Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,368
- High8,677
- Medium6,690
- Low718
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2007-4051—30.1%
——9——CVE-2004-1453—30.1%
——9——CVE-2025-69347—30.1%
——9——CVE-2026-91065.5 MED30.1%
——9A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.78dCVE-2026-23525—30.1%
——9——CVE-2026-43918—30.1%
——9FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing authenticated sessions are not invalidated. The session identity loaders in src/di.php (loggedin_client and loggedin_admin) only reject sessions if the backing account record no longer exists in the database. They do not verify that the account's status is still active. This allows a suspended or deactivated user to retain full access until their session naturally expires. This issue has been fixed in version 0.8.0.72dCVE-2022-33065—30.1%
——9——CVE-2018-7572—30.1%
——9——CVE-2026-47657—30.1%
——9HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.57dCVE-2025-12862—30.1%
——9——CVE-2026-57868—30.1%
——9MicroRealEstate is affected by broken object-level access controls in PDF generator functionality.
This issue affects MicroRealEstate: through 1.0.0-alpha3.73dCVE-2025-53208—30.1%
——9——CVE-2025-44007—30.1%
——9——CVE-2016-9637—30.1%
——9——CVE-2025-30275—30.1%
——9——CVE-2025-56795—30.1%
——9——CVE-2025-62180—30.1%
——9——CVE-2026-1258—30.1%
——9——CVE-2025-27591—30.1%
——9——CVE-2024-25907—30.1%
——9——CVE-2020-26186—30.1%
——9——CVE-2020-27821—30.1%
——9——CVE-2026-710796.5 MED30.1%
——9Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).16dCVE-2021-32991—30.1%
——9——CVE-2024-25922—30.1%
——9——CVE-2005-0624—30.1%
——9——CVE-2005-3147—30.1%
——9——CVE-2025-44006—30.1%
——9——CVE-2026-11779—30.1%
——9——CVE-2026-41566—30.1%
——9——CVE-2022-23691—30.1%
——9——CVE-2022-36070—30.1%
——9——CVE-2024-12349—30.1%
——9——CVE-2026-59190—30.1%
——9——CVE-2026-757263.5 LOW30.1%
——9Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.8dCVE-2025-30267—30.1%
——9——CVE-2025-64105—30.1%
——9——CVE-2024-21273—30.1%
——9——CVE-2025-2974—30.1%
——9——CVE-2025-12613—30.1%
——9——