Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1377—25.5%
——8——CVE-2013-5166—25.5%
——8——CVE-2016-1889—25.5%
——8——CVE-2016-20082—25.5%
——8——CVE-2025-28168—25.5%
——8——CVE-2026-5147—25.5%
——8——CVE-2025-10158—25.5%
——8——CVE-2021-20221—25.5%
——8——CVE-2024-29318—25.5%
——8——CVE-2012-3731—25.5%
——8——CVE-2026-428377.8 HIG25.5%
——8Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.54dCVE-2026-429167.8 HIG25.5%
——8Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.54dCVE-2026-612158.7 HIG25.5%
——8Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).22dCVE-2025-27237—25.5%
——8——CVE-2022-40299—25.5%
——8——CVE-2022-4266—25.5%
——8——CVE-2022-25619—25.5%
——8——CVE-2010-0223—25.5%
——8——CVE-2023-21621—25.5%
——8——CVE-2023-42817—25.5%
——8——CVE-2023-1331—25.5%
——8——CVE-2026-54008—25.5%
——8——CVE-2025-13644—25.5%
——8——CVE-2024-13082—25.5%
——8——CVE-2025-49509—25.5%
——8——CVE-2023-5120—25.5%
——8——CVE-2026-3999—25.5%
——8——CVE-2026-604438.7 HIG25.5%
——8Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).53dCVE-2023-38013—25.5%
——8——CVE-2024-48953—25.5%
——8——CVE-2016-6470—25.5%
——8——CVE-2025-64749—25.5%
——8——CVE-2026-9690—25.5%
——8——CVE-2020-11541—25.5%
——8——CVE-2026-49112—25.5%
——8——CVE-2023-26545—25.5%
——8——CVE-2026-46804—25.5%
——8——CVE-2026-586597.8 HIG25.5%
——8PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.40dCVE-2026-609818.7 HIG25.5%
——8Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).26dCVE-2026-604708.7 HIG25.5%
——8Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).49d