Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-3516—31.4%
——9——CVE-2026-703225.5 MED31.4%
——9Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.38dCVE-2026-349539.1 CRI31.4%
——9PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.58dCVE-2006-0741—31.4%
——9——CVE-2026-472537.3 HIG31.4%
——9Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve .. segments outside $XDG_CACHE_HOME/anyquery/plugins/ and os.RemoveAll to recursively delete any reachable directory writable by the Anyquery server process. This causes permanent data loss and denial of service without disclosing file contents. This issue is fixed in version 0.4.5.6dCVE-2002-0788—31.4%
——9——CVE-2026-608256.6 MED31.4%
——9Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).53dCVE-2025-45610—31.4%
——9——CVE-2008-5690—31.4%
——9——CVE-1999-0094—31.4%
——9——CVE-2023-51839—31.4%
——9——CVE-2009-3897—31.4%
——9——CVE-2009-3035—31.4%
——9——CVE-2005-2456—31.4%
——9——CVE-2025-43450—31.4%
——9——CVE-2023-22856—31.4%
——9——CVE-2013-5163—31.4%
——9——CVE-2026-703155.5 MED31.4%
——9Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.38dCVE-2026-469238.0 HIG31.4%
——9Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).46dCVE-2013-2195—31.4%
——9——CVE-2024-29116—31.4%
——9——CVE-2019-0123—31.4%
——9——CVE-2024-9413—31.4%
——9——CVE-2022-25738—31.4%
——9——CVE-2026-2666—31.4%
——9——CVE-2026-703165.5 MED31.4%
——9Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.38dCVE-2024-29124—31.4%
——9——CVE-2022-33229—31.4%
——9——CVE-2024-11891—31.4%
——9——CVE-2026-607908.0 HIG31.4%
——9Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Sales Offline. While the vulnerability is in Oracle Sales Offline, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Sales Offline. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).56dCVE-2021-47831—31.4%
——9——CVE-2023-50928—31.4%
——9——CVE-2026-703255.5 MED31.4%
——9Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.38dCVE-2022-25732—31.4%
——9——CVE-2008-2931—31.4%
——9——CVE-2026-56351—31.4%
——9——CVE-2023-28727—31.4%
——9——CVE-2026-0729—31.4%
——9——CVE-2000-0364—31.4%
——9——CVE-2005-3001—31.4%
——9——