Vulnerabilities exploitable today
372,980in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,226
- High8,209
- Medium6,217
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-0227—24.2%
——7——CVE-2022-0851—24.2%
——7——CVE-2020-1621—24.2%
——7——CVE-2024-45989—24.2%
——7——CVE-2025-58052—24.2%
——7——CVE-2019-8504—24.2%
——7——CVE-2024-53348—24.2%
——7——CVE-2026-708037.6 HIG24.2%
——7Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized read access to a subset of Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L).18dCVE-2023-4013—24.2%
——7——CVE-2024-39627—24.2%
——7——CVE-2023-48424—24.2%
——7——CVE-2026-27329—24.2%
——7——CVE-2020-12307—24.2%
——7——CVE-2026-31712—24.2%
——7——CVE-2025-48756—24.2%
——7——CVE-2026-165787.5 HIG24.2%
——7The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles, and two-factor authentication enrollment status.17dCVE-2025-3939—24.2%
——7——CVE-2024-34122—24.2%
——7——CVE-2026-510787.5 HIG24.2%
——7An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component46dCVE-2026-20888—24.2%
——7——CVE-2020-12345—24.2%
——7——CVE-2024-36486—24.2%
——7——CVE-2026-786627.5 HIG24.2%
——7Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.8dCVE-2020-1622—24.2%
——7——CVE-2026-163619.8 CRI24.2%
——7Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.50dCVE-2026-59180—24.2%
——7——CVE-2026-848096.5 MED24.2%
——7Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled bytecode that executes on import while the scanner reports a safe verdict, enabling code execution when operators install the skill.8dCVE-2026-7273—24.2%
——7——CVE-2026-25387—24.2%
——7——CVE-2026-855345.9 MED24.2%
——7A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.4dCVE-2025-53638—24.2%
——7——CVE-2026-393559.9 CRI24.2%
——7Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces and unrestricted access to all genealogy data associated with the compromised team. This vulnerability is fixed in 5.9.1.50dCVE-2025-52203—24.2%
——7——CVE-2026-647737.5 HIG24.2%
——7An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.11dCVE-2024-52060—24.2%
——7——CVE-2026-45569—24.2%
——7——CVE-2023-22239—24.2%
——7——CVE-2026-35043—24.2%
——7——CVE-2024-56826—24.2%
——7——CVE-2024-20753—24.2%
——7——