Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,742
- Medium6,778
- Low726
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-1509—29.9%
——9——CVE-2000-0602—29.9%
——9——CVE-2025-31742—29.9%
——9——CVE-2004-1758—29.9%
——9——CVE-2024-6033—29.9%
——9——CVE-2008-1205—29.9%
——9——CVE-2026-763568.1 HIG29.9%
——9In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.22dCVE-2025-26942—29.9%
——9——CVE-2020-1981—29.9%
——9——CVE-2024-36414—29.9%
——9——CVE-2025-30545—29.9%
——9——CVE-2026-610208.1 HIG29.9%
——9Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customers Online accessible data as well as unauthorized access to critical data or complete access to all Oracle Customers Online accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).46dCVE-2024-37095—29.9%
——9——CVE-2024-11973—29.9%
——9——CVE-2024-54153—29.9%
——9——CVE-2022-39161—29.9%
——9——CVE-2025-9402—29.9%
——9——CVE-2026-150178.8 HIG29.9%
——9The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.57dCVE-2026-78085—29.9%
——9Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.8dCVE-2014-9252—29.9%
——9——CVE-2025-24097—29.9%
——9——CVE-2026-708358.1 HIG29.9%
——9Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).21dCVE-2023-31237—29.9%
——9——CVE-2025-9144—29.9%
——9——CVE-2024-13275—29.9%
——9——CVE-2025-31750—29.9%
——9——CVE-2026-708158.1 HIG29.8%
——9Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).15dCVE-2025-30117—29.9%
——9——CVE-2025-5434—29.9%
——9——CVE-2025-32493—29.9%
——9——CVE-2023-23040—29.9%
——9——CVE-2025-30537—29.9%
——9——CVE-2026-75542—29.9%
——9Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages.
When an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries the repositories permission and the scope string begins with repository:. The organization name is never resolved against the principal, and expand_repositories_scope/3 only rewrites the literal repositories scope, so an explicit repository:<name> passes through untouched. Both CDN edges authorize repository access from the token claim without querying the database, so the minted token is read access to that organization's private packages until it expires.
This issue affects hex.pm: from 2025-10-18 before 2026-08-24.17dCVE-2025-6846—29.9%
——9——CVE-2017-5409—29.9%
——9——CVE-2020-3966—29.9%
——9——CVE-2025-12121—29.9%
——9——CVE-2024-54687—29.9%
——9——CVE-2025-26929—29.9%
——9——CVE-2020-0505—29.9%
——9——