Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-3477—25.3%
——8——CVE-2024-9068—25.3%
——8——CVE-2025-41430—25.3%
——8——CVE-2026-603495.9 MED25.3%
——8Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L).46dCVE-2021-366976.7 MED25.3%
——8With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.69dCVE-2025-50465—25.3%
——8——CVE-2025-55036—25.3%
——8——CVE-2026-27740—25.3%
——8——CVE-2025-562006.1 MED25.3%
——8A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.72dCVE-2025-46334—25.3%
——8——CVE-2025-6168—25.3%
——8——CVE-2026-40618—25.3%
——8——CVE-2025-15069—25.3%
——8——CVE-2019-4666—25.3%
——8——CVE-2023-33100—25.3%
——8——CVE-2026-30121—25.3%
——8——CVE-2010-2022—25.3%
——8——CVE-2023-43523—25.3%
——8——CVE-2026-454768.2 HIG25.3%
——8Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.54dCVE-2024-8113—25.3%
——8——CVE-2026-478867.5 HIG25.3%
——8Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier5dCVE-2011-2176—25.3%
——8——CVE-2023-43536—25.3%
——8——CVE-2025-12482—25.3%
——8——CVE-2023-45370—25.3%
——8——CVE-2018-6400—25.3%
——8——CVE-2024-22168—25.3%
——8——CVE-2024-43188—25.3%
——8——CVE-2023-49797—25.3%
——8——CVE-2025-53856—25.3%
——8——CVE-2026-478887.5 HIG25.3%
——8A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE5dCVE-1999-1300—25.3%
——8——CVE-2026-40067—25.3%
——8——CVE-2026-48797—25.3%
——8——CVE-2003-0448—25.3%
——8——CVE-2020-11833—25.3%
——8——CVE-2026-48702—25.3%
——8——CVE-2026-876219.6 CRI25.3%
——8Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)5dCVE-2025-29992—25.3%
——8——CVE-2022-40228—25.3%
——8——