Vulnerabilities exploitable today
354,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,622
- High9,423
- Medium7,591
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22996—5.2%
——2——CVE-2026-622245.4 MED5.2%
——2OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.14dCVE-2026-48613—5.2%
——2——CVE-2025-64380—5.2%
——2——CVE-2025-38557—5.2%
——2——CVE-2024-35207—5.2%
——2——CVE-2026-21503—5.2%
——2——CVE-2025-68760—5.2%
——2——CVE-2026-5026—5.2%
——2——CVE-2026-21502—5.2%
——2——CVE-2025-68751—5.2%
——2——CVE-2025-36116—5.2%
——2——CVE-2018-25200—5.2%
——2——CVE-2026-20662—5.2%
——2——CVE-2026-606358.8 HIG5.1%
——2Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).2dCVE-2025-38417—5.2%
——2——CVE-2024-36266—5.2%
——2——CVE-2026-565873.7 LOW5.2%
——2HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.2dCVE-2026-45880—5.2%
——2——CVE-2026-45973—5.2%
——2——CVE-2026-45874—5.2%
——2——CVE-2024-43781—5.2%
——2——CVE-2026-0063—5.2%
——2——CVE-2024-53160—5.2%
——2——CVE-2025-38654—5.2%
——2——CVE-2026-4971—5.2%
——2——CVE-2026-63873—5.2%
——2In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
aie2_populate_range() jumps back to the again label without calling
mmput(mm), leaking a reference to the mm_struct.
Add the missing mmput() before jumping to again.4dCVE-2017-9689—5.2%
——2——CVE-2026-21498—5.2%
——2——CVE-2026-45863—5.2%
——2——CVE-2025-37088—5.2%
——2——CVE-2026-606368.8 HIG5.1%
——2Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).2dCVE-2025-15622—5.2%
——2——CVE-2025-2501—5.2%
——2——CVE-2025-8386—5.2%
——2——CVE-2023-23348—5.2%
——2——CVE-2026-41125—5.2%
——2——CVE-2026-8576—5.2%
——2——CVE-2025-40582—5.2%
——2——CVE-2025-68762—5.2%
——2——