Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,308
- Medium6,572
- Low708
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62863—30.2%
——9——CVE-2019-14822—30.2%
——9——CVE-2022-38863—30.2%
——9——CVE-2021-40396—30.2%
——9——CVE-2023-21900—30.2%
——9——CVE-2026-45570—30.2%
——9——CVE-2024-30965—30.2%
——9——CVE-2024-13955—30.2%
——9——CVE-2026-22264—30.2%
——9——CVE-2024-31489—30.2%
——9——CVE-2014-4659—30.2%
——9——CVE-2025-52731—30.2%
——9——CVE-2024-7825—30.2%
——9——CVE-2026-538718.1 HIG30.2%
——9Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access sessions, files, and resources across different profiles.1dCVE-2026-792167.5 HIG30.2%
——9Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)23dCVE-2024-3862—30.2%
——9——CVE-2025-12657—30.2%
——9——CVE-2025-0476—30.2%
——9——CVE-2025-4493—30.2%
——9——CVE-2025-9434—30.2%
——9——CVE-2022-38858—30.2%
——9——CVE-2019-19694—30.2%
——9——CVE-2023-52274—30.2%
——9——CVE-2026-310698.8 HIG30.2%
——9BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.56dCVE-2024-55196—30.2%
——9——CVE-2025-54692—30.2%
——9——CVE-2025-29000—30.2%
——9——CVE-2025-62864—30.2%
——9——CVE-2026-834288.1 HIG30.2%
——9Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).2dCVE-2026-834308.1 HIG30.2%
——9Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).2dCVE-2026-23495—30.2%
——9——CVE-2021-27761—30.2%
——9——CVE-2024-9956—30.2%
——9——CVE-2026-765764.3 MED30.2%
——9A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownload of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java of the component Common Download Endpoint. Performing a manipulation of the argument fileName/resource results in path traversal. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.28dCVE-2025-12346—30.2%
——9——CVE-2006-3123—30.2%
——9——CVE-2026-834298.1 HIG30.2%
——9Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).2dCVE-2012-2252—30.2%
——9——CVE-2023-6349—30.2%
——9——CVE-2023-48014—30.2%
——9——