Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,753
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-37106—29.7%
——9——CVE-2026-170155.4 MED29.7%
——9IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.25dCVE-1999-0422—29.7%
——9——CVE-2006-2036—29.7%
——9——CVE-2004-1295—29.7%
——9——CVE-2020-24394—29.7%
——9——CVE-2010-3517—29.7%
——9——CVE-2025-54468—29.7%
——9——CVE-2023-25946—29.7%
——9——CVE-2022-43359—29.7%
——9——CVE-2026-63301—29.7%
——9In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can bypass the UI-level restriction and delete the primary language by sending a direct HTTP request to the API endpoint. Successful deletion of the primary language results in a Denial of Service (DoS) of application.
Critically, when combined with a separate Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) an unauthenticated remote attacker can craft a malicious link, which if visited by an authenticated administrator, will trigger the DoS condition without direct access to the application
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.50dCVE-2026-571459.1 CRI29.7%
——9PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.3dCVE-2024-20941—29.7%
——9——CVE-2025-31546—29.7%
——9——CVE-2025-3996—29.7%
——9——CVE-2025-30767—29.7%
——9——CVE-2026-4779—29.7%
——9——CVE-2026-110468.8 HIG29.7%
——9Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)57dCVE-2016-8776—29.7%
——9——CVE-2025-23192—29.7%
——9——CVE-2023-6006—29.7%
——9——CVE-2025-60834—29.7%
——9——CVE-2024-20949—29.7%
——9——CVE-2009-3468—29.7%
——9——CVE-2024-35333—29.7%
——9——CVE-2025-31511—29.7%
——9——CVE-2026-709347.1 HIG29.7%
——9Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).25dCVE-2025-7366—29.7%
——9——CVE-2024-2847—29.7%
——9——CVE-2026-12760—29.7%
——9——CVE-2026-2781—29.7%
——9——CVE-2025-20153—29.7%
——9——CVE-2024-47173—29.7%
——9——CVE-2026-3591—29.7%
——9——CVE-2026-15933—29.7%
——9OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data.
This issue was fixed in version 26.0810dCVE-2026-635175.5 MED29.7%
——9Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.36dCVE-2025-11620—29.7%
——9——CVE-2022-22999—29.7%
——9——CVE-2025-7357—29.7%
——9——CVE-2026-447528.2 HIG29.7%
——9SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.66d