Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3576—32.0%
——10——CVE-2023-2228—32.0%
——10——CVE-2019-11137—32.0%
——10——CVE-2013-3233—32.0%
——10——CVE-2011-1745—32.0%
——10——CVE-2011-2022—32.0%
——10——CVE-2026-25140—32.0%
——10——CVE-2024-37883—32.0%
——10——CVE-2023-37038—32.0%
——10——CVE-2022-31030—32.0%
——10——CVE-2023-1189—32.0%
——10——CVE-2017-4950—32.0%
——10——CVE-2026-539857.5 HIG32.0%
——10Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enforcement and a wildcard CORS policy, then emit the service_control event to terminate all active satellite-tracking sessions, SDR recording pipelines, demodulators, decoders, and rotator controllers, with repeated triggering possible in Docker deployments to create a persistent denial-of-service condition.46dCVE-2018-1999041—32.0%
——10——CVE-2015-8553—32.0%
——10——CVE-2025-20644—31.9%
——10——CVE-2006-0494—32.0%
——10——CVE-2026-709589.6 CRI32.0%
——10Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Infrastructure Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).27dCVE-2006-4092—32.0%
——10——CVE-2022-1743—32.0%
——10——CVE-2024-12420—32.0%
——10——CVE-2006-4184—32.0%
——10——CVE-2021-1563—32.0%
——10——CVE-2021-28695—32.0%
——10——CVE-2021-28694—32.0%
——10——CVE-2021-1564—32.0%
——10——CVE-2021-34734—32.0%
——10——CVE-2013-4956—32.0%
——10——CVE-2026-523497.8 HIG32.0%
——10Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename functionality, PedComponentChanger create folder/createfile/rename functionality.60dCVE-2025-50641—32.0%
——10——CVE-2023-37037—32.0%
——10——CVE-2025-43889—32.0%
——10——CVE-2024-0232—32.0%
——10——CVE-2023-37036—32.0%
——10——CVE-2024-1745—32.0%
——10——CVE-2025-59238—31.9%
——10——CVE-2026-178368.8 HIG32.0%
——10Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)49dCVE-2026-20009—32.0%
——10——CVE-2023-37033—32.0%
——10——CVE-2021-0292—32.0%
——10——