Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-43277—21.8%
——7——CVE-2026-733986.5 MED21.8%
——7Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.19dCVE-2026-145287.4 HIG21.8%
——7IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.34dCVE-2026-626035.4 MED21.8%
——7Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).14dCVE-2023-23540—21.8%
——7——CVE-2025-1489—21.8%
——7——CVE-2017-8155—21.8%
——7——CVE-2025-13701—21.8%
——7——CVE-2026-24546—21.8%
——7——CVE-2025-11068—21.8%
——7——CVE-2025-24439—21.8%
——7——CVE-2025-3037—21.8%
——7——CVE-2026-24428—21.8%
——7——CVE-2023-51413—21.8%
——7——CVE-2025-23982—21.8%
——7——CVE-2024-13399—21.8%
——7——CVE-2025-3498—21.8%
——7——CVE-2026-33759—21.8%
——7——CVE-2026-125118.1 HIG21.8%
——7The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.56dCVE-2023-45720—21.8%
——7——CVE-2026-790886.5 MED21.8%
——7Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)8dCVE-2025-21169—21.8%
——7——CVE-2025-1406—21.8%
——7——CVE-2012-6646—21.8%
——7——CVE-2026-42433—21.8%
——7——CVE-2026-646197.5 HIG21.8%
——7FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve other users' files without authentication.47dCVE-2026-64972—21.8%
——7ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out of the attribute value, and append a new event handler such as onload. The related preview_top.php file sanitises these parameters, but that does not prevent XSS in the parent frameset rendered by preview.php itself.
Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.11dCVE-2024-4028—21.8%
——7——CVE-2024-22856—21.8%
——7——CVE-2025-66513—21.8%
——7——CVE-2023-3290—21.8%
——7——CVE-2023-38349—21.8%
——7——CVE-2023-21597—21.8%
——7——CVE-2017-13679—21.8%
——7——CVE-2024-38290—21.8%
——7——CVE-2024-5252—21.8%
——7——CVE-2026-728386.5 MED21.8%
——7FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability.22dCVE-2025-34247—21.8%
——7——CVE-2025-55267—21.8%
——7——CVE-2026-554645.4 MED21.8%
——7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyperlinks, allowing a user with assets.edit permission to place a malicious link in a markdown-textarea custom field that executes arbitrary JavaScript when another user opens the asset detail page and clicks the link. This issue is fixed in version 8.6.2.57d