Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,330
- High8,526
- Medium6,729
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-56255—31.2%
——9——CVE-2024-48125—31.2%
——9——CVE-2025-24471—31.2%
——9——CVE-2021-21726—31.2%
——9——CVE-2023-5529—31.2%
——9——CVE-2024-13633—31.2%
——9——CVE-2024-25696—31.2%
——9——CVE-2026-334435.9 MED31.2%
——9CVE-2026-33443 is a memory management error in
Secure Access servers prior to 14.55. Attackers with an intimate knowledge of
and total control over the tunnel protocol can create a persistent DoS against
the server.66dCVE-2026-831698.1 HIG31.2%
——9Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).3dCVE-2009-5044—31.2%
——9——CVE-2026-890137.5 HIG31.2%
——9Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.2dCVE-2025-3163—31.2%
——9——CVE-2024-25708—31.2%
——9——CVE-2024-20367—31.2%
——9——CVE-2022-46784—31.2%
——9——CVE-2019-5511—31.2%
——9——CVE-2022-35092—31.2%
——9——CVE-2023-3369—31.2%
——9——CVE-2017-14575—31.2%
——9——CVE-2017-10750—31.2%
——9——CVE-2017-14548—31.2%
——9——CVE-2026-711615.3 MED31.2%
——9Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).22dCVE-2017-14692—31.2%
——9——CVE-2026-31965—31.2%
——9——CVE-2025-138116.3 MED31.2%
——9A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/common/constant/factory/PageFactory.java. Executing a manipulation of the argument sort can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2020-25595—31.2%
——9——CVE-2026-4057—31.2%
——9——CVE-2019-25452—31.2%
——9——CVE-2026-3893—31.2%
——9——CVE-2024-8276—31.2%
——9——CVE-2017-14580—31.2%
——9——CVE-2026-933828.8 HIG31.2%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-178078.8 HIG31.2%
——9Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)47dCVE-2017-10748—31.2%
——9——CVE-2019-14935—31.2%
——9——CVE-2024-11203—31.2%
——9——CVE-2009-5139—31.2%
——9——CVE-2017-14291—31.2%
——9——CVE-2024-5079—31.2%
——9——CVE-2017-14549—31.2%
——9——