Vulnerabilities exploitable today
369,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,150
- High7,652
- Medium5,617
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13659—20.0%
——6——CVE-2024-4473—20.0%
——6——CVE-2024-26903—20.0%
——6——CVE-2023-46720—20.0%
——6——CVE-2026-40793—20.0%
——6——CVE-2024-26840—20.0%
——6——CVE-2026-666476.5 MED20.0%
——6Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.17dCVE-2021-45089—20.0%
——6——CVE-2026-666936.5 MED20.0%
——6Subscriber Broken Access Control in Motors <= 1.4.113 versions.22dCVE-2024-34773—20.0%
——6——CVE-2023-42900—20.0%
——6——CVE-2017-0787—20.0%
——6——CVE-2019-4307—20.0%
——6——CVE-2026-28038—20.0%
——6——CVE-2025-4593—20.0%
——6——CVE-2025-59412—20.0%
——6——CVE-2026-55768—20.0%
——6GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.36dCVE-2024-43413—20.0%
——6——CVE-2020-25836—20.0%
——6——CVE-2026-609877.1 HIG20.0%
——6Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).36dCVE-2026-63641—20.0%
——6MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.18dCVE-2026-24768—20.0%
——6——CVE-2026-180398.1 HIG20.0%
——6The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthenticated attackers to register an account with an arbitrary role, including administrator, on sites where a custom profile field with a particular label has been configured.11dCVE-2025-54780—20.0%
——6——CVE-2026-40773—20.0%
——6——CVE-2026-32813—20.0%
——6——CVE-2026-184688.1 HIG20.0%
——6The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.11dCVE-2026-31172—20.0%
——6——CVE-2025-11890—20.0%
——6——CVE-2024-44062—20.0%
——6——CVE-2025-54859—20.0%
——6——CVE-2026-31164—20.0%
——6——CVE-2026-31176—20.0%
——6——CVE-2026-360286.8 MED20.0%
——6A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset59dCVE-2024-32635—20.0%
——6——CVE-2025-12602—20.0%
——6——CVE-2025-23187—20.0%
——6——CVE-2010-0436—20.0%
——6——CVE-2024-7108—20.0%
——6——CVE-2026-708377.1 HIG20.0%
——6Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as unauthorized read access to a subset of Oracle Financials for Asia/Pacific accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).3d