Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-28917—23.2%
——7——CVE-2026-186537.2 HIG23.2%
——7The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.16dCVE-2026-32850—23.2%
——7——CVE-2024-11609—23.2%
——7——CVE-2025-31578—23.2%
——7——CVE-2020-7282—23.2%
——7——CVE-2025-596977.2 HIG23.2%
——7Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06.16dCVE-2025-54339—23.2%
——7——CVE-2026-726976.5 MED23.2%
——7Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply arbitrary filesystem paths to media_directory() and use the allow-listed filepath accessor on Medium objects to read file contents of any file matching configured media extensions that the web server process can access.11dCVE-2016-8100—23.2%
——7——CVE-2017-1595—23.2%
——7——CVE-2015-3692—23.2%
——7——CVE-2012-3718—23.2%
——7——CVE-2025-15400—23.2%
——7——CVE-2025-28869—23.2%
——7——CVE-2026-27405—23.2%
——7——CVE-2026-47189—23.2%
——7——CVE-2024-38759—23.2%
——7——CVE-2025-28921—23.2%
——7——CVE-2023-0500—23.2%
——7——CVE-2021-1070—23.2%
——7——CVE-2023-1340—23.2%
——7——CVE-2025-28890—23.2%
——7——CVE-2025-31571—23.2%
——7——CVE-2016-8916—23.2%
——7——CVE-2025-28924—23.2%
——7——CVE-2025-597027.2 HIG23.2%
——7Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.16dCVE-2024-549946.5 MED23.2%
——7MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.68dCVE-2014-0686—23.2%
——7——CVE-2024-39337—23.2%
——7——CVE-2024-24886—23.2%
——7——CVE-2026-32212—23.2%
——7——CVE-2025-28903—23.2%
——7——CVE-2024-50577—23.2%
——7——CVE-2026-612087.6 HIG23.2%
——7Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).22dCVE-2026-32851—23.2%
——7——CVE-2025-28882—23.2%
——7——CVE-2023-1345—23.2%
——7——CVE-2025-7734—23.2%
——7——CVE-2023-24588—23.2%
——7——