Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-26958—31.9%
——10——CVE-2023-36259—31.9%
——10——CVE-2025-5103—31.9%
——10——CVE-2022-0486—31.9%
——10——CVE-2025-25945—31.9%
——10——CVE-2020-28191—31.9%
——10——CVE-2026-42473—31.9%
——10——CVE-2020-4230—31.9%
——10——CVE-2017-7487—31.9%
——10——CVE-2005-0596—31.9%
——10——CVE-2005-3071—31.9%
——10——CVE-2022-35097—31.9%
——10——CVE-2026-7071—31.9%
——10——CVE-2026-47151—31.9%
——10——CVE-2023-39413—31.9%
——10——CVE-2026-2966—31.9%
——10——CVE-2025-15110—31.9%
——10——CVE-2026-34917—31.9%
——10——CVE-2026-42472—31.9%
——10——CVE-2026-45035—31.9%
——10——CVE-2025-10249—31.9%
——10——CVE-2026-834258.5 HIG31.9%
——10Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).5dCVE-2024-58385—31.9%
——10——CVE-2025-23700—31.9%
——10——CVE-2023-47051—31.9%
——10——CVE-2025-62235—31.9%
——10——CVE-2015-5231—31.9%
——10——CVE-2022-21471—31.9%
——10——CVE-2019-18645—31.9%
——10——CVE-2026-50745—31.9%
——10——CVE-2024-8842—31.9%
——10——CVE-2024-5866—31.9%
——10——CVE-2022-42956—31.9%
——10——CVE-2026-335778.1 HIG31.9%
——10OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes validation in node-pairing.ts to extend privileges onto paired nodes beyond their authorization level.59dCVE-2023-35128—31.9%
——10——CVE-2024-31137—31.9%
——10——CVE-2026-133346.1 MED31.9%
——10The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.74dCVE-2024-28133—31.9%
——10——CVE-2023-50093—31.9%
——10——CVE-2026-446978.6 HIG31.9%
——10Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip payload. A single packet is sufficient to OOM-kill a validator with conventional memory provisioning. Fleet-wide application affects chain liveness. This vulnerability is fixed in 1.7.17.62d