Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32127—25.6%
——8——CVE-2007-5827—25.6%
——8——CVE-2024-11275—25.6%
——8——CVE-2026-35167—25.6%
——8——CVE-2018-15375—25.6%
——8——CVE-2026-32024—25.6%
——8——CVE-2018-15376—25.6%
——8——CVE-2008-3426—25.6%
——8——CVE-2024-11779—25.6%
——8——CVE-2019-25636—25.6%
——8——CVE-2026-602136.5 MED25.6%
——8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).53dCVE-2024-20908—25.6%
——8——CVE-2023-45369—25.6%
——8——CVE-2022-1729—25.6%
——8——CVE-2021-0144—25.6%
——8——CVE-2024-10565—25.6%
——8——CVE-2026-312369.8 CRI25.6%
——8The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to allow users to provide custom Python function definitions. However, the tool directly executes the provided code using the unsafe exec() function without any sanitization, sandboxing, or security restrictions. An attacker can exploit this by crafting a malicious llm command with arbitrary Python code in the --functions argument and using social engineering to trick a victim into running it. This leads to arbitrary code execution on the victim's system, potentially granting the attacker full control.63dCVE-2007-1940—25.6%
——8——CVE-2024-45454—25.6%
——8——CVE-2025-53903—25.6%
——8——CVE-2026-29087—25.6%
——8——CVE-2024-12113—25.6%
——8——CVE-2019-25635—25.6%
——8——CVE-2026-418937.5 HIG25.6%
——8Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path — sending {login: {username, password}} messages over an established WebSocket connection — calls app.securityStrategy.login() directly without any rate limiting. An attacker can bypass HTTP rate limiting entirely by opening a WebSocket connection and attempting unlimited password guesses at the speed bcrypt allows (~20 attempts/sec with 10 salt rounds). This issue has been patched in version 2.25.0.53dCVE-2024-37117—25.6%
——8——CVE-2024-37461—25.6%
——8——CVE-1999-0367—25.6%
——8——CVE-2024-47638—25.6%
——8——CVE-2009-4996—25.6%
——8——CVE-2024-37559—25.6%
——8——CVE-2025-1881—25.6%
——8——CVE-2026-663959.6 CRI25.6%
——8SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.49dCVE-2019-256848.2 HIG25.6%
——8OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.53dCVE-2024-8678—25.6%
——8——CVE-2025-53904—25.6%
——8——CVE-2023-22029—25.6%
——8——CVE-2025-22591—25.6%
——8——CVE-2026-34030—25.6%
——8——CVE-2024-37029—25.6%
——8——CVE-2019-18829—25.6%
——8——