Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-46842—25.8%
——8——CVE-2024-5075—25.8%
——8——CVE-2025-46838—25.8%
——8——CVE-2025-25016—25.8%
——8——CVE-2025-27201—25.8%
——8——CVE-2024-33121—25.8%
——8——CVE-2024-5664—25.8%
——8——CVE-2023-32967—25.8%
——8——CVE-2020-5855—25.8%
——8——CVE-2022-31244—25.8%
——8——CVE-2026-190176.8 MED25.8%
——8Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.18dCVE-2024-4376—25.8%
——8——CVE-2015-1951—25.8%
——8——CVE-2026-30228—25.8%
——8——CVE-2024-13439—25.8%
——8——CVE-2026-1200—25.8%
——8——CVE-2022-48430—25.8%
——8——CVE-2023-2860—25.8%
——8——CVE-2021-39771—25.8%
——8——CVE-2024-5788—25.8%
——8——CVE-2022-45674—25.8%
——8——CVE-2026-23825—25.8%
——8——CVE-2024-11577—25.8%
——8——CVE-2012-3818—25.8%
——8——CVE-2024-35680—25.8%
——8——CVE-2026-28383—25.8%
——8——CVE-2023-31908—25.8%
——8——CVE-2014-5400—25.8%
——8——CVE-2026-468339.0 CRI25.8%
——8Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).56dCVE-2025-20325—25.8%
——8——CVE-2026-23824—25.8%
——8——CVE-2023-51493—25.8%
——8——CVE-2025-15579—25.8%
——8——CVE-2026-6242210.0 CRI25.8%
——8In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible34dCVE-2026-48735.9 MED25.8%
——8A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to that same host bypasses the TLS requirement and instead transmit data
unencrypted.11hCVE-2009-4411—25.8%
——8——CVE-1999-1470—25.8%
——8——CVE-2023-52194—25.8%
——8——CVE-2024-10017—25.8%
——8——CVE-2026-33084—25.8%
——8——