Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-4036—32.5%
——10——CVE-2019-16089—32.5%
——10——CVE-2005-1751—32.5%
——10——CVE-2006-1355—32.5%
——10——CVE-2019-15347—32.5%
——10——CVE-2010-0622—32.5%
——10——CVE-2014-3811—32.5%
——10——CVE-2024-49396—32.5%
——10——CVE-2013-3496—32.5%
——10——CVE-2015-1144—32.5%
——10——CVE-2019-19056—32.5%
——10——CVE-2020-35923—32.5%
——10——CVE-2021-40829—32.5%
——10——CVE-2020-35921—32.5%
——10——CVE-2025-30475—32.5%
——10——CVE-2024-50423—32.5%
——10——CVE-2026-100755.3 MED32.5%
——10DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.62dCVE-2023-20180—32.5%
——10——CVE-2025-1830—32.5%
——10——CVE-2022-3233—32.5%
——10——CVE-2020-4497—32.5%
——10——CVE-2026-818295.3 MED32.5%
——10A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inbound JWT without sanitizing path traversal characters or query-string separators. This allows an unauthenticated remote attacker to force the application server to issue GET requests to arbitrary paths on the same origin as the configured key endpoint. As a result, non-public endpoints or internal data reachable on that origin may be read by the attacker before JWT signature verification takes place.6hCVE-2024-8189—32.5%
——10——CVE-2026-33755—32.5%
——10——CVE-2025-69227—32.5%
——10——CVE-2025-59221—32.5%
——10——CVE-2026-812707.5 HIG32.5%
——10Apache Allura: exposure of non-public information via search.
This issue affects Apache Allura: through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.13dCVE-2026-693445.5 MED32.5%
——10Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.4dCVE-2024-57189—32.5%
——10——CVE-2026-696275.5 MED32.5%
——10Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.6dCVE-2026-692865.5 MED32.5%
——10Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.5dCVE-2026-627405.5 MED32.5%
——10Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.36dCVE-2014-1226—32.5%
——10——CVE-2023-44148—32.5%
——10——CVE-2021-1439—32.5%
——10——CVE-2026-62672—32.5%
——10Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). When security.twig_content.process_enabled is enabled, an authenticated page editor can publish a catastrophically backtracking pattern that consumes PHP worker CPU and denies service to site visitors. This issue is fixed in version 2.0.4.12dCVE-2024-29471—32.5%
——10——CVE-2025-34304—32.5%
——10——CVE-2026-871788.7 HIG32.5%
——10Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).3dCVE-2024-44019—32.5%
——10——