Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,222
- High8,145
- Medium6,171
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-34171—22.8%
——7——CVE-2024-6668—22.8%
——7——CVE-2026-39405—22.8%
——7Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1.49dCVE-2019-13013—22.8%
——7——CVE-2024-45068—22.8%
——7——CVE-2025-28983—22.8%
——7——CVE-2026-2216—22.8%
——7——CVE-2021-44190—22.8%
——7——CVE-2023-36850—22.8%
——7——CVE-2023-31088—22.8%
——7——CVE-2026-504597.0 HIG22.8%
——7Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.50dCVE-2025-49588—22.8%
——7——CVE-2026-22009—22.8%
——7——CVE-2026-46362—22.8%
——7——CVE-2025-46173—22.8%
——7——CVE-2026-4825—22.8%
——7——CVE-2026-34308—22.8%
——7——CVE-2023-49748—22.8%
——7——CVE-2024-56358—22.8%
——7——CVE-2023-36849—22.8%
——7——CVE-2025-49509—22.8%
——7——CVE-2021-44191—22.8%
——7——CVE-2025-36556—22.8%
——7——CVE-2024-9769—22.8%
——7——CVE-2021-44193—22.8%
——7——CVE-2019-25434—22.8%
——7——CVE-2023-32794—22.8%
——7——CVE-2026-22017—22.8%
——7——CVE-2026-40605—22.8%
——7Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary data loss and service disruption. Version 2.17.1 fixes the issue.50dCVE-2026-34276—22.8%
——7——CVE-2026-344255.4 MED22.8%
——7OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails to recognize. Attackers can craft commands such as piped execution, command substitution, or subshell invocation to bypass the validateScriptFileForShellBleed() validation checks and execute arbitrary script content that would otherwise be blocked.48dCVE-2022-41420—22.8%
——7——CVE-2023-27445—22.8%
——7——CVE-2024-54349—22.8%
——7——CVE-2026-706957.7 HIG22.8%
——7Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).16dCVE-2023-32744—22.8%
——7——CVE-2021-44192—22.8%
——7——CVE-2023-36834—22.8%
——7——CVE-2026-728408.8 HIG22.8%
——7OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.1dCVE-2025-13829—22.8%
——7Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user.
Critical information retrieved:
* APIKEY (1 year user Session)
* RefreshToken (10 minutes user Session)
* Password hashed with bcrypt
* User IP
* Email
* Full Name8d