Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-25154—25.5%
——8——CVE-2023-21588—25.5%
——8——CVE-2026-612198.7 HIG25.5%
——8Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).22dCVE-2026-9690—25.5%
——8——CVE-2020-11541—25.5%
——8——CVE-2025-64749—25.5%
——8——CVE-2026-49112—25.5%
——8——CVE-2023-26545—25.5%
——8——CVE-2016-1889—25.5%
——8——CVE-2001-1189—25.5%
——8——CVE-2001-0415—25.5%
——8——CVE-2024-25676—25.5%
——8——CVE-2025-59947—25.5%
——8——CVE-2016-20082—25.5%
——8——CVE-2023-22228—25.5%
——8——CVE-2001-0848—25.5%
——8——CVE-2025-28168—25.5%
——8——CVE-2025-10158—25.5%
——8——CVE-2026-46804—25.5%
——8——CVE-2021-20221—25.5%
——8——CVE-2025-597056.8 MED25.5%
——8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.20dCVE-2026-852128.3 HIG25.5%
——8CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.5dCVE-2026-170712.7 LOW25.5%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.27dCVE-2024-9456—25.5%
——8——CVE-2025-47003—25.4%
——8——CVE-2023-26404—25.5%
——8——CVE-2023-21620—25.5%
——8——CVE-2018-7839—25.5%
——8——CVE-2023-26378—25.5%
——8——CVE-2026-3188—25.5%
——8——CVE-2023-26374—25.5%
——8——CVE-2025-24023—25.5%
——8——CVE-2024-37415—25.5%
——8——CVE-2023-4256—25.5%
——8——CVE-2023-25875—25.5%
——8——CVE-2023-29286—25.5%
——8——CVE-2026-729628.2 HIG25.5%
——8Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.7dCVE-2025-46979—25.4%
——8——CVE-2026-85063—25.5%
——8node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing property in packages/csv-parse/lib/api/index.js, assigns an attacker-controlled array through obj['__proto__'], and replaces the parsed record object's prototype. A malicious CSV header can therefore inject inherited array values into the returned record, hide those inherited values from JSON serialization, and affect property enumeration and type or shape checks in applications that process the record. This issue is fixed in version 7.0.2.11dCVE-2026-762257.7 HIG25.5%
——8ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and return sensitive data from restricted services.7d