Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-5213—27.2%
——8——CVE-2025-20085—27.2%
——8——CVE-2020-0600—27.2%
——8——CVE-2024-22217—27.2%
——8——CVE-2013-2851—27.2%
——8——CVE-2026-608237.4 HIG27.2%
——8Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iSupport accessible data as well as unauthorized access to critical data or complete access to all Oracle iSupport accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).48dCVE-2026-605538.7 HIG27.2%
——8Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).46dCVE-2026-611737.4 HIG27.2%
——8Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).22dCVE-2024-52485—27.2%
——8——CVE-2023-32740—27.2%
——8——CVE-2023-38272—27.2%
——8——CVE-2024-49525—27.2%
——8——CVE-2024-49572—27.2%
——8——CVE-2017-14903—27.2%
——8——CVE-2019-25408—27.2%
——8——CVE-2025-30945—27.2%
——8——CVE-2026-611137.4 HIG27.2%
——8Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).46dCVE-2025-2009—27.2%
——8——CVE-2025-49241—27.2%
——8——CVE-2026-581658.8 HIG27.2%
——8OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attackers can redeem the resulting one-time token through the unauthenticated client API enrollment endpoint to obtain a client certificate authenticating as the targeted admin identity, yielding full administrative control of the controller and the zero-trust overlay it manages.63dCVE-2026-43253—27.2%
——8——CVE-2017-13303—27.2%
——8——CVE-2023-25711—27.2%
——8——CVE-2017-14905—27.2%
——8——CVE-2024-22146—27.2%
——8——CVE-2023-45607—27.2%
——8——CVE-2006-2045—27.2%
——8——CVE-2007-3849—27.2%
——8——CVE-2006-5677—27.2%
——8——CVE-2025-1249—27.2%
——8——CVE-2006-5807—27.2%
——8——CVE-2017-7143—27.2%
——8——CVE-2016-2556—27.2%
——8——CVE-2025-5420—27.2%
——8——CVE-2025-5405—27.2%
——8——CVE-2024-10727—27.2%
——8——CVE-2024-47431—27.2%
——8——CVE-2024-45139—27.2%
——8——CVE-2026-23139—27.2%
——8——CVE-2024-27278—27.2%
——8——