Vulnerabilities exploitable today
366,194in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,415
- High10,330
- Medium5,246
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-21428—15.3%
——5——CVE-2026-470615.6 MED15.3%
——5Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JDBC executes to compromise JDBC. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N).22dCVE-2026-44521—15.3%
——5——CVE-2026-502259.1 CRI15.3%
——5The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.36dCVE-2021-47962—15.3%
——5——CVE-2026-3527—15.3%
——5——CVE-2022-28200—15.3%
——5——CVE-2025-15112—15.3%
——5——CVE-2026-1093—15.3%
——5——CVE-2024-41068—15.3%
——5——CVE-2024-56600—15.3%
——5——CVE-2026-116719.6 CRI15.3%
——5Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)36dCVE-2021-0200—15.3%
——5——CVE-2026-153346.4 MED15.3%
——5The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.34dCVE-2026-27917—15.3%
——5——CVE-2024-55604—15.3%
——5——CVE-2026-153936.4 MED15.3%
——5The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.30dCVE-2024-47100—15.3%
——5——CVE-2026-27967—15.3%
——5——CVE-2019-25264—15.3%
——5——CVE-2026-469899.1 CRI15.3%
——5Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).34dCVE-2026-32195—15.3%
——5——CVE-2025-30455—15.3%
——5——CVE-2025-49570—15.3%
——5——CVE-2025-13988—15.3%
——5——CVE-2025-52043—15.3%
——5——CVE-2025-50949—15.3%
——5——CVE-2022-27635—15.3%
——5——CVE-2023-37992—15.3%
——5——CVE-2025-12834—15.3%
——5——CVE-2025-55647—15.2%
——5——CVE-2022-50762—15.2%
——5——CVE-2022-0192—15.2%
——5——CVE-2024-4811—15.2%
——5——CVE-2026-12527—15.2%
——5——CVE-2025-609677.3 HIG15.2%
——5Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.53dCVE-2024-27861—15.2%
——5——CVE-2023-2538—15.2%
——5——CVE-2026-2601—15.2%
——5——CVE-2018-9426—15.2%
——5——