Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1371—21.5%
——6——CVE-2023-37770—21.5%
——6——CVE-2021-26401—21.5%
——6——CVE-2022-38139—21.5%
——6——CVE-2025-15482—21.5%
——6——CVE-2024-46889—21.5%
——6——CVE-2025-2290—21.5%
——6——CVE-2025-32562—21.5%
——6——CVE-2021-1103—21.5%
——6——CVE-2026-637424.3 MED21.5%
——6SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to confirm or recover restricted field values through repeated guesses.48dCVE-2026-609405.7 MED21.5%
——6Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).28dCVE-2025-10879—21.5%
——6——CVE-2026-593155.3 MED21.5%
——6The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier8dCVE-2006-6286—21.5%
——6——CVE-2024-37409—21.5%
——6——CVE-2025-22477—21.5%
——6——CVE-2026-21436—21.5%
——6——CVE-2024-41023—21.5%
——6——CVE-2025-25142—21.5%
——6——CVE-2025-3999—21.5%
——6——CVE-2026-33531—21.5%
——6——CVE-2025-60856—21.5%
——6——CVE-2022-38773—21.5%
——6——CVE-2017-7113—21.5%
——6——CVE-2025-53509—21.5%
——6——CVE-2005-2134—21.5%
——6——CVE-2025-32490—21.5%
——6——CVE-2026-25759—21.5%
——6——CVE-2025-46570—21.5%
——6——CVE-2026-2977—21.5%
——6——CVE-2021-0166—21.5%
——6——CVE-2008-4676—21.5%
——6——CVE-2025-25133—21.5%
——6——CVE-2025-61543—21.5%
——6——CVE-2025-62382—21.5%
——6——CVE-2025-59111—21.5%
——6——CVE-2023-2301—21.5%
——6——CVE-2025-6210—21.5%
——6——CVE-2025-32512—21.5%
——6——CVE-2026-452267.1 HIG21.5%
——6Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds pointing to victim workflow UUIDs to load and execute those workflows under attacker-controlled execution paths, exposing victim workflow outputs and triggering workflow nodes with unintended side effects.56d