Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48331—29.2%
——9——CVE-2017-0848—29.2%
——9——CVE-2017-0851—29.2%
——9——CVE-2025-13023—29.2%
——9——CVE-2003-1124—29.2%
——9——CVE-2015-1324—29.2%
——9——CVE-2025-0781—29.2%
——9——CVE-2026-3963—29.2%
——9——CVE-2026-872567.7 HIG29.2%
——9Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).1dCVE-2024-26272—29.2%
——9——CVE-2026-816347.5 HIG29.2%
——9In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.1dCVE-2026-831417.7 HIG29.2%
——9Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. While the vulnerability is in Oracle Field Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).1dCVE-2026-66539.8 CRI29.2%
——9Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.65dCVE-2024-4564—29.2%
——9——CVE-2026-812806.5 MED29.2%
——9Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.16dCVE-2024-20251—29.2%
——9——CVE-2025-41672—29.2%
——9——CVE-2026-3555—29.2%
——9——CVE-2023-22061—29.2%
——9——CVE-2020-37087—29.2%
——9——CVE-2025-9292—29.2%
——9——CVE-2026-5500—29.2%
——9——CVE-2023-50954—29.2%
——9——CVE-2024-11576—29.2%
——9——CVE-2007-5690—29.2%
——9——CVE-2025-55194—29.2%
——9——CVE-2023-46018—29.2%
——9——CVE-2022-2905—29.2%
——9——CVE-2025-20659—29.2%
——9——CVE-2023-46017—29.2%
——9——CVE-2023-38920—29.2%
——9——CVE-2024-12642—29.2%
——9——CVE-2024-3035—29.1%
——9——CVE-2025-13026—29.2%
——9——CVE-2025-36041—29.2%
——9——CVE-2026-601205.4 MED29.2%
——9Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer.65dCVE-2026-428499.3 CRI29.2%
——9authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.57dCVE-2023-22863—29.2%
——9——CVE-2013-4343—29.2%
——9——CVE-2025-9412—29.2%
——9——