Vulnerabilities exploitable today
373,010in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,127
- Medium6,187
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9282—24.3%
——7——CVE-2026-2561—24.4%
——7——CVE-2023-46096—24.4%
——7——CVE-2024-9584—24.4%
——7——CVE-2023-38360—24.4%
——7——CVE-2025-10880—24.4%
——7——CVE-2026-274474.8 MED24.4%
——7OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.50dCVE-2020-3828—24.4%
——7——CVE-2025-8744—24.4%
——7——CVE-2014-8535—24.4%
——7——CVE-2023-38271—24.4%
——7——CVE-2026-27333—24.4%
——7——CVE-2023-40209—24.4%
——7——CVE-2026-607667.4 HIG24.4%
——7Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).23dCVE-2026-52034.7 MED24.4%
——7A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. This issue has been reported early to the project. They confirmed, that "this has already been discovered and fixed for the next release."50dCVE-2024-32508—24.4%
——7——CVE-2026-609337.4 HIG24.4%
——7Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).16dCVE-2019-25254—24.4%
——7——CVE-2025-5390—24.4%
——7——CVE-2013-0310—24.4%
——7——CVE-2025-2946—24.4%
——7——CVE-2024-53277—24.4%
——7——CVE-2026-2562—24.4%
——7——CVE-2024-34126—24.4%
——7——CVE-2024-24839—24.4%
——7——CVE-2025-2166—24.4%
——7——CVE-2024-3756—24.4%
——7——CVE-2024-11489—24.4%
——7——CVE-2022-34556—24.4%
——7——CVE-2025-94979.8 CRI24.4%
——7Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.31dCVE-2026-609548.7 HIG24.4%
——7Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).23dCVE-2025-12849—24.4%
——7——CVE-2024-32456—24.4%
——7——CVE-2025-0871—24.4%
——7——CVE-2025-12094—24.4%
——7——CVE-2023-50294—24.4%
——7——CVE-2026-630985.3 MED24.4%
——7TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.44dCVE-2019-25699—24.4%
——7——CVE-2026-22320—24.4%
——7——CVE-2020-3404—24.4%
——7——