Vulnerabilities exploitable today
354,867in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,555
- High9,167
- Medium7,432
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44659—6.1%
——2——CVE-2023-53765—6.1%
——2——CVE-2025-41392—6.1%
——2——CVE-2025-38185—6.1%
——2——CVE-2025-6923—6.1%
——2——CVE-2025-40287—6.1%
——2——CVE-2023-53134—6.1%
——2——CVE-2026-470112.6 LOW6.1%
——2Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).10dCVE-2024-34595—6.1%
——2——CVE-2025-4198—6.1%
——2——CVE-2025-13955—6.1%
——2——CVE-2026-32891—6.1%
——2——CVE-2025-30919—6.1%
——2——CVE-2024-11263—6.1%
——2——CVE-2023-53750—6.1%
——2——CVE-2024-20832—6.1%
——2——CVE-2025-37790—6.1%
——2——CVE-2026-28678—6.1%
——2Rejected reason: Further research determined the issue is not a vulnerability.33dCVE-2020-0115—6.1%
——2——CVE-2025-20935—6.1%
——2——CVE-2025-38109—6.1%
——2——CVE-2026-656965.4 MED6.1%
——2Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.10dCVE-2024-13522—6.1%
——2——CVE-2025-40289—6.1%
——2——CVE-2024-43866—6.1%
——2——CVE-2025-12575—6.1%
——2——CVE-2019-11341—6.1%
——2——CVE-2024-9450—6.1%
——2——CVE-2022-38707—6.1%
——2——CVE-2023-43079—6.1%
——2——CVE-2025-20882—6.1%
——2——CVE-2025-2098—6.1%
——2——CVE-2026-151465.9 MED6.1%
——2GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.18dCVE-2025-6241—6.1%
——2——CVE-2024-235704.3 MED6.1%
——2HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.16dCVE-2025-34180—6.1%
——2——CVE-2023-53358—6.1%
——2——CVE-2023-53806—6.1%
——2——CVE-2025-52713—6.1%
——2——CVE-2024-48842—6.1%
——2——