Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,699
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,246
- High8,352
- Medium6,366
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-613408.2 HIG22.2%
——7Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).7dCVE-2025-10703—22.2%
——7——CVE-2026-208747.8 HIG22.2%
——7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.42dCVE-2025-281707.6 HIG22.2%
——7Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.67dCVE-2025-46855—22.2%
——7——CVE-2024-56351—22.2%
——7——CVE-2026-35234—22.2%
——7——CVE-2025-53373—22.2%
——7——CVE-2025-26381—22.2%
——7——CVE-2026-657845.5 MED22.2%
——7Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.25dCVE-2026-367386.8 MED22.2%
——7U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical access to the UART pins can connect to the interface and gain unrestricted access to device functionality.72dCVE-2019-5686—22.2%
——7——CVE-2025-46843—22.2%
——7——CVE-2021-22677—22.2%
——7——CVE-2024-9864—22.2%
——7——CVE-2025-46871—22.2%
——7——CVE-2026-727206.4 MED22.2%
——7Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute values are reparsed as markup. Crafted Vimeo iframe sources, secure-upload URLs or dimensions, and hashtag data-slug values can cause decoded attribute text to be reinterpreted as HTML. The vulnerable conversion also fails to strictly validate the Vimeo iframe host and path, allowing non-Vimeo allowlisted iframes to be converted. This issue is fixed in versions 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1.2dCVE-2019-19894—22.2%
——7——CVE-2026-4718—22.2%
——7——CVE-2025-8068—22.2%
——7——CVE-2025-37156—22.2%
——7——CVE-2025-23080—22.2%
——7——CVE-2024-9607—22.2%
——7——CVE-2024-10647—22.2%
——7——CVE-2026-208677.8 HIG22.2%
——7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.42dCVE-2016-1963—22.2%
——7——CVE-2025-56353—22.2%
——7——CVE-2026-710188.2 HIG22.2%
——7Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).17dCVE-2024-9241—22.2%
——7——CVE-2025-53545—22.2%
——7——CVE-2025-46847—22.2%
——7——CVE-2024-27780—22.2%
——7——CVE-2021-39049—22.2%
——7——CVE-2025-46699—22.2%
——7——CVE-2026-1048—22.2%
——7——CVE-2021-39050—22.2%
——7——CVE-2026-208157.0 HIG22.2%
——7Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.42dCVE-2026-49826—22.2%
——7Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available.27dCVE-2026-28210—22.2%
——7——CVE-2025-46848—22.2%
——7——