Vulnerabilities exploitable today
368,008in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,380
- High9,625
- Medium5,570
- Low544
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-41001—18.9%
——6——CVE-2025-20298—18.9%
——6——CVE-2025-25096—18.9%
——6——CVE-2024-52470—18.9%
——6——CVE-2024-52473—18.9%
——6——CVE-2023-52882—18.9%
——6——CVE-2021-27242—18.9%
——6——CVE-2026-40795—18.9%
——6——CVE-2024-4462—18.9%
——6——CVE-2026-13350—18.9%
——6——CVE-2026-28522—18.9%
——6——CVE-2025-30593—18.9%
——6——CVE-2026-21933—18.9%
——6——CVE-2026-4301—18.9%
——6——CVE-2024-42383—18.9%
——6——CVE-2024-50956—18.9%
——6——CVE-2026-625947.7 HIG18.9%
——6Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H).12dCVE-2023-0970—18.9%
——6——CVE-2026-3921—18.9%
——6——CVE-2025-10559—18.9%
——6——CVE-2025-65830—18.9%
——6——CVE-2026-31779—18.9%
——6——CVE-2024-38621—18.9%
——6——CVE-2023-20556—18.9%
——6——CVE-2018-25210—18.9%
——6——CVE-2025-52801—18.9%
——6——CVE-2026-672945.9 MED18.9%
——6FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP server certificate. In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.2dCVE-2025-22766—18.9%
——6——CVE-2021-35589—18.9%
——6——CVE-2026-21879—18.9%
——6——CVE-2021-38553—18.9%
——6——CVE-2022-40686—18.9%
——6——CVE-2025-61155—18.9%
——6——CVE-2024-13262—18.9%
——6——CVE-2022-45073—18.9%
——6——CVE-2024-47322—18.9%
——6——CVE-2024-30164—18.9%
——6——CVE-2023-20561—18.9%
——6——CVE-2026-3922—18.9%
——6——CVE-2013-1014—18.9%
——6——