Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-9122—29.1%
——9——CVE-2007-3337—29.1%
——9——CVE-2009-2912—29.1%
——9——CVE-2024-50552—29.1%
——9——CVE-2008-2552—29.1%
——9——CVE-2025-31478—29.1%
——9——CVE-2022-26359—29.1%
——9——CVE-2026-831519.8 CRI29.1%
——9Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).1dCVE-2026-728829.9 CRI29.1%
——9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for a service can inject shell metacharacters into filePath, causing Dokploy to execute attacker-controlled commands on the configured remote managed server over SSH. In the default deployment model, this yields direct remote host RCE from the web interface.9dCVE-2024-12549—29.1%
——9——CVE-2024-50549—29.1%
——9——CVE-2022-20405—29.1%
——9——CVE-2026-801938.8 HIG29.1%
——9Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.17dCVE-2024-50553—29.1%
——9——CVE-2025-58789—29.1%
——9——CVE-2023-48116—29.1%
——9——CVE-2026-351857.5 HIG29.1%
——9HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. This vulnerability is fixed in 25.0.0.55dCVE-2026-627617.8 HIG29.1%
——9Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.15dCVE-2009-1146—29.1%
——9——CVE-2007-6285—29.1%
——9——CVE-2009-0132—29.1%
——9——CVE-2022-20384—29.1%
——9——CVE-2024-1987—29.1%
——9——CVE-2026-48524—29.1%
——9——CVE-2024-10858—29.1%
——9——CVE-2024-32805—29.1%
——9——CVE-2026-322817.5 HIG29.1%
——9Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.55dCVE-2024-37161—29.1%
——9——CVE-2024-5784—29.1%
——9——CVE-2025-48299—29.1%
——9——CVE-2025-13211—29.1%
——9——CVE-2023-48115—29.1%
——9——CVE-2024-28581—29.1%
——9——CVE-2024-2337—29.1%
——9——CVE-2025-49549—29.1%
——9——CVE-2026-91256.4 MED29.1%
——9The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.20dCVE-2024-13605—29.1%
——9——CVE-2026-850303.7 LOW29.1%
——9A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown function of the file service/server/routes_agent.py of the component selfRegister API Endpoint. Such manipulation of the argument initial_balance leads to business logic errors. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. profit_percent_for_display() divides by INITIAL_CAPITAL + deposited, and challenge scoring's return_pct also normalises against the attacker-inflated starting_cash. So an inflated initial_balance does not yield artificial percent returns - it inflates the absolute cash/equity column only, which is a cosmetic/leaderboard-gaming concern in a simulated game.13dCVE-2020-36853—29.1%
——9——CVE-2019-11163—29.1%
——9——