Vulnerabilities exploitable today
359,691in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,519
- High11,197
- Medium7,131
- Low649
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22805—11.1%
——3——CVE-2024-20877—11.1%
——3——CVE-2025-46803—11.1%
——3——CVE-2024-37230—11.1%
——3——CVE-2026-38569—11.1%
——3——CVE-2024-35287—11.1%
——3——CVE-2025-59923—11.1%
——3——CVE-2025-660765.3 MED11.1%
——3Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.44dCVE-2025-13141—11.1%
——3——CVE-2025-47328—11.1%
——3——CVE-2021-26278—11.1%
——3——CVE-2022-41205—11.1%
——3——CVE-2024-37198—11.1%
——3——CVE-2026-44113—11.1%
——3——CVE-2026-21429—11.1%
——3——CVE-2024-8588—11.1%
——3——CVE-2026-24711—11.1%
——3——CVE-2024-10093—11.1%
——3——CVE-2024-8593—11.1%
——3——CVE-2026-606695.9 MED11.1%
——3Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Mexico product of Oracle PeopleSoft (component: Global Payroll for Mexico). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Mexico. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Mexico accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Mexico. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L).12dCVE-2024-9489—11.1%
——3——CVE-2024-43325—11.1%
——3——CVE-2024-9827—11.1%
——3——CVE-2026-6779—11.1%
——3——CVE-2024-58128—11.1%
——3——CVE-2026-491984.9 MED11.1%
——3Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.25dCVE-2026-179236.5 MED11.1%
——3Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)12dCVE-2024-8600—11.1%
——3——CVE-2023-4394—11.1%
——3——CVE-2026-577825.3 MED11.1%
——3Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.33dCVE-2025-68346—11.1%
——3——CVE-2026-25408—11.1%
——3——CVE-2026-179296.5 MED11.1%
——3Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)12dCVE-2026-2994—11.1%
——3——CVE-2026-577785.3 MED11.1%
——3Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.33dCVE-2009-5152—11.1%
——3——CVE-2024-49407—11.1%
——3——CVE-2026-91065.5 MED11.1%
——3A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to authorize it, as the scope was not displayed on the authorization consent screen. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.2, 3.20.4, 3.19.8, 3.18.11, 3.17.17, 3.16.20. This vulnerability was reported via the GitHub Bug Bounty program.44dCVE-2024-44162—11.1%
——3——CVE-2024-58129—11.1%
——3——