Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,328
- High8,275
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-24710—26.9%
——8——CVE-2006-7108—26.9%
——8——CVE-2014-5943—26.9%
——8——CVE-2014-5811—26.9%
——8——CVE-2026-27610—26.9%
——8——CVE-2004-1124—26.9%
——8——CVE-2023-30436—26.9%
——8——CVE-2008-1130—26.9%
——8——CVE-2024-12203—26.9%
——8——CVE-2025-8198—26.9%
——8——CVE-2025-21156—26.9%
——8——CVE-2023-44472—26.9%
——8——CVE-2014-6692—26.9%
——8——CVE-2014-5764—26.9%
——8——CVE-2024-9618—26.9%
——8——CVE-2023-1086—26.9%
——8——CVE-2012-1684—26.9%
——8——CVE-2024-41482—26.9%
——8——CVE-2024-45965—26.9%
——8——CVE-2025-21591—26.9%
——8——CVE-2025-1114—26.9%
——8——CVE-2026-456086.8 MED26.9%
——8Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.55dCVE-2018-1000104—26.9%
——8——CVE-2026-865154.3 MED26.9%
——8A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 4b6a02dd1aff6428255db912563d77d4cb0a143e. It is advisable to implement a patch to correct this issue.8dCVE-2026-609638.1 HIG26.9%
——8Vulnerability in the Oracle Treasury product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Treasury. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Treasury accessible data as well as unauthorized access to critical data or complete access to all Oracle Treasury accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).41dCVE-2026-452323.1 LOW26.9%
——8Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.63dCVE-2026-610008.1 HIG26.9%
——8Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).35dCVE-2014-5672—26.9%
——8——CVE-2014-5654—26.9%
——8——CVE-2020-5965—26.9%
——8——CVE-2012-5474—26.9%
——8——CVE-2019-11096—26.9%
——8——CVE-2023-34030—26.9%
——8——CVE-2006-1125—26.9%
——8——CVE-2026-597958.1 HIG26.9%
——8In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible65dCVE-2026-40016—26.9%
——8——CVE-2025-67823—26.9%
——8——CVE-2017-0493—26.9%
——8——CVE-2023-50165—26.9%
——8——CVE-2025-4855—26.9%
——8——