Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,276
- High8,382
- Medium6,420
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-625795.3 MED23.1%
——7Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).16dCVE-2023-48758—23.1%
——7——CVE-2025-60119—23.1%
——7——CVE-2026-139326.5 MED23.1%
——7Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)71dCVE-2013-2213—23.1%
——7——CVE-2026-0116—23.1%
——7——CVE-2025-30563—23.1%
——7——CVE-2025-30796—23.1%
——7——CVE-2025-0787—23.1%
——7——CVE-2026-1433—23.1%
——7uniFLOW Universal Login Manager (ULM) Standalone
contains an information disclosure vulnerability that may allow an
authenticated administrator to access sensitive configuration information
through the ULM Remote User Interface (RUI). Exploitation requires
administrative privileges and may disclose configuration data associated with
SMTP or LDAP integrations. ULM deployments connected to uniFLOW Server or
uniFLOW Online are not affected.66dCVE-2026-774925.5 MED23.1%
——7Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.2dCVE-2026-693695.5 MED23.1%
——7Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally.2dCVE-2024-405827.5 HIG23.1%
——7Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.68dCVE-2025-13580—23.1%
——7——CVE-2025-30559—23.1%
——7——CVE-2023-34178—23.1%
——7——CVE-2024-13584—23.1%
——7——CVE-2025-49916—23.1%
——7——CVE-2026-138619.6 CRI23.1%
——7Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)71dCVE-2026-48493—23.1%
——7——CVE-2025-35112—23.1%
——7——CVE-2023-0664—23.1%
——7——CVE-2023-300865.5 MED23.1%
——7Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.64dCVE-2023-22699—23.1%
——7——CVE-2025-30544—23.1%
——7——CVE-2021-31403—23.1%
——7——CVE-2025-22570—23.1%
——7——CVE-2025-138729.1 CRI23.1%
——7Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.8dCVE-2024-13100—23.1%
——7——CVE-2025-30869—23.1%
——7——CVE-2026-0113—23.1%
——7——CVE-2025-30917—23.1%
——7——CVE-2020-3427—23.1%
——7——CVE-2024-10321—23.1%
——7——CVE-2025-30827—23.1%
——7——CVE-2025-24730—23.1%
——7——CVE-2024-13599—23.1%
——7——CVE-2026-66844.6 MED23.1%
——7FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.71dCVE-2024-40514—23.1%
——7——CVE-2022-1744—23.1%
——7——