Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-1388—27.2%
——8——CVE-2019-20547—27.2%
——8——CVE-2020-10834—27.2%
——8——CVE-2026-576696.5 MED27.2%
——8Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.76dCVE-2024-1650—27.2%
——8——CVE-2026-401107.3 HIG27.2%
——8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pat configuration value. Because re.match() only anchors at the start of the string and does not require a full match, a pattern intended to match only a trusted domain (e.g., trusted.example.com) will also match any origin that begins with that domain followed by additional characters (e.g., trusted.example.com.evil.com). An attacker who controls such a domain can bypass the CORS origin restriction and make cross-origin requests to the Jupyter Server API from an untrusted site. This issue has been fixed in version 2.18.0.54dCVE-2025-11638—27.2%
——8——CVE-2020-15581—27.2%
——8——CVE-2026-649077.8 HIG27.2%
——8Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.33dCVE-2015-9546—27.2%
——8——CVE-2004-0135—27.2%
——8——CVE-2023-34142—27.2%
——8——CVE-2026-33268—27.2%
——8——CVE-2026-5935—27.2%
——8——CVE-2005-4506—27.2%
——8——CVE-2020-5866—27.2%
——8——CVE-2007-5900—27.2%
——8——CVE-2024-1337—27.2%
——8——CVE-2026-610127.1 HIG27.2%
——8Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).44dCVE-2026-542616.5 MED27.2%
——8Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.76dCVE-2019-20617—27.2%
——8——CVE-2026-649097.8 HIG27.2%
——8Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.33dCVE-2026-573956.5 MED27.2%
——8Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.65dCVE-2024-48941—27.2%
——8——CVE-2023-4627—27.2%
——8——CVE-2020-8485—27.2%
——8——CVE-2004-0647—27.2%
——8——CVE-2005-1185—27.2%
——8——CVE-2005-4668—27.2%
——8——CVE-2006-0255—27.2%
——8——CVE-2017-18694—27.2%
——8——CVE-2002-2018—27.2%
——8——CVE-2025-5472—27.2%
——8——CVE-2026-539356.9 MED27.2%
——8Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, enabling hijacking traffic to Services in any namespace and bypassing namespace scoping enforced by serviceMatcher; deleting such a policy can also corrupt Cilium internal service state and stop service translation for the affected Service. This issue is fixed in versions 1.17.16, 1.18.10, and 1.19.4.68dCVE-2026-707747.1 HIG27.2%
——8Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Warehouse Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Warehouse Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).23dCVE-2025-63080—27.2%
——8Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system file read or command execution.
This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.19dCVE-2025-27371—27.2%
——8——CVE-2024-51559—27.2%
——8——CVE-2026-595226.5 MED27.2%
——8Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.55dCVE-2021-31747—27.2%
——8——