Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-126958.1 HIG21.4%
——6The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.13dCVE-2014-6873—21.4%
——6——CVE-2025-66201—21.4%
——6——CVE-2026-30078—21.4%
——6——CVE-2022-4549—21.4%
——6——CVE-2026-48904—21.4%
——6——CVE-2014-6909—21.4%
——6——CVE-2025-69430—21.4%
——6——CVE-2024-48898—21.4%
——6——CVE-2017-11747—21.4%
——6——CVE-2026-163628.8 HIG21.4%
——6Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.46dCVE-2024-2211—21.4%
——6——CVE-2026-624845.9 MED21.4%
——6Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).43dCVE-2026-843249.0 CRI21.4%
——6Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)5dCVE-2014-7467—21.4%
——6——CVE-2014-7334—21.4%
——6——CVE-2025-48448—21.4%
——6——CVE-2026-53537—21.4%
——6——CVE-2025-37881—21.4%
——6——CVE-2025-33023—21.4%
——6——CVE-2025-9452—21.4%
——6——CVE-2026-0912—21.4%
——6——CVE-2024-45400—21.4%
——6——CVE-2024-7863—21.4%
——6——CVE-2026-671815.4 MED21.4%
——6Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.40dCVE-2023-25526—21.4%
——6——CVE-2026-58638.8 HIG21.4%
——6Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)46dCVE-2014-6855—21.4%
——6——CVE-2026-10831—21.4%
——6——CVE-2014-7585—21.4%
——6——CVE-2025-31876—21.4%
——6——CVE-2014-7310—21.4%
——6——CVE-2025-2352—21.4%
——6——CVE-2025-26159—21.4%
——6——CVE-2014-7341—21.4%
——6——CVE-2025-47651—21.4%
——6——CVE-2014-7798—21.4%
——6——CVE-2026-47244—21.4%
——6——CVE-2026-26079—21.4%
——6——CVE-2025-15606—21.4%
——6——