Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,753
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-36001—29.7%
——9——CVE-2024-43944—29.7%
——9——CVE-2016-6402—29.7%
——9——CVE-2025-50503—29.7%
——9——CVE-2025-362547.4 HIG29.7%
——9IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.25dCVE-2011-2678—29.7%
——9——CVE-2016-6428—29.7%
——9——CVE-2026-709337.1 HIG29.7%
——9Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).25dCVE-2026-733105.9 MED29.7%
——9XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted authorization code using a mismatched redirect URI to steal OAuth2 tokens from intercepted authorization flows.7dCVE-2024-0240—29.7%
——9——CVE-2025-39528—29.7%
——9——CVE-2024-24254—29.6%
——9——CVE-2024-30443—29.7%
——9——CVE-2026-628425.5 MED29.7%
——9Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.36dCVE-2024-24740—29.7%
——9——CVE-2025-23829—29.7%
——9——CVE-2026-917289.6 CRI29.7%
——9Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)1dCVE-2026-504527.0 HIG29.7%
——9Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.58dCVE-2019-11140—29.7%
——9——CVE-2024-21045—29.7%
——9——CVE-2023-22093—29.7%
——9——CVE-2021-34740—29.7%
——9——CVE-2021-34713—29.7%
——9——CVE-2026-64971—29.7%
——9ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.21dCVE-2024-13228—29.7%
——9——CVE-2026-571378.8 HIG29.7%
——9PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false records tool_rejected only after the denied tool has already produced side effects and populated toolResults. Applications using onToolCall as a human or policy approval boundary can therefore execute rejected file, command, API, or data-modifying operations. This issue is fixed in version 1.7.2.3dCVE-2025-7357—29.7%
——9——CVE-2025-24644—29.7%
——9——CVE-2026-447528.2 HIG29.7%
——9SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.66dCVE-2026-13311—29.7%
——9——CVE-2026-503487.0 HIG29.7%
——9Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.58dCVE-2025-29311—29.7%
——9——CVE-2026-46932—29.7%
——9——CVE-2025-25115—29.7%
——9——CVE-2025-11994—29.7%
——9——CVE-2026-7112—29.6%
——9——CVE-2024-10937—29.7%
——9——CVE-2023-38353—29.7%
——9——CVE-2026-94644.7 MED29.7%
——9A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.57dCVE-2023-39731—29.7%
——9——