Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-32952—29.0%
——9——CVE-2022-33283—29.0%
——9——CVE-2014-2277—29.0%
——9——CVE-2013-3797—29.0%
——9——CVE-2014-0018—29.0%
——9——CVE-2014-5881—29.0%
——9——CVE-2024-11928—29.0%
——9——CVE-2013-2976—29.0%
——9——CVE-2023-27149—29.0%
——9——CVE-2023-51540—29.0%
——9——CVE-2024-11945—29.0%
——9——CVE-2026-832158.2 HIG29.0%
——9Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).1dCVE-2026-127294.3 MED29.0%
——9The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action, which performs no nonce verification via check_ajax_referer() and no capability check via current_user_can() before executing sensitive operations. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a full BetterDocs-to-weDocs data migration, creating and modifying 'docs' custom post type entries with attacker-controlled titles, updating site options, and deactivating the BetterDocs and BetterDocs Pro plugins via deactivate_plugins().73dCVE-2022-25737—29.0%
——9——CVE-2023-21625—29.0%
——9——CVE-2013-6436—29.0%
——9——CVE-2024-38680—29.0%
——9——CVE-2005-4133—29.0%
——9——CVE-1999-1174—29.0%
——9——CVE-2026-813537.8 HIG29.0%
——9Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.5hCVE-2007-5907—29.0%
——9——CVE-2024-52454—29.0%
——9——CVE-2022-25747—29.0%
——9——CVE-2022-25730—29.0%
——9——CVE-2025-2624—29.0%
——9——CVE-2023-51488—29.0%
——9——CVE-2024-6710—29.0%
——9——CVE-2018-11461—29.0%
——9——CVE-2024-31123—29.0%
——9——CVE-2020-3215—29.0%
——9——CVE-2022-21571—29.0%
——9——CVE-2024-13278—29.0%
——9——CVE-2024-52464—29.0%
——9——CVE-2026-13724.3 MED29.0%
——9The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.57dCVE-2023-27148—29.0%
——9——CVE-2024-13241—29.0%
——9——CVE-2024-21004—29.0%
——9——CVE-2023-0593—29.0%
——9——CVE-2024-58293—29.0%
——9——CVE-2026-833438.2 HIG29.0%
——9Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data as well as unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).1d