Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-25449—33.4%
——10——CVE-2023-48882—33.4%
——10——CVE-2023-46652—33.4%
——10——CVE-2025-0376—33.4%
——10——CVE-2010-0227—33.4%
——10——CVE-2023-5976—33.4%
——10——CVE-2026-27868—33.4%
——10An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2:
11.02.05.10.02.83dCVE-2008-4863—33.4%
——10——CVE-2026-845545.9 MED33.4%
——10An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to cause a denial-of-service.6dCVE-2026-1589—33.4%
——10——CVE-2025-46247—33.4%
——10——CVE-2016-10117—33.4%
——10——CVE-2016-10123—33.4%
——10——CVE-2026-577277.5 HIG33.4%
——10Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.71dCVE-2000-0534—33.4%
——10——CVE-2026-404307.5 HIG33.4%
——10Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.57dCVE-2015-0949—33.4%
——10——CVE-2023-33793—33.4%
——10——CVE-2026-22598—33.4%
——10——CVE-2026-40967—33.4%
——10——CVE-2023-0591—33.4%
——10——CVE-2020-11957—33.4%
——10——CVE-2017-20188—33.4%
——10——CVE-2023-43990—33.4%
——10——CVE-2026-832707.5 HIG33.4%
——10Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).1dCVE-2023-33789—33.4%
——10——CVE-2026-647793.1 LOW33.4%
——10A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.8dCVE-2023-22100—33.4%
——10——CVE-2016-9101—33.4%
——10——CVE-2026-22626—33.4%
——10——CVE-2023-43991—33.4%
——10——CVE-2025-30256—33.4%
——10——CVE-2023-33787—33.4%
——10——CVE-2026-844447.4 HIG33.4%
——10libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2.7hCVE-2016-10119—33.4%
——10——CVE-2023-33798—33.4%
——10——CVE-2007-5634—33.4%
——10——CVE-2023-36488—33.4%
——10——CVE-2023-33795—33.4%
——10——CVE-2004-0968—33.4%
——10——