Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-13294—27.2%
——8——CVE-2023-2019—27.2%
——8——CVE-2018-12224—27.2%
——8——CVE-2023-23130—27.2%
——8——CVE-2024-2468—27.2%
——8——CVE-2024-10727—27.2%
——8——CVE-2025-49241—27.2%
——8——CVE-2026-581658.8 HIG27.2%
——8OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attackers can redeem the resulting one-time token through the unauthenticated client API enrollment endpoint to obtain a client certificate authenticating as the targeted admin identity, yielding full administrative control of the controller and the zero-trust overlay it manages.63dCVE-2024-22217—27.2%
——8——CVE-2013-2851—27.2%
——8——CVE-2023-45607—27.2%
——8——CVE-2006-2045—27.2%
——8——CVE-2020-0600—27.2%
——8——CVE-2024-22146—27.2%
——8——CVE-2006-5213—27.2%
——8——CVE-2026-77998—27.2%
——8Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing Joomla user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.8dCVE-2026-767898.8 HIG27.2%
——8The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.24dCVE-2026-43253—27.2%
——8——CVE-2017-13303—27.2%
——8——CVE-2017-13235—27.2%
——8——CVE-2023-25711—27.2%
——8——CVE-2017-14905—27.2%
——8——CVE-2024-2143—27.2%
——8——CVE-2024-0367—27.2%
——8——CVE-2023-42554—27.2%
——8——CVE-2006-5677—27.2%
——8——CVE-2025-1249—27.2%
——8——CVE-2007-3849—27.2%
——8——CVE-2024-49517—27.2%
——8——CVE-2025-30945—27.2%
——8——CVE-2026-611137.4 HIG27.2%
——8Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).46dCVE-2025-2009—27.2%
——8——CVE-2019-14960—27.2%
——8——CVE-2026-707797.4 HIG27.2%
——8Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupplier Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).23dCVE-2019-25409—27.2%
——8——CVE-2017-13297—27.2%
——8——CVE-2024-2688—27.2%
——8——CVE-2019-25410—27.2%
——8——CVE-2025-5513—27.2%
——8——CVE-2019-25406—27.2%
——8——