Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-39318—27.2%
——8——CVE-2023-47215—27.2%
——8——CVE-2020-15309—27.2%
——8——CVE-2017-18449—27.2%
——8——CVE-2026-49492—27.2%
——8——CVE-2002-1284—27.2%
——8——CVE-2025-50950—27.2%
——8——CVE-2026-24884—27.2%
——8——CVE-2023-4626—27.2%
——8——CVE-2025-66206—27.2%
——8——CVE-2026-635327.8 HIG27.2%
——8Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.34dCVE-2024-46920—27.2%
——8——CVE-2025-5472—27.2%
——8——CVE-2025-11638—27.2%
——8——CVE-2015-9546—27.2%
——8——CVE-2026-401107.3 HIG27.2%
——8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.54dCVE-2026-649077.8 HIG27.2%
——8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.33dCVE-2020-15581—27.2%
——8——CVE-2017-1134—27.2%
——8——CVE-2026-609857.1 HIG27.2%
——8Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).47dCVE-2026-611197.1 HIG27.2%
——8Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).54dCVE-2026-826117.3 HIG27.2%
——8A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.16dCVE-2026-57429—27.2%
——8——CVE-2023-52048—27.2%
——8——CVE-2026-688167.8 HIG27.2%
——8Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.34dCVE-2020-8003—27.2%
——8——CVE-2026-574186.5 MED27.2%
——8Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.65dCVE-2026-649107.8 HIG27.2%
——8Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.33dCVE-2024-1649—27.2%
——8——CVE-2020-9969—27.2%
——8——CVE-2020-8484—27.2%
——8——CVE-2023-5770—27.2%
——8——CVE-2026-9822—27.2%
——8——CVE-2024-10518—27.2%
——8——CVE-2026-2618—27.2%
——8——CVE-2025-63080—27.2%
——8Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.19dCVE-2025-27371—27.2%
——8——CVE-2026-707747.1 HIG27.2%
——8Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).23dCVE-2026-595226.5 MED27.2%
——8Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.55dCVE-2024-51559—27.2%
——8——