Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-52521—26.8%
——8——CVE-2024-37203—26.8%
——8——CVE-2026-602375.3 MED26.8%
——8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).53dCVE-2008-1810—26.8%
——8——CVE-2024-45609—26.8%
——8——CVE-2026-603945.3 MED26.8%
——8Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).46dCVE-2023-51692—26.8%
——8——CVE-2026-763898.8 HIG26.8%
——8In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.25dCVE-2026-115948.5 HIG26.8%
——8IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.75dCVE-2025-10760—26.8%
——8——CVE-2023-44093—26.8%
——8——CVE-2026-26710—26.8%
——8——CVE-2023-22002—26.8%
——8——CVE-2025-587078.1 HIG26.8%
——8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.
This issue affects Spin: from n/a through 1.8.55dCVE-2026-28118—26.8%
——8——CVE-2026-4992—26.8%
——8——CVE-2024-12445—26.8%
——8——CVE-2023-54340—26.8%
——8——CVE-2026-55424.3 MED26.8%
——8A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.53dCVE-2026-626477.4 HIG26.8%
——8A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.2dCVE-2025-4669—26.8%
——8——CVE-2026-4845—26.8%
——8——CVE-2024-29114—26.8%
——8——CVE-2025-47993—26.8%
——8——CVE-2026-818456.3 MED26.8%
——8A vulnerability has been found in arben-adm mcp-sequential-thinking up to 0.5.0. Impacted is the function import_session/export_session of the file mcp_sequential_thinking/server.py of the component Import Session/Export Session. Such manipulation of the argument file_path leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.6.0 is recommended to address this issue. The name of the patch is 2fad3ee8ab1d0868b6c1afb5895bc336a10e5267. Upgrading the affected component is recommended.15dCVE-2024-0656—26.8%
——8——CVE-2025-12609—26.8%
——8——CVE-2024-27189—26.8%
——8——CVE-2024-51487—26.8%
——8——CVE-2005-2939—26.8%
——8——CVE-2006-0858—26.8%
——8——CVE-2026-94736.3 MED26.8%
——8A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the argument filePath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.55dCVE-2025-27001—26.8%
——8——CVE-2024-30524—26.8%
——8——CVE-2024-29115—26.8%
——8——CVE-2024-12515—26.8%
——8——CVE-2026-28128—26.8%
——8——CVE-2022-46457—26.8%
——8——CVE-2024-10725—26.8%
——8——CVE-2024-11777—26.8%
——8——