Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-53584—25.4%
——8——CVE-2026-698748.2 HIG25.4%
——8Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.6dCVE-2026-606955.9 MED25.4%
——8Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).49dCVE-2024-12178—25.4%
——8——CVE-2026-41491—25.4%
——8——CVE-2025-65403—25.4%
——8——CVE-2025-47045—25.4%
——8——CVE-2018-6764—25.4%
——8——CVE-2025-47057—25.4%
——8——CVE-2025-47051—25.4%
——8——CVE-2026-568547.5 HIG25.4%
——8The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.12dCVE-2025-11241—25.4%
——8——CVE-2024-29207—25.4%
——8——CVE-2022-47093—25.4%
——8——CVE-2025-47012—25.4%
——8——CVE-2026-699068.2 HIG25.4%
——8Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.2hCVE-2021-0358—25.4%
——8——CVE-2022-26878—25.4%
——8——CVE-2025-2603—25.4%
——8——CVE-2026-109078.8 HIG25.4%
——8Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)55dCVE-2015-1841—25.4%
——8——CVE-2007-6209—25.4%
——8——CVE-2024-43233—25.4%
——8——CVE-2026-729588.2 HIG25.4%
——8Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.6dCVE-2026-605347.7 HIG25.4%
——8Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).49dCVE-2025-47026—25.4%
——8——CVE-2021-0356—25.4%
——8——CVE-2019-14584—25.4%
——8——CVE-2026-32611—25.4%
——8——CVE-2025-47035—25.4%
——8——CVE-2023-52534—25.4%
——8——CVE-2025-47025—25.4%
——8——CVE-2026-3918—25.4%
——8——CVE-2026-109898.8 HIG25.4%
——8Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)55dCVE-2026-623774.3 MED25.4%
——8libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get_track(ctx, 0) is called. HeifContext::get_track() in libheif/context.cc executes assert(has_sequence()) before its normal error handling, so assert-enabled builds abort instead of allowing the public wrapper in libheif/api/libheif/heif_sequences.cc to return null. In release builds, removing the assertion lets the track_id zero path dereference m_tracks.begin()->second on an empty map, which is undefined behavior and typically crashes. The issue is reachable through documented public APIs after parsing attacker-controlled bytes. This issue is fixed in version 1.23.1.6dCVE-2026-12199—25.4%
——8——CVE-2026-628816.7 MED25.4%
——8Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.29dCVE-2025-2604—25.4%
——8——CVE-2022-41849—25.4%
——8——CVE-2024-23504—25.4%
——8——