Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-3760—29.0%
——9——CVE-2025-31754—29.0%
——9——CVE-2025-31747—29.0%
——9——CVE-2025-31748—29.0%
——9——CVE-2025-26537—29.0%
——9——CVE-2025-31738—29.0%
——9——CVE-2025-31849—29.0%
——9——CVE-2024-13150—29.0%
——9——CVE-2026-880155.3 MED29.0%
——9rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range start through Object.Open and openTranslatedLink. The function slices the target string as linkdst[offset:], so a Range start larger than the target length causes a deterministic slice-bounds panic when lib/http/serve exposes the object through HTTP or WebDAV. Go net/http normally recovers the panic per connection, causing request-level denial of service rather than terminating the entire process. This issue is fixed in version 1.75.1.7dCVE-2025-31731—29.0%
——9——CVE-2025-39514—29.0%
——9——CVE-2026-54518—29.0%
——9——CVE-2026-606808.1 HIG29.0%
——9Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).27dCVE-2025-31783—29.0%
——9——CVE-2025-31737—29.0%
——9——CVE-2019-20532—29.0%
——9——CVE-2025-31829—29.0%
——9——CVE-2025-31740—29.0%
——9——CVE-2025-67897—29.0%
——9——CVE-2025-4738—29.0%
——9——CVE-2025-31771—29.0%
——9——CVE-2025-31762—29.0%
——9——CVE-2025-39529—29.0%
——9——CVE-2025-30776—29.0%
——9——CVE-2026-2711—29.0%
——9——CVE-2025-31804—29.0%
——9——CVE-2025-31770—29.0%
——9——CVE-2025-31847—29.0%
——9——CVE-2026-625439.8 CRI29.0%
——9Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).23dCVE-2026-28461—29.0%
——9——CVE-2024-4384—29.0%
——9——CVE-2026-76848—29.0%
——9Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.14dCVE-2025-30826—29.0%
——9——CVE-2009-0874—29.0%
——9——CVE-2018-1505—29.0%
——9——CVE-2025-31743—29.0%
——9——CVE-2025-30850—29.0%
——9——CVE-2025-31730—29.0%
——9——CVE-2025-31815—29.0%
——9——CVE-2025-30812—29.0%
——9——