Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-27704—29.2%
——9——CVE-2026-624165.3 MED29.2%
——9Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.45dCVE-2024-57174—29.2%
——9——CVE-2024-3853—29.2%
——9——CVE-2022-25836—29.2%
——9——CVE-2025-31881—29.2%
——9——CVE-2023-53882—29.2%
——9——CVE-2026-7468—29.2%
——9——CVE-2024-4970—29.2%
——9——CVE-2014-2667—29.2%
——9——CVE-2026-56309—29.2%
——9——CVE-2024-27801—29.2%
——9——CVE-2025-6766—29.2%
——9——CVE-2023-39993—29.2%
——9——CVE-2017-10408—29.2%
——9——CVE-2025-59155—29.2%
——9——CVE-2007-1226—29.2%
——9——CVE-2025-58629—29.2%
——9——CVE-2025-53043—29.2%
——9——CVE-2025-30896—29.2%
——9——CVE-2026-15285—29.2%
——9——CVE-2025-2228—29.2%
——9——CVE-2024-29776—29.2%
——9——CVE-2023-28441—29.2%
——9——CVE-2026-34530—29.2%
——9——CVE-2022-2966—29.2%
——9——CVE-2023-40723—29.2%
——9——CVE-2026-272207.8 HIG29.2%
——9Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.21dCVE-2022-0646—29.2%
——9——CVE-2026-610678.0 HIG29.2%
——9Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).52dCVE-2026-52822—29.2%
——9Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or activity has been revoked. TimesheetVoter evaluates the own-timesheet permission before current team access, and its canStart() logic validates object visibility but does not verify the user's current team access to the referenced project and activity. An old entry therefore acts as a persistent capability to create new time records under an unauthorized project and activity, corrupting budgets, statistics, reports, and invoices after an administrative revocation. This issue is fixed in version 2.58.0.3dCVE-2026-52828—29.2%
——9Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API routes and user interface. A teamlead can directly access the export template creation and editing web routes to create or modify global ExportTemplate records marked available to all users, altering export columns, renderer, format, and output used by other users and administrators. This issue is fixed in version 2.58.0.3dCVE-2026-42809—29.2%
——9——CVE-2022-4353—29.2%
——9——CVE-2026-648639.1 CRI29.2%
——9goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4.49dCVE-2026-17593—29.2%
——9An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.16dCVE-2025-9796—29.2%
——9——CVE-2023-28786—29.2%
——9——CVE-2022-4401—29.2%
——9——CVE-2026-15297—29.2%
——9——