Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-14331—31.2%
——9——CVE-2017-1304—31.2%
——9——CVE-2017-14558—31.2%
——9——CVE-2023-6109—31.2%
——9——CVE-2026-762627.5 HIG31.2%
——9In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/about-splunk-sidecars) in the Splunk documentation.24dCVE-2026-792909.6 CRI31.2%
——9Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)19dCVE-2024-52597—31.2%
——9——CVE-2024-52973—31.2%
——9——CVE-2014-7298—31.2%
——9——CVE-2024-22547—31.2%
——9——CVE-2026-8952—31.2%
——9——CVE-2025-9551—31.2%
——9——CVE-2017-14286—31.2%
——9——CVE-2023-24747—31.2%
——9——CVE-2024-35134—31.2%
——9——CVE-2025-45661—31.2%
——9——CVE-2026-3893—31.2%
——9——CVE-2025-138116.3 MED31.2%
——9A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/common/constant/factory/PageFactory.java. Executing a manipulation of the argument sort can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2023-34474—31.2%
——9——CVE-2025-3050—31.2%
——9——CVE-2020-25595—31.2%
——9——CVE-2025-67877—31.2%
——9——CVE-2017-1382—31.2%
——9——CVE-2018-5916—31.2%
——9——CVE-2026-140878.8 HIG31.2%
——9Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)80dCVE-2026-200065.8 MED31.2%
——9A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this vulnerability by sending a crafted TLS packet to an affected system. A successful exploit could allow the attacker to cause a device that is running Cisco Secure FTD Software to drop network traffic, resulting in a DoS condition.
Note: TLS 1.3 is not affected by this vulnerability.30dCVE-2017-14275—31.2%
——9——CVE-2017-10749—31.2%
——9——CVE-2025-30507—31.2%
——9——CVE-2017-14561—31.2%
——9——CVE-2017-14288—31.2%
——9——CVE-2017-14573—31.2%
——9——CVE-2017-14566—31.2%
——9——CVE-2024-27330—31.2%
——9——CVE-2013-2013—31.2%
——9——CVE-2017-14568—31.2%
——9——CVE-2026-610168.2 HIG31.2%
——9Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).31dCVE-2017-14289—31.2%
——9——CVE-2025-23053—31.2%
——9——CVE-2024-49602—31.2%
——9——