Vulnerabilities exploitable today
368,208in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,147
- High7,679
- Medium5,506
- Low542
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-53599—19.2%
——6——CVE-2021-39805—19.2%
——6——CVE-2026-46810—19.2%
——6——CVE-2024-54176—19.2%
——6——CVE-2026-3079—19.2%
——6——CVE-2024-33228—19.2%
——6——CVE-2025-30106—19.2%
——6——CVE-2026-63360—19.2%
——6LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding.
This issue affects LimeSurvey: 7.0.5.6dCVE-2024-5789—19.2%
——6——CVE-2024-53152—19.2%
——6——CVE-2026-55197—19.2%
——6——CVE-2024-23216—19.2%
——6——CVE-2022-32914—19.2%
——6——CVE-2026-42341—19.2%
——6FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gateway if not actively needed and/or restrict access to `/ipn.php` at the web server level (e.g., via IP allowlisting), noting that this may interfere with legitimate payment callback processing.58dCVE-2025-40679—19.2%
——6——CVE-2020-8968—19.2%
——6——CVE-2017-18653—19.2%
——6——CVE-2026-23782—19.2%
——6——CVE-2026-125136.8 MED19.2%
——6The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.6dCVE-2026-273117.8 HIG19.2%
——6Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.7dCVE-2025-62261—19.2%
——6——CVE-2025-25010—19.2%
——6——CVE-2025-2598—19.2%
——6——CVE-2026-33834—19.2%
——6——CVE-2024-5869—19.2%
——6——CVE-2023-6314—19.2%
——6——CVE-2026-726927.5 HIG19.2%
——6A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and a caller-supplied DeclineBy pointer without verifying the caller's identity, enabling workflow termination and evidentiary record falsification against any accessible document.8dCVE-2024-2483—19.2%
——6——CVE-2025-36090—19.2%
——6——CVE-2021-4453—19.2%
——6——CVE-2025-12772—19.2%
——6——CVE-2023-50946—19.2%
——6——CVE-2024-3987—19.2%
——6——CVE-2026-54029—19.2%
——6——CVE-2026-605216.5 MED19.2%
——6Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data as well as unauthorized read access to a subset of Oracle Advanced Pricing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).27dCVE-2026-351453.1 LOW19.2%
——6HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to an unencrypted connection (HTTP) and conduct man-in-the-middle (MitM) attacks. To remediate this, the application must include the "Strict-Transport-Security" header in all web application responses.48dCVE-2021-25366—19.2%
——6——CVE-2026-34309—19.2%
——6——CVE-2024-5731—19.2%
——6——CVE-2024-50272—19.2%
——6——