Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2009-3274—21.5%
——6——CVE-2023-52357—21.5%
——6——CVE-2022-24419—21.5%
——6——CVE-2023-0657—21.5%
——6——CVE-2026-1969—21.5%
——6——CVE-2026-34217—21.5%
——6——CVE-2016-0259—21.5%
——6——CVE-2022-47425—21.5%
——6——CVE-2026-705616.5 MED21.5%
——6TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any project or role authorization check. Attackers can enumerate sequential integer IDs through the attachment download endpoint to retrieve file contents from private projects they have no membership in, bypassing the per-project access control model and exposing test specifications, requirements documents, execution evidence, and other sensitive uploaded files across the entire installation.29dCVE-2025-60100—21.5%
——6——CVE-2001-1578—21.5%
——6——CVE-2026-138729.1 CRI21.5%
——6Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)64dCVE-2026-75162—21.5%
——6An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response.4dCVE-2025-32359—21.5%
——6——CVE-2024-5309—21.4%
——6——CVE-2026-707907.4 HIG21.5%
——6Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Telecommunications Billing Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).11dCVE-2022-24416—21.5%
——6——CVE-2025-64064—21.5%
——6——CVE-2026-126059.6 CRI21.5%
——6In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.29dCVE-2026-7052—21.5%
——6——CVE-2024-53566—21.5%
——6——CVE-2023-202475.0 MED21.5%
——6A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to improper error handling during remote access VPN authentication. An attacker could exploit this vulnerability by sending crafted requests during remote access VPN session establishment. A successful exploit could allow the attacker to bypass the configured multiple certificate authentication policy while retaining the privileges and permissions associated with the original connection profile.28dCVE-2026-32492—21.5%
——6——CVE-2019-15378—21.5%
——6——CVE-2025-54720—21.5%
——6——CVE-2026-57909—21.5%
——6A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.11dCVE-2007-5626—21.5%
——6——CVE-2025-62730—21.5%
——6——CVE-2006-6509—21.5%
——6——CVE-2026-41101—21.5%
——6——CVE-2025-2573—21.5%
——6——CVE-2024-27038—21.5%
——6——CVE-2025-64065—21.5%
——6——CVE-2026-25750—21.5%
——6——CVE-2026-595069.3 CRI21.5%
——6: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.11dCVE-2005-2073—21.5%
——6——CVE-2023-33200—21.5%
——6——CVE-2026-582115.4 MED21.5%
——6NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.61dCVE-2026-772337.2 HIG21.5%
——6The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only manifests when the 'Secondary' parser engine is active (parser_engine=default); it does not exist under the default 'new' DOM-based parser engine.3dCVE-2024-53786—21.5%
——6——