Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,735
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-144097.5 HIG29.9%
——9Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)77dCVE-2024-28775—29.9%
——9——CVE-2019-16355—29.9%
——9——CVE-2026-8309910.0 CRI29.9%
——9Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).2dCVE-2026-768684.9 MED29.9%
——9Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer dereference, resulting in a denial of service.2dCVE-2025-5519—29.9%
——9——CVE-2023-46182—29.9%
——9——CVE-2025-0696—29.9%
——9——CVE-2026-144267.5 HIG29.9%
——9Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)77dCVE-2024-34099—29.9%
——9——CVE-2026-168708.8 HIG29.9%
——9Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests — including credentials and tokens — to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. The Snowflake PHP PDO Driver and Snowflake ODBC Driver embed the affected library; fixes are available in versions 4.1.0 and 3.19.0 respectively. Users must manually upgrade.50dCVE-2026-872388.8 HIG29.9%
——9Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).2dCVE-2025-9431—29.9%
——9——CVE-2016-10102—29.9%
——9——CVE-2026-46721—29.9%
——9——CVE-2024-12584—29.9%
——9——CVE-2025-66862—29.9%
——9——CVE-2024-21035—29.9%
——9——CVE-2026-325599.9 CRI29.9%
——9Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.22dCVE-2025-49124—29.9%
——9——CVE-2024-11154—29.9%
——9——CVE-2023-7234—29.9%
——9——CVE-2023-37360—29.9%
——9——CVE-2024-13133—29.9%
——9——CVE-2024-41916—29.9%
——9——CVE-2025-27864.3 MED29.9%
——9A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.10dCVE-2025-43982—29.9%
——9——CVE-2026-44635—29.9%
——9——CVE-2026-564439.6 CRI29.9%
——9Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #3711823dCVE-2026-7113—29.9%
——9——CVE-2024-21026—29.9%
——9——CVE-2025-28233—29.9%
——9——CVE-2024-8388—29.9%
——9——CVE-2020-8026—29.9%
——9——CVE-2025-20349—29.9%
——9——CVE-2024-33598—29.9%
——9——CVE-2025-53654—29.9%
——9——CVE-2026-619807.5 HIG29.9%
——9Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.35dCVE-2024-7869—29.9%
——9——CVE-2025-30539—29.9%
——9——