Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-22282—26.0%
——8——CVE-2023-45065—26.0%
——8——CVE-2017-0772—26.0%
——8——CVE-2023-7194—26.0%
——8——CVE-2023-25476—26.0%
——8——CVE-2023-46312—26.0%
——8——CVE-2025-4691—26.0%
——8——CVE-2023-45054—26.0%
——8——CVE-2024-27960—26.0%
——8——CVE-2024-33947—26.0%
——8——CVE-2024-21751—26.0%
——8——CVE-2017-0771—26.0%
——8——CVE-2023-50905—26.0%
——8——CVE-2025-70650—26.0%
——8——CVE-2026-33768—26.0%
——8——CVE-2023-41867—26.0%
——8——CVE-2023-46076—26.0%
——8——CVE-2026-775579.8 CRI26.0%
——8A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.18dCVE-2026-12812—26.0%
——8——CVE-2025-7413—26.0%
——8——CVE-2025-70644—26.0%
——8——CVE-2023-4100—26.0%
——8——CVE-2023-46081—26.0%
——8——CVE-2025-65033—26.0%
——8——CVE-2026-426809.8 CRI26.0%
——8Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation.
This issue affects Contest Gallery Pro: from n/a through 29.0.1.56dCVE-2024-22142—26.0%
——8——CVE-2017-0775—26.0%
——8——CVE-2025-3947—26.0%
——8——CVE-2025-70651—26.0%
——8——CVE-2021-35052—26.0%
——8——CVE-2023-46075—26.0%
——8——CVE-2026-155053.5 LOW26.0%
——8A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross site scripting. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.63dCVE-2025-20633—26.0%
——8——CVE-2026-123598.1 HIG26.0%
——8IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.29dCVE-2025-21459—26.0%
——8——CVE-2026-605817.5 HIG26.0%
——8Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).42dCVE-2025-6429—26.0%
——8——CVE-2025-1759—26.0%
——8——CVE-2011-2263—26.0%
——8——CVE-2019-15363—26.0%
——8——