Vulnerabilities exploitable today
369,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,149
- High7,649
- Medium5,616
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-49085—20.1%
——6——CVE-2024-54106—20.1%
——6——CVE-2024-53441—20.1%
——6——CVE-2021-27504—20.1%
——6——CVE-2025-10892—20.1%
——6——CVE-2026-612907.1 HIG20.1%
——6Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).16dCVE-2026-8918—20.1%
——6——CVE-2021-34721—20.1%
——6——CVE-2026-93573.5 LOW20.1%
——6A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. VulDB is withholding an extended redistribution of exploit details to prevent simplified exploitation. The vendor was contacted early about this disclosure but did not respond in any way.45dCVE-2025-28905—20.1%
——6——CVE-2025-22749—20.1%
——6——CVE-2025-12394—20.1%
——6——CVE-2025-68136—20.1%
——6——CVE-2024-37519—20.1%
——6——CVE-2025-46958—20.1%
——6——CVE-2025-41661—20.1%
——6——CVE-2026-8699—20.1%
——6A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side validation and lack of proper output encoding of user-controlled input in a certain field. An attacker with administrative privileges can inject crafted HTML or JS payloads into the affected field. The payload is stored and later executed when the affected page is rendered in an administrator's browser.Successful exploitation allows execution of arbitrary JavaScript in an admin's browser, potentially leading to session hijacking and unauthorized access to router configuration, possibly resulting in exposure of sensitive data and modification of device settings.
The vulnerability affects ISP-managed firmware variants of the product. Remediation is coordinated through service providers.65dCVE-2025-25877—20.1%
——6——CVE-2026-86207.5 HIG20.1%
——6IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.45dCVE-2019-16283—20.1%
——6——CVE-2025-24542—20.1%
——6——CVE-2012-0644—20.1%
——6——CVE-2012-5630—20.0%
——6——CVE-2026-685537.1 HIG20.0%
——6Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_redis() in src/apps/relay/hiredis_libevent2.c then passes the attacker-controlled key as the format argument to redisAsyncCommand() while supplying only one variadic value, causing hiredis redisvFormatCommand() to read past the va_list. Exploitation can crash the coturn process and terminate active TURN sessions or disclose stack memory into Redis. This issue is fixed in version 4.13.0.16dCVE-2025-13441—20.0%
——6——CVE-2026-40773—20.0%
——6——CVE-2026-24768—20.0%
——6——CVE-2025-54780—20.0%
——6——CVE-2026-180398.1 HIG20.0%
——6The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.11dCVE-2026-32813—20.0%
——6——CVE-2026-184688.1 HIG20.0%
——6The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.11dCVE-2025-11816—20.0%
——6——CVE-2024-25528—20.0%
——6——CVE-2026-31163—20.0%
——6——CVE-2025-55052—20.0%
——6——CVE-2025-9122—20.0%
——6——CVE-2020-7311—20.0%
——6——CVE-2015-7814—20.0%
——6——CVE-2023-2662—20.0%
——6——CVE-2017-0790—20.0%
——6——