Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,319
- High8,273
- Medium6,560
- Low705
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-4823—30.4%
——9——CVE-2023-46316—30.4%
——9——CVE-2025-13303—30.4%
——9——CVE-2009-0370—30.4%
——9——CVE-2014-1422—30.4%
——9——CVE-2015-4177—30.4%
——9——CVE-2005-3124—30.4%
——9——CVE-2025-0215—30.4%
——9——CVE-2000-0618—30.4%
——9——CVE-2016-3907—30.4%
——9——CVE-2016-6749—30.4%
——9——CVE-2008-2515—30.4%
——9——CVE-2016-8814—30.4%
——9——CVE-2019-1010221—30.4%
——9——CVE-2017-7493—30.4%
——9——CVE-2024-24903—30.4%
——9——CVE-2016-6748—30.4%
——9——CVE-2026-834817.2 HIG30.4%
——9Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts. Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).2dCVE-2024-29392—30.4%
——9——CVE-2026-452298.8 HIG30.4%
——9Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services.66dCVE-2026-45272—30.4%
——9MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quotes or newline characters, and SettingsLoader.dumpfile in webserver/loader.py concatenates those names into the generated Python source file auto.py without escaping them. An administrator can submit a crafted SOCIAL_AUTH key name that closes the settings dictionary and injects arbitrary Python statements. The application later executes those statements because SettingsLoader.loadfile imports auto.py as a module, and setting autoreload to true invokes restart_async so a process supervisor restarts the service and triggers the import. Successful exploitation executes commands with the privileges of the application service account and can disclose data, modify files, establish persistence, or disrupt the service. Related authorization and registration vulnerabilities can reduce the effective privilege requirement in a chained attack, but the standalone vulnerability requires administrator access. This issue is fixed in version 3.42.0.9dCVE-2023-1005—30.4%
——9——CVE-2025-3640—30.4%
——9——CVE-2016-8813—30.4%
——9——CVE-2026-488079.1 CRI30.4%
——9Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0.64dCVE-2026-370688.1 HIG30.4%
——9Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.16dCVE-2024-44101—30.4%
——9——CVE-2017-10221—30.4%
——9——CVE-2020-23906—30.4%
——9——CVE-2016-8815—30.4%
——9——CVE-2005-4803—30.4%
——9——CVE-2016-8818—30.4%
——9——CVE-2016-8819—30.4%
——9——CVE-2025-24345—30.3%
——9——CVE-2016-6494—30.4%
——9——CVE-2024-21417—30.4%
——9——CVE-2006-4982—30.4%
——9——CVE-2024-1952—30.4%
——9——CVE-2026-832299.1 CRI30.4%
——9Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).2dCVE-2009-0605—30.4%
——9——