Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,753
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-1215—29.6%
——9——CVE-2021-40088—29.6%
——9——CVE-2017-17466—29.6%
——9——CVE-2024-39386—29.6%
——9——CVE-2026-94957.3 HIG29.6%
——9Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.57dCVE-2026-762176.5 MED29.6%
——9GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.15dCVE-2024-39655—29.6%
——9——CVE-2024-29802—29.6%
——9——CVE-2024-36600—29.6%
——9——CVE-2026-249118.6 HIG29.6%
——9Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.17dCVE-2024-30543—29.6%
——9——CVE-2014-5646—29.6%
——9——CVE-2023-42147—29.6%
——9——CVE-2026-21682—29.6%
——9——CVE-2008-3609—29.6%
——9——CVE-2013-0111—29.6%
——9——CVE-2013-0110—29.6%
——9——CVE-2020-0598—29.6%
——9——CVE-2003-0697—29.6%
——9——CVE-2021-28950—29.6%
——9——CVE-2024-3306—29.6%
——9——CVE-2024-8843—29.6%
——9——CVE-2022-3677—29.6%
——9——CVE-2025-2697—29.6%
——9——CVE-2024-23561—29.6%
——9——CVE-2019-20769—29.6%
——9——CVE-2025-1005—29.6%
——9——CVE-2021-2443—29.6%
——9——CVE-2026-22598—29.6%
——9——CVE-2026-831788.0 HIG29.6%
——9Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).2dCVE-2017-17468—29.6%
——9——CVE-2007-0738—29.6%
——9——CVE-2023-2762—29.6%
——9——CVE-2015-1900—29.6%
——9——CVE-2026-1134—29.6%
——9——CVE-2004-2394—29.6%
——9——CVE-2026-659456.5 MED29.6%
——9Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.32dCVE-2026-4101—29.6%
——9——CVE-2016-3810—29.6%
——9——CVE-2026-2682—29.6%
——9——