Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-23419—33.4%
——10——CVE-2024-13922—33.4%
——10——CVE-2026-109628.8 HIG33.4%
——10Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)62dCVE-2024-24579—33.4%
——10——CVE-2026-33281—33.4%
——10——CVE-2020-28013—33.4%
——10——CVE-2026-27407—33.4%
——10——CVE-2019-25524—33.4%
——10——CVE-2022-33646—33.4%
——10——CVE-2021-4421—33.4%
——10——CVE-2024-25746—33.4%
——10——CVE-2024-26145—33.4%
——10——CVE-2026-199798.3 HIG33.4%
——10A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."33dCVE-2025-0165—33.4%
——10——CVE-2023-34335—33.4%
——10——CVE-2022-46330—33.4%
——10——CVE-2023-217047.8 HIG33.4%
——10Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability34dCVE-2024-20764—33.4%
——10——CVE-2026-592047.5 HIG33.4%
——10Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.63dCVE-2024-20763—33.4%
——10——CVE-2023-4876—33.4%
——10——CVE-2025-39536—33.4%
——10——CVE-2026-470096.5 MED33.4%
——10Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).53dCVE-2024-4766—33.4%
——10——CVE-2021-4424—33.4%
——10——CVE-2026-568776.3 MED33.4%
——10The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.69dCVE-2026-30938—33.4%
——10——CVE-2024-12103—33.4%
——10——CVE-2024-9692—33.4%
——10——CVE-2024-50516—33.4%
——10——CVE-2024-1175—33.4%
——10——CVE-2017-4935—33.4%
——10——CVE-2025-64114—33.4%
——10——CVE-2026-136994.3 MED33.4%
——10In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id but omits data_point, the server directly calls unwrap() on request.data_point, triggering a panic in the Tokio worker thread. This issue can be triggered by any client holding a valid JWT token. Unauthenticated or invalid-token requests are rejected and do not reach the vulnerable path. The panic causes the individual gRPC call to be cancelled but does not terminate the Databroker process, which remains available for subsequent requests.70dCVE-2025-26600—33.4%
——10——CVE-2025-28028—33.4%
——10——CVE-2019-17044—33.4%
——10——CVE-2019-4101—33.4%
——10——CVE-2018-1685—33.4%
——10——CVE-2017-4937—33.4%
——10——