Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,702
- Medium6,686
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-35662—28.4%
——9——CVE-2026-6206—28.4%
——9——CVE-2024-28725—28.4%
——9——CVE-2024-49798—28.4%
——9——CVE-2023-5444—28.4%
——9——CVE-2025-632936.5 MED28.4%
——9FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API.74dCVE-2025-6929—28.4%
——9——CVE-2025-12790—28.4%
——9——CVE-2010-0792—28.4%
——9——CVE-2026-20255—28.4%
——9——CVE-2013-0977—28.4%
——9——CVE-2026-42855—28.4%
——9——CVE-2024-1437—28.4%
——9——CVE-2024-2864—28.4%
——9——CVE-2023-51509—28.4%
——9——CVE-2023-44245—28.4%
——9——CVE-2026-40347—28.4%
——9——CVE-2024-7234—28.4%
——9——CVE-2025-7492—28.4%
——9——CVE-2025-64235—28.4%
——9——CVE-2024-47617—28.4%
——9——CVE-2026-509806.1 MED28.4%
——9Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via a crafted DNS TXT record7dCVE-2014-9941—28.4%
——9——CVE-2023-41874—28.4%
——9——CVE-2024-43792—28.4%
——9——CVE-2023-4331—28.4%
——9——CVE-2024-27196—28.4%
——9——CVE-2024-35777—28.4%
——9——CVE-2026-606329.3 CRI28.4%
——9Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).49dCVE-2023-41847—28.4%
——9——CVE-2007-2480—28.4%
——9——CVE-2023-46313—28.4%
——9——CVE-2024-40579—28.4%
——9——CVE-2023-44474—28.4%
——9——CVE-2026-709018.1 HIG28.4%
——9Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).23dCVE-2023-30961—28.4%
——9——CVE-2012-1699—28.4%
——9——CVE-2012-2669—28.4%
——9——CVE-2026-827688.1 HIG28.4%
——9Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.2dCVE-2024-4621—28.4%
——9——