Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1267—25.9%
——8——CVE-2021-43940—25.9%
——8——CVE-2026-43899—25.9%
——8——CVE-2026-468199.1 CRI25.9%
——8Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).56dCVE-2025-30744—25.9%
——8——CVE-2010-3349—25.9%
——8——CVE-2026-362146.4 MED25.9%
——8osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions.42dCVE-2026-44602—25.9%
——8——CVE-2018-1783—25.9%
——8——CVE-2020-2145—25.9%
——8——CVE-2026-66785.3 MED25.9%
——8Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.76dCVE-1999-1354—25.9%
——8——CVE-2026-95237.3 HIG25.9%
——8A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.54dCVE-2025-5628—25.9%
——8——CVE-2015-2714—25.9%
——8——CVE-2024-22855—25.9%
——8——CVE-2025-64637—25.9%
——8——CVE-2026-811625.3 MED25.9%
——8Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.6dCVE-2026-534675.3 MED25.9%
——8ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.75dCVE-2024-2956—25.9%
——8——CVE-2026-35218—25.9%
——8——CVE-2002-1420—25.9%
——8——CVE-1999-1528—25.9%
——8——CVE-2024-25132—25.9%
——8——CVE-2024-235745.3 MED25.9%
——8HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system60dCVE-2023-31910—25.9%
——8——CVE-2024-235755.3 MED25.9%
——8HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.60dCVE-2023-29596—25.9%
——8——CVE-2024-37472—25.9%
——8——CVE-2024-49808—25.9%
——8——CVE-2019-10345—25.9%
——8——CVE-2020-8487—25.9%
——8——CVE-2022-29557—25.9%
——8——CVE-2004-2676—25.9%
——8——CVE-2014-3093—25.9%
——8——CVE-2005-3291—25.9%
——8——CVE-2010-1651—25.9%
——8——CVE-2024-12076—25.9%
——8——CVE-2020-8486—25.9%
——8——CVE-2014-6143—25.9%
——8——