Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1759—26.0%
——8——CVE-2026-605817.5 HIG26.0%
——8Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).42dCVE-2026-41351—26.0%
——8——CVE-2026-133234.1 MED26.0%
——8In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users.71dCVE-2025-15474—26.0%
——8——CVE-2026-862087.3 HIG26.0%
——8A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.5dCVE-2025-10437—26.0%
——8——CVE-2024-26633—26.0%
——8——CVE-2025-11273—26.0%
——8——CVE-2023-52722—26.0%
——8——CVE-2021-0186—26.0%
——8——CVE-2026-778476.5 MED26.0%
——8Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.6dCVE-2010-3516—26.0%
——8——CVE-2016-4755—26.0%
——8——CVE-2025-13488—26.0%
——8——CVE-2026-51144.9 MED26.0%
——8The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due to a mismatch between CSS URL validation (which allows query strings like `.css?...`) and path resolution (which strips query strings), combined with no validation that the resolved file is actually a CSS file. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files from the server (including `wp-config.php` and `/etc/passwd`) by injecting crafted `<link>` tags into page content, with the file contents written to publicly accessible cache files.48dCVE-2023-21889—26.0%
——8——CVE-2024-24848—26.0%
——8——CVE-2024-40516—26.0%
——8——CVE-2025-63622—26.0%
——8——CVE-2016-2202—26.0%
——8——CVE-2019-8576—26.0%
——8——CVE-2019-25428—26.0%
——8——CVE-2026-91218.8 HIG26.0%
——8Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)54dCVE-2023-21885—26.0%
——8——CVE-2026-6810—26.0%
——8——CVE-2022-38533—26.0%
——8——CVE-2012-2693—26.0%
——8——CVE-2026-329208.4 HIG26.0%
——8OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory.52dCVE-2026-79845—26.0%
——8——CVE-2024-31036—26.0%
——8——CVE-2026-16626—26.0%
——8Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.
This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.15dCVE-2026-33230—26.0%
——8——CVE-2023-3324—26.0%
——8——CVE-2024-44918—26.0%
——8——CVE-2026-186649.1 CRI26.0%
——8When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the comparison is done in 4 times a unsigned 32 bit number comparison, again with the endianness of the host where all values are actually in network bye order.7dCVE-2026-24824—26.0%
——8——CVE-2007-5047—26.0%
——8——CVE-2025-49900—26.0%
——8——CVE-2018-1985—26.0%
——8——