Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-11022—27.2%
——8——CVE-2024-47450—27.2%
——8——CVE-2009-2835—27.2%
——8——CVE-2024-35195—27.2%
——8——CVE-2024-52903—27.2%
——8——CVE-2026-624927.4 HIG27.2%
——8Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).20dCVE-2025-26515—27.2%
——8——CVE-2011-2318—27.2%
——8——CVE-2025-32586—27.2%
——8——CVE-2025-32951—27.2%
——8——CVE-2026-32729—27.2%
——8——CVE-2026-55581—27.2%
——8——CVE-2024-45143—27.2%
——8——CVE-2024-30289—27.2%
——8——CVE-2026-604488.7 HIG27.2%
——8Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).50dCVE-2024-11768—27.2%
——8——CVE-2024-32798—27.2%
——8——CVE-2023-27850—27.2%
——8——CVE-2025-49268—27.2%
——8——CVE-2024-5676—27.2%
——8——CVE-2024-49572—27.2%
——8——CVE-2025-27194—27.2%
——8——CVE-2023-38272—27.2%
——8——CVE-2021-31747—27.2%
——8——CVE-2023-32740—27.2%
——8——CVE-2026-4813—27.2%
——8A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to be executed from malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations, resulting in the execution of arbitrary code on the server.15dCVE-2024-1730—27.2%
——8——CVE-2025-47485—27.2%
——8——CVE-2025-5887—27.2%
——8——CVE-2024-2477—27.2%
——8——CVE-2026-57407.5 HIG27.2%
——8Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the public WebSocket endpoint.. Mattermost Advisory ID: MMSA-2026-0064755dCVE-2024-11743—27.2%
——8——CVE-2024-27278—27.2%
——8——CVE-2023-32119—27.2%
——8——CVE-2026-611647.4 HIG27.2%
——8Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).54dCVE-2026-23139—27.2%
——8——CVE-2024-13045—27.2%
——8——CVE-2024-29134—27.2%
——8——CVE-2022-26888—27.2%
——8——CVE-2019-18575—27.2%
——8——