Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-31913—26.6%
——8——CVE-2024-53382—26.6%
——8——CVE-2026-73661—26.6%
——8FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.32dCVE-2026-765724.7 MED26.6%
——8A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.27dCVE-2020-9501—26.6%
——8——CVE-2026-51252—26.6%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.46dCVE-2026-464808.8 HIG26.6%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2.55dCVE-2024-0977—26.6%
——8——CVE-2026-706709.6 CRI26.6%
——8Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Reports Developer executes to compromise Oracle Reports Developer. While the vulnerability is in Oracle Reports Developer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Reports Developer. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).21dCVE-2018-16663—26.6%
——8——CVE-2025-5135—26.6%
——8——CVE-2025-11593—26.6%
——8——CVE-2026-576946.5 MED26.6%
——8Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.64dCVE-2023-0828—26.6%
——8——CVE-2026-464768.8 HIG26.6%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.55dCVE-2026-41064—26.6%
——8——CVE-2024-2234—26.6%
——8——CVE-2026-31245—26.6%
——8——CVE-2017-7836—26.6%
——8——CVE-2023-4042—26.6%
——8——CVE-2024-7941—26.6%
——8——CVE-2022-23763—26.6%
——8——CVE-2023-27370—26.6%
——8——CVE-2009-0346—26.6%
——8——CVE-2026-48126—26.6%
——8——CVE-2026-629147.3 HIG26.6%
——8Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.33dCVE-2025-10627—26.6%
——8——CVE-2024-45894—26.6%
——8——CVE-2025-11588—26.6%
——8——CVE-2025-46268—26.6%
——8——CVE-2025-10613—26.6%
——8——CVE-2024-2817—26.6%
——8——CVE-2025-10626—26.6%
——8——CVE-2022-42846—26.6%
——8——CVE-2026-1577—26.6%
——8——CVE-2018-17491—26.6%
——8——CVE-2024-5811—26.6%
——8——CVE-2026-464798.8 HIG26.6%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.55dCVE-2009-0926—26.6%
——8——CVE-2026-198535.3 MED26.6%
——8NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.23d