Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45453—22.0%
——7——CVE-2021-30697—22.0%
——7——CVE-2026-1619—22.0%
——7——CVE-2026-41168—22.0%
——7——CVE-2023-51252—22.0%
——7——CVE-2026-737717.5 HIG22.0%
——7An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.5dCVE-2025-9921—22.0%
——7——CVE-2023-48039—22.0%
——7——CVE-2024-7542—22.0%
——7——CVE-2024-33767—22.0%
——7——CVE-1999-1429—22.0%
——7——CVE-2021-20295—22.0%
——7——CVE-2026-43935—22.0%
——7——CVE-2025-59337—22.0%
——7——CVE-2025-66549—22.0%
——7——CVE-2026-7712—22.0%
——7——CVE-2013-6122—22.0%
——7——CVE-2026-11848—22.0%
——7——CVE-2026-614387.3 HIG22.0%
——7PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.55dCVE-2026-177153.1 LOW22.0%
——7Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)36dCVE-2026-261996.5 MED22.0%
——7HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.42dCVE-2020-8474—22.0%
——7——CVE-2021-0632—22.0%
——7——CVE-2024-53763—22.0%
——7——CVE-2026-66065—22.0%
——7Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.35dCVE-2024-21180—22.0%
——7——CVE-2026-603927.8 HIG22.0%
——7Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).19dCVE-2019-16258—22.0%
——7——CVE-2022-41282—21.9%
——7——CVE-2024-13080—22.0%
——7——CVE-2024-51910—22.0%
——7——CVE-2025-36556—22.0%
——7——CVE-2024-32455—22.0%
——7——CVE-2025-41692—22.0%
——7——CVE-2024-51904—22.0%
——7——CVE-2026-30962—22.0%
——7——CVE-2017-0913—22.0%
——7——CVE-2026-40315—22.0%
——7——CVE-2026-55188—22.0%
——7——CVE-2025-53854—22.0%
——7——