Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-4265—33.9%
——10——CVE-2026-2446—33.9%
——10——CVE-2026-40195—33.9%
——10——CVE-2019-256948.2 HIG33.9%
——10Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify data.60dCVE-2026-581548.9 HIG33.9%
——10Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.51dCVE-2024-47944—33.9%
——10——CVE-2025-69228—33.9%
——10——CVE-2024-47362—33.9%
——10——CVE-2020-26570—33.9%
——10——CVE-2022-36036—33.9%
——10——CVE-2026-1618—33.9%
——10——CVE-2026-0696—33.9%
——10——CVE-2026-410802.9 LOW33.9%
——10libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.71dCVE-2021-44466—33.9%
——10——CVE-2025-11511—33.9%
——10——CVE-2025-5122—33.9%
——10——CVE-2026-736707.2 HIG33.9%
——10A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform table traversal, time-based blind, boolean-based blind, and error-based injection techniques to enumerate full database schema, access system tables such as information_schema, and chain the disclosure with secondary injection points to extract credential data.13dCVE-2024-50924—33.9%
——10——CVE-2024-50351—33.9%
——10——CVE-2021-39701—33.9%
——10——CVE-2026-601954.9 MED33.9%
——10Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON Duality). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).57dCVE-2025-24773—33.9%
——10——CVE-2025-11474—33.9%
——10——CVE-2021-2442—33.9%
——10——CVE-2025-11597—33.9%
——10——CVE-2024-2063—33.9%
——10——CVE-2023-4709—33.9%
——10——CVE-2022-41662—33.9%
——10——CVE-1999-0338—33.9%
——10——CVE-2005-0867—33.9%
——10——CVE-2024-5689—33.9%
——10——CVE-2025-11056—33.9%
——10——CVE-2017-15537—33.9%
——10——CVE-2020-15564—33.9%
——10——CVE-2017-12855—33.9%
——10——CVE-2019-12804—33.9%
——10——CVE-1999-0411—33.9%
——10——CVE-1999-0420—33.9%
——10——CVE-2023-33736—33.9%
——10——CVE-2025-31686—33.9%
——10——