Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,702
- Medium6,686
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25581—28.5%
——9——CVE-2026-33931—28.5%
——9——CVE-2008-6801—28.5%
——9——CVE-2026-1065—28.5%
——9——CVE-2023-4802—28.5%
——9——CVE-2026-175395.9 MED28.5%
——9RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104 fatal write error, resulting in connection interruption and restart, and ultimately a denial of service for bidirectional IEC 60870-5-104 communication.13dCVE-2021-33453—28.5%
——9——CVE-2024-11183—28.5%
——9——CVE-2024-5056—28.5%
——9——CVE-2020-0588—28.5%
——9——CVE-2025-63058—28.5%
——9——CVE-2024-29766—28.5%
——9——CVE-2024-30451—28.5%
——9——CVE-2024-1437—28.4%
——9——CVE-2013-0977—28.4%
——9——CVE-2023-51509—28.4%
——9——CVE-2026-40347—28.4%
——9——CVE-2026-42855—28.4%
——9——CVE-2023-44245—28.4%
——9——CVE-2024-2864—28.4%
——9——CVE-2024-7234—28.4%
——9——CVE-2020-1866—28.4%
——9——CVE-2025-7489—28.4%
——9——CVE-2016-5328—28.4%
——9——CVE-2008-5256—28.4%
——9——CVE-2019-18248—28.4%
——9——CVE-2018-20889—28.4%
——9——CVE-2015-3285—28.4%
——9——CVE-2025-11996—28.4%
——9——CVE-2026-707468.1 HIG28.4%
——9Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Reporting accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).22dCVE-2022-39834—28.4%
——9——CVE-2026-827937.2 HIG28.4%
——9Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.2dCVE-2015-7333—28.4%
——9——CVE-2024-7227—28.4%
——9——CVE-2024-13013—28.4%
——9——CVE-2019-3500—28.4%
——9——CVE-2006-0917—28.4%
——9——CVE-2024-45863—28.4%
——9——CVE-2026-571629.1 CRI28.4%
——9PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bounding their number; a remote peer that includes an excessive number of a=crypto attributes in a single media description can write past the end of that array on the stack. This is reachable from an incoming SIP INVITE during offer/answer, before application-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. Applications that do not enable SRTP are not affected. This issue has been patched via commit a1b707c.5dCVE-2026-590917.3 HIG28.4%
——9A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction.23d