Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,231
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-66736—23.8%
——7——CVE-2020-27256—23.8%
——7——CVE-2025-54853—23.8%
——7——CVE-2023-33528—23.8%
——7——CVE-2022-45332—23.8%
——7——CVE-2026-4827—23.8%
——7——CVE-2025-57881—23.8%
——7——CVE-2021-33444—23.7%
——7——CVE-2026-21388—23.7%
——7——CVE-2021-33445—23.7%
——7——CVE-2026-789544.3 MED23.7%
——7Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)14dCVE-2026-46966—23.7%
——7——CVE-2024-7139—23.7%
——7——CVE-2023-52083—23.7%
——7——CVE-2019-257028.2 HIG23.7%
——7Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database information or modify data.49dCVE-2026-451906.5 MED23.7%
——7Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.
Inputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.
Example:
my $cidr = Net::CIDR::Lite->new();
$cidr->add("::1\n/128");
$cidr->find("::1a"); # incorrectly returns true
See also CVE-2026-45191.49dCVE-2026-729996.8 MED23.7%
——7Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.1dCVE-2026-41211—23.7%
——7——CVE-2026-48114.9 MED23.7%
——7The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Icon CSS Class' category field in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.50dCVE-2024-21848—23.7%
——7——CVE-2017-7761—23.7%
——7——CVE-2026-118896.5 MED23.7%
——7SALTO ProAccess Space software using the tenancy feature / logical
partition is vulnerable to a privilege escalation attack that could
allow an authorized attacker to access any space managed by the affected
product.56dCVE-2025-52873—23.7%
——7——CVE-2025-11286—23.7%
——7——CVE-2026-5003—23.7%
——7——CVE-2026-7028—23.7%
——7——CVE-2025-43792—23.7%
——7——CVE-2026-708657.5 HIG23.7%
——7Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).15dCVE-2019-256968.2 HIG23.7%
——7Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify data.49dCVE-2026-44326—23.7%
——7——CVE-2019-25710—23.7%
——7——CVE-2026-38533—23.7%
——7——CVE-2025-3104—23.7%
——7——CVE-2026-46934—23.7%
——7——CVE-2026-749827.5 HIG23.7%
——7Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.17dCVE-2026-646658.1 HIG23.7%
——7Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0.3dCVE-2026-789614.3 MED23.7%
——7Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)14dCVE-2024-6495—23.7%
——7——CVE-2026-35295—23.7%
——7——CVE-2026-709307.5 HIG23.7%
——7Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).14d