Vulnerabilities exploitable today
378,026in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,410
- Medium6,691
- Low753
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2008-2578—31.6%
——9——CVE-2024-51826—31.6%
——9——CVE-2026-449459.1 CRI31.6%
——9A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user
global role can gain full administrative access to the Rancher control
plane and transitively to all downstream clusters it manages.
This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.19dCVE-2024-13423—31.6%
——9——CVE-2022-25688—31.6%
——9——CVE-2025-50158—31.6%
——9——CVE-2022-41308—31.6%
——9——CVE-2026-927727.1 HIG31.6%
——9Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.4dCVE-2004-2609—31.6%
——9——CVE-2024-51806—31.6%
——9——CVE-2025-63648—31.6%
——9——CVE-2022-45839—31.6%
——9——CVE-2024-51846—31.6%
——9——CVE-2020-25835—31.6%
——9——CVE-2025-12270—31.6%
——9——CVE-2024-50518—31.6%
——9——CVE-2023-376467.8 HIG31.6%
——9An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.74dCVE-2018-12150—31.6%
——9——CVE-2023-47258—31.6%
——9——CVE-2026-804337.5 HIG31.6%
——9Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.24dCVE-2026-3089—31.6%
——9——CVE-2026-33280—31.6%
——9——CVE-2020-3388—31.6%
——9——CVE-2026-24363—31.6%
——9——CVE-2025-1669—31.6%
——9——CVE-2023-1913—31.6%
——9——CVE-2022-3943—31.6%
——9——CVE-2026-54550—31.6%
——9——CVE-2026-66493—31.6%
——9Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths for delete, copy and move actions lead to path traversal vulnerabilities.26dCVE-2026-66491—31.6%
——9Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the getSource function lead to an arbitrary file read vulnerability.26dCVE-2026-306497.3 HIG31.6%
——9Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component61dCVE-2024-50538—31.6%
——9——CVE-2023-47260—31.6%
——9——CVE-2026-8723010.0 CRI31.6%
——9Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).3dCVE-2026-54393—31.6%
——9——CVE-2024-4869—31.6%
——9——CVE-2024-51851—31.6%
——9——CVE-2013-3399—31.6%
——9——CVE-2023-27460—31.6%
——9——CVE-2024-0875—31.6%
——9——