Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-80797.3 HIG25.2%
——8In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.71dCVE-2022-4104—25.2%
——8——CVE-2024-56365—25.2%
——8——CVE-2025-5088—25.2%
——8——CVE-2025-5134—25.2%
——8——CVE-2016-8006—25.2%
——8——CVE-2020-1619—25.2%
——8——CVE-2019-5303—25.2%
——8——CVE-2024-52925—25.2%
——8——CVE-2022-2896—25.2%
——8——CVE-2026-80938.1 HIG25.2%
——8Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.62dCVE-2025-61234—25.2%
——8——CVE-2025-61116—25.2%
——8——CVE-2017-16526—25.2%
——8——CVE-2024-11400—25.2%
——8——CVE-2024-45875—25.2%
——8——CVE-2025-1944—25.2%
——8——CVE-2026-490884.4 MED25.2%
——8Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access.75dCVE-2017-13263—25.2%
——8——CVE-2017-13270—25.2%
——8——CVE-2018-17154—25.2%
——8——CVE-2008-2366—25.2%
——8——CVE-2026-3765—25.2%
——8——CVE-2026-708128.8 HIG25.2%
——8Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).19dCVE-2020-4717—25.2%
——8——CVE-2026-175439.8 CRI25.2%
——8Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.41dCVE-2012-0097—25.2%
——8——CVE-2024-8179—25.2%
——8——CVE-2024-49210—25.2%
——8——CVE-2021-0060—25.2%
——8——CVE-2008-4593—25.2%
——8——CVE-2025-8578—25.2%
——8——CVE-2026-618613.7 LOW25.2%
——8ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution.64dCVE-2025-713118.2 HIG25.2%
——8In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Initialize new folios before use
KMSAN reports an uninitialized value in longest_match_std(), invoked
from ntfs_compress_write(). When new folios are allocated without being
marked uptodate and ni_read_frame() is skipped because the caller expects
the frame to be completely overwritten, some reserved folios may remain
only partially filled, leaving the rest memory uninitialized.47dCVE-2024-13306—25.2%
——8——CVE-2025-10224—25.2%
——8——CVE-2019-20469—25.2%
——8——CVE-2007-4600—25.2%
——8——CVE-2022-44718—25.2%
——8——CVE-2025-15033—25.2%
——8——