Vulnerabilities exploitable today
369,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,152
- High7,669
- Medium5,612
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22667—19.9%
——6——CVE-2024-0103—19.9%
——6——CVE-2026-7025—19.9%
——6——CVE-2022-49530—19.9%
——6——CVE-2024-35759—19.9%
——6——CVE-2025-22647—19.9%
——6——CVE-2023-52467—19.9%
——6——CVE-2026-125628.8 HIG19.9%
——6The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communications Framework (TCF)
service that does not require any authentication, allowing an attacker
to directly interact with the Linux environment that powers the device.
Once connected, an attacker can freely view and modify the filesystem,
manipulate running processes, and control network interfaces, enabling
deep alteration of system behavior.36dCVE-2026-609988.0 HIG19.9%
——6Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).15dCVE-2020-8755—19.9%
——6——CVE-2021-34751—19.9%
——6——CVE-2025-69303—19.9%
——6——CVE-2024-54110—19.9%
——6——CVE-2022-22908—19.9%
——6——CVE-2019-0150—19.9%
——6——CVE-2026-6218—19.9%
——6——CVE-2025-22665—19.9%
——6——CVE-2026-21783—19.9%
——6——CVE-2023-34160—19.9%
——6——CVE-2025-23111—19.9%
——6——CVE-2025-57990—19.9%
——6——CVE-2017-2707—19.9%
——6——CVE-2026-04118.0 HIG19.9%
——6An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability.
Orbi WiFi Systems without satellite devices are not impacted by this issue.45dCVE-2024-45392—19.9%
——6——CVE-2025-27258—19.9%
——6——CVE-2024-12753—19.9%
——6——CVE-2026-56714.3 MED19.9%
——6A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Impacted is an unknown function of the file /admin/class%20schedule/delete_batch.php of the component Class Schedule Deletion Endpoint. Executing a manipulation of the argument batch can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.44dCVE-2026-828017.3 HIG19.9%
——6A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.4dCVE-2026-565802.2 LOW19.9%
——6HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.33dCVE-2025-25188—19.9%
——6——CVE-2026-595297.5 HIG19.9%
——6Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.40dCVE-2026-673288.1 HIG19.9%
——6@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.33dCVE-2020-6971—19.9%
——6——CVE-2025-2231—19.9%
——6——CVE-2026-44298—19.9%
——6——CVE-2026-93507.3 HIG19.9%
——6A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.45dCVE-2026-726777.3 HIG19.9%
——6Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.3dCVE-2023-1077—19.9%
——6——CVE-2026-24738—19.9%
——6——CVE-2026-34987—19.9%
——6——