Vulnerabilities exploitable today
367,144in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,256
- High9,258
- Medium5,266
- Low507
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-585886.1 MED17.0%
——5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.41dCVE-2025-24262—17.0%
——5——CVE-2024-38547—17.0%
——5——CVE-2025-5100—17.0%
——5——CVE-2025-8463—17.0%
——5——CVE-2023-25708—17.0%
——5——CVE-2025-56429—17.0%
——5——CVE-2023-34323—17.0%
——5——CVE-2023-49749—17.0%
——5——CVE-2026-33948—17.0%
——5——CVE-2023-25474—17.0%
——5——CVE-2023-25038—17.0%
——5——CVE-2022-1256—17.0%
——5——CVE-2021-1219—17.0%
——5——CVE-2023-48331—17.0%
——5——CVE-2022-25038—17.0%
——5——CVE-2022-50804—17.0%
——5——CVE-2026-58048.4 HIG17.0%
——5An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.38dCVE-2023-29054—16.9%
——5——CVE-2023-35773—16.9%
——5——CVE-2023-51257—16.9%
——5——CVE-2025-62800—16.9%
——5——CVE-2026-710237.5 HIG16.9%
——5Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).7dCVE-2026-53538—16.9%
——5——CVE-2026-504587.8 HIG16.9%
——5Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.40dCVE-2024-30112—16.9%
——5——CVE-2023-25475—16.9%
——5——CVE-2026-503617.8 HIG16.9%
——5Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.40dCVE-2022-46812—16.9%
——5——CVE-2024-47307—16.9%
——5——CVE-2024-3313—16.9%
——5——CVE-2023-25487—16.9%
——5——CVE-2023-25056—16.9%
——5——CVE-2023-30484—16.9%
——5——CVE-2026-27482—16.9%
——5——CVE-2025-63872—16.9%
——5——CVE-2023-25470—16.9%
——5——CVE-2023-32964—16.9%
——5——CVE-2025-24021—16.9%
——5——CVE-2023-25058—16.9%
——5——