Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41671—25.1%
——8——CVE-2022-44321—25.1%
——8——CVE-2026-709115.3 MED25.1%
——8Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).22dCVE-2025-6427—25.1%
——8——CVE-2025-156628.6 HIG25.1%
——8The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal resources.50dCVE-1999-0473—25.1%
——8——CVE-2008-5375—25.1%
——8——CVE-2024-3883—25.1%
——8——CVE-2026-0403—25.1%
——8——CVE-2026-175855.3 MED25.1%
——8The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.17hCVE-2007-5043—25.1%
——8——CVE-2025-33247—25.1%
——8——CVE-2022-2989—25.1%
——8——CVE-2021-1485—25.1%
——8——CVE-2025-24453—25.1%
——8——CVE-2025-24692—25.1%
——8——CVE-2016-2393—25.1%
——8——CVE-2024-24097—25.1%
——8——CVE-2013-5416—25.1%
——8——CVE-2026-737528.8 HIG25.1%
——8An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.11dCVE-2018-4379—25.1%
——8——CVE-2026-42087—25.1%
——8——CVE-2026-287407.1 HIG25.1%
——8Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.70dCVE-2024-46081—25.1%
——8——CVE-2021-30739—25.1%
——8——CVE-2024-9728—25.1%
——8——CVE-2020-18409—25.1%
——8——CVE-2020-15024—25.1%
——8——CVE-2023-27472—25.1%
——8——CVE-2026-691075.9 MED25.1%
——8An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.4dCVE-2026-876188.3 HIG25.1%
——8Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)5dCVE-2026-24411—25.1%
——8——CVE-2024-10187—25.1%
——8——CVE-2009-1601—25.1%
——8——CVE-2017-6666—25.1%
——8——CVE-2017-1176—25.1%
——8——CVE-2024-13827—25.1%
——8——CVE-2025-22288—25.1%
——8——CVE-2026-813987.8 HIG25.1%
——8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6dCVE-2013-0490—25.1%
——8——