Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,374
- High9,659
- Medium5,457
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-30654—15.9%
——5——CVE-2023-2976—15.9%
——5——CVE-2021-43050—15.9%
——5——CVE-2026-32539—15.9%
——5——CVE-2026-2247—15.9%
——5——CVE-2026-624465.3 MED15.9%
——5Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).5dCVE-2025-1091—15.9%
——5——CVE-2023-6980—15.9%
——5——CVE-2024-32800—15.9%
——5——CVE-2026-80199—15.9%
——5——CVE-2026-710628.5 HIG15.9%
——5Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).9dCVE-2026-24941—15.9%
——5——CVE-2022-21163—15.9%
——5——CVE-2025-66551—15.9%
——5——CVE-2024-56242—15.9%
——5——CVE-2024-28764—15.9%
——5——CVE-2026-99126.5 MED15.9%
——5Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)39dCVE-2026-20076—15.9%
——5——CVE-2026-733526.5 MED15.9%
——5Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.9dCVE-2024-34414—15.9%
——5——CVE-2025-3774—15.9%
——5——CVE-2026-6455—15.9%
——5——CVE-2024-36033—15.9%
——5——CVE-2024-49935—15.9%
——5——CVE-2013-4481—15.9%
——5——CVE-2016-20027—15.9%
——5——CVE-2022-42784—15.9%
——5——CVE-2026-138876.5 MED15.9%
——5Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)54dCVE-2026-5717—15.9%
——5——CVE-2025-54471—15.9%
——5——CVE-2026-25926—15.9%
——5——CVE-2025-13032—15.9%
——5——CVE-2025-58795—15.9%
——5——CVE-2024-49264—15.9%
——5——CVE-2022-50836—15.9%
——5——CVE-2026-106614.3 MED15.9%
——5A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the argument input_image_url leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The identifier of the patch is 5b37be25242e73dc4cf1328974d30458b9e5d67e. To fix this issue, it is recommended to deploy a patch.38dCVE-2026-139136.5 MED15.9%
——5Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)54dCVE-2025-32098—15.9%
——5——CVE-2026-601938.5 HIG15.9%
——5Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).26dCVE-2026-138266.5 MED15.9%
——5Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)54d