Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,150
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-612215.4 MED13.8%
——4Vulnerability in the Oracle Item Master product of Oracle E-Business Suite (component: iSet-up bugs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Item Master. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Item Master accessible data as well as unauthorized read access to a subset of Oracle Item Master accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).19dCVE-2022-47148—13.8%
——4——CVE-2025-21803—13.8%
——4——CVE-2023-25008—13.8%
——4——CVE-2023-42298—13.8%
——4——CVE-2022-50641—13.8%
——4——CVE-2021-29671—13.8%
——4——CVE-2021-1802—13.8%
——4——CVE-2026-601545.4 MED13.8%
——4Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).20dCVE-2022-45804—13.8%
——4——CVE-2021-31411—13.8%
——4——CVE-2025-7111—13.8%
——4——CVE-2024-50097—13.8%
——4——CVE-2025-5166—13.8%
——4——CVE-2024-29009—13.8%
——4——CVE-2025-5169—13.8%
——4——CVE-2022-50625—13.8%
——4——CVE-2022-2783—13.8%
——4——CVE-2025-29476—13.8%
——4——CVE-2021-22334—13.8%
——4——CVE-2026-603105.4 MED13.8%
——4Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).19dCVE-2025-7109—13.8%
——4——CVE-2025-7110—13.8%
——4——CVE-2025-1272—13.8%
——4——CVE-2023-22700—13.8%
——4——CVE-2021-34687—13.8%
——4——CVE-2026-9653—13.8%
——4A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.42dCVE-2026-92649.3 CRI13.8%
——4A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary system commands and read local files without user interaction by exploiting an embedded Internet Explorer 11 browser.34dCVE-2025-9123—13.7%
——4——CVE-2025-1433—13.7%
——4——CVE-2023-23497—13.7%
——4——CVE-2026-41126—13.7%
——4——CVE-2022-33176—13.7%
——4——CVE-2025-9857—13.7%
——4——CVE-2026-02349.1 CRI13.7%
——4An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.49dCVE-2022-23714—13.7%
——4——CVE-2025-8398—13.7%
——4——CVE-2025-33005—13.7%
——4——CVE-2024-269197.8 HIG13.7%
——4In the Linux kernel, the following vulnerability has been resolved:
usb: ulpi: Fix debugfs directory leak
The ULPI per-device debugfs root is named after the ulpi device's
parent, but ulpi_unregister_interface tries to remove a debugfs
directory named after the ulpi device itself. This results in the
directory sticking around and preventing subsequent (deferred) probes
from succeeding. Change the directory name to match the ulpi device.22dCVE-2024-50146—13.7%
——4——