Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,372
- High8,700
- Medium6,720
- Low721
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-830447.1 HIG30.0%
——9Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).2dCVE-2017-10738—30.0%
——9——CVE-2026-4117—30.0%
——9——CVE-2024-37165—30.0%
——9——CVE-2026-126677.1 HIG30.0%
——9IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to read files from a vulnerable .NET client or cause limited denial of service due to improper handling of XML external entities in RFH2 folder parsing.2dCVE-2017-14297—30.0%
——9——CVE-2019-5691—30.0%
——9——CVE-2019-20570—30.0%
——9——CVE-2025-53407—30.0%
——9——CVE-2015-5763—30.0%
——9——CVE-2026-239814.3 MED30.0%
——9An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards) to associate the chart with. The validation logic in the UpdateChartCommand failed to verify that the user had write permissions for the target dashboards specified in the request body.
This issue affects Apache Superset: before 6.0.0.
Users are recommended to upgrade to version 6.0.0, which fixes the issue.44dCVE-2014-4375—30.0%
——9——CVE-2026-193756.3 MED30.0%
——9A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.37dCVE-2017-10745—30.0%
——9——CVE-2022-38472—30.0%
——9——CVE-2020-15579—30.0%
——9——CVE-1999-0459—30.0%
——9——CVE-2000-1146—30.0%
——9——CVE-2017-14301—30.0%
——9——CVE-2011-3637—30.0%
——9——CVE-2017-14570—30.0%
——9——CVE-2022-32970—30.0%
——9——CVE-2020-25051—30.0%
——9——CVE-2026-876178.8 HIG30.0%
——9Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)8dCVE-2026-84884.3 MED30.0%
——9Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.57dCVE-2026-736138.2 HIG30.0%
——9filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL window to redirect the raw os.Remove call to an out-of-scope target, bypassing ScopedFs scope guards and Perm.Delete checks.10dCVE-2023-21522—30.0%
——9——CVE-2026-730318.7 HIG30.0%
——9telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly to v-html without HTML escaping or sanitization, enabling stored, cross-user, zero-click execution of injected payloads such as image onerror handlers when victims browse or search messages.35dCVE-2025-8027—30.0%
——9——CVE-2023-22375—30.0%
——9——CVE-2017-10742—30.0%
——9——CVE-2025-2928—30.0%
——9——CVE-2026-40561—30.0%
——9——CVE-2017-14295—30.0%
——9——CVE-2023-29639—30.0%
——9——CVE-2025-12244—30.0%
——9——CVE-2024-39755—30.0%
——9——CVE-2024-409297.1 HIG30.0%
——9In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: check n_ssids before accessing the ssids
In some versions of cfg80211, the ssids poinet might be a valid one even
though n_ssids is 0. Accessing the pointer in this case will cuase an
out-of-bound access. Fix this by checking n_ssids first.45dCVE-2017-14574—30.0%
——9——CVE-2023-42321—30.0%
——9——