Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,457
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1767—15.6%
——5——CVE-2026-45108—15.6%
——5——CVE-2025-34050—15.6%
——5——CVE-2025-45893—15.6%
——5——CVE-2022-32782—15.6%
——5——CVE-2026-349277.8 HIG15.6%
——5An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.37dCVE-2022-32902—15.6%
——5——CVE-2024-358137.8 HIG15.6%
——5In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Avoid negative index with array access
Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns
prev_idata = idatas[i - 1], but doesn't check that the iterator i is
greater than zero. Let's fix this by adding a check.25dCVE-2026-708647.6 HIG15.6%
——5Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).2dCVE-2026-627267.0 HIG15.6%
——5Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.11dCVE-2025-6759—15.6%
——5——CVE-2017-2728—15.6%
——5——CVE-2026-429787.8 HIG15.6%
——5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.37dCVE-2021-0160—15.6%
——5——CVE-2017-18300—15.6%
——5——CVE-2024-22237—15.6%
——5——CVE-2026-33732—15.6%
——5——CVE-2025-68010—15.6%
——5——CVE-2012-0953—15.6%
——5——CVE-2021-36315—15.6%
——5——CVE-2025-60298—15.6%
——5——CVE-2026-7002—15.6%
——5——CVE-2026-55946.3 MED15.6%
——5A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.36dCVE-2026-94516.3 MED15.6%
——5A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.37dCVE-2023-1652—15.6%
——5——CVE-2024-13547—15.6%
——5——CVE-2021-47058—15.6%
——5——CVE-2025-27380—15.6%
——5——CVE-2025-32691—15.6%
——5——CVE-2025-68011—15.6%
——5——CVE-2024-39923—15.6%
——5——CVE-2024-1334—15.6%
——5——CVE-2021-3550—15.6%
——5——CVE-2024-39519—15.6%
——5——CVE-2021-22705—15.6%
——5——CVE-2026-183484.1 MED15.6%
——5Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.13hCVE-2023-22818—15.6%
——5——CVE-2025-24937—15.6%
——5——CVE-2025-49043—15.6%
——5——CVE-2021-30066—15.6%
——5——