI33.6%
——10Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).56dCVE-2026-35405—33.6%
——10——CVE-2024-21028—33.6%
——10——CVE-2024-51625—33.6%
——10——CVE-2026-47426—33.6%
——10Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in ClientCredentialsReader. An attacker controlling any registered client with published keys, including one obtained through open dynamic registration when enabled, can authenticate as another client whose keys are exposed through jwks_uri and mint tokens in that client's name across realms in the same OpenAM process. This issue is fixed in version 16.1.1.5dCVE-2026-27584—33.6%
——10——CVE-2023-22075—33.6%
——10——CVE-2015-8744—33.6%
——10——CVE-2024-51570—33.6%
——10——CVE-2020-37067—33.6%
——10——CVE-2026-34211—33.6%
——10——CVE-2025-36124—33.6%
——10——CVE-2026-21964—33.6%
——10——CVE-2015-7812—33.6%
——10——CVE-2022-33881—33.6%
——10——CVE-2024-42416—33.6%
——10——CVE-2026-2013010.0 CRI33.6%
——10As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20130 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.4dCVE-2014-9888—33.6%
——10——CVE-2014-9934—33.6%
——10——CVE-2022-3232—33.6%
——10——CVE-2026-535997.5 HIG33.6%
——10REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.13dCVE-2024-13696—33.6%
——10——