Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-4626—31.8%
——10——CVE-2026-710076.8 MED31.8%
——10Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).28dCVE-2020-1835—31.8%
——10——CVE-2023-26146—31.8%
——10——CVE-2025-14990—31.8%
——10——CVE-2009-4902—31.8%
——10——CVE-2024-27091—31.8%
——10——CVE-2023-49700—31.8%
——10——CVE-2023-28761—31.8%
——10——CVE-2023-23467—31.8%
——10——CVE-2026-547046.5 MED31.8%
——10OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends. This issue has been fixed in version 2.28.0.77dCVE-2024-8475—31.8%
——10——CVE-2023-4824—31.8%
——10——CVE-2023-51463—31.8%
——10——CVE-2024-3791—31.8%
——10——CVE-2013-5833—31.8%
——10——CVE-2023-29012—31.8%
——10——CVE-2024-54254—31.8%
——10——CVE-2024-0879—31.8%
——10——CVE-2026-58738.8 HIG31.8%
——10Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)59dCVE-2025-45333—31.8%
——10——CVE-2024-3793—31.8%
——10——CVE-2018-1664—31.8%
——10——CVE-2005-1774—31.8%
——10——CVE-2024-25182—31.8%
——10——CVE-2026-177228.3 HIG31.8%
——10Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)49dCVE-2024-28982—31.8%
——10——CVE-2025-11985—31.8%
——10——CVE-2010-5164—31.8%
——10——CVE-2008-1517—31.8%
——10——CVE-2024-3790—31.8%
——10——CVE-2023-457457.9 HIG31.8%
——10Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.21dCVE-2025-51040—31.8%
——10——CVE-2020-17365—31.8%
——10——CVE-2024-12201—31.8%
——10——CVE-2023-31183—31.8%
——10——CVE-2025-59974—31.8%
——10——CVE-2023-33849—31.8%
——10——CVE-2017-15860—31.8%
——10——CVE-2026-892749.1 CRI31.8%
——10The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.3h