Vulnerabilities exploitable today
377,882in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,336
- High8,527
- Medium6,725
- Low744
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-25783—30.8%
——9——CVE-2023-23789—30.8%
——9——CVE-2023-25479—30.8%
——9——CVE-2023-25490—30.8%
——9——CVE-2023-23875—30.8%
——9——CVE-2023-23733—30.8%
——9——CVE-2025-40666—30.8%
——9——CVE-2026-637416.5 MED30.8%
——9SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the RPC use method and SurrealQL executor.58dCVE-2023-27416—30.8%
——9——CVE-2023-28695—30.8%
——9——CVE-2023-23818—30.8%
——9——CVE-2025-9937—30.8%
——9——CVE-2023-25782—30.8%
——9——CVE-2023-23710—30.8%
——9——CVE-2023-25484—30.8%
——9——CVE-2010-4420—30.8%
——9——CVE-2023-24376—30.8%
——9——CVE-2017-2397—30.8%
——9——CVE-2023-33323—30.8%
——9——CVE-2026-0667—30.8%
——9CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.51dCVE-2023-34183—30.8%
——9——CVE-2026-1224—30.8%
——9——CVE-2023-25451—30.8%
——9——CVE-2006-1283—30.8%
——9——CVE-2016-9215—30.8%
——9——CVE-2023-32958—30.8%
——9——CVE-2026-764284.9 MED30.8%
——9A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database.
This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the session database. To exploit this vulnerability, the attacker must have valid administrative credentials.1dCVE-2023-28934—30.8%
——9——CVE-2025-14929—30.8%
——9——CVE-2026-66665.9 MED30.8%
——9A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.58dCVE-2021-46900—30.8%
——9——CVE-2023-32498—30.8%
——9——CVE-2022-45827—30.8%
——9——CVE-2023-25977—30.8%
——9——CVE-2023-36530—30.8%
——9——CVE-2023-29438—30.8%
——9——CVE-2022-47157—30.8%
——9——CVE-2023-28751—30.8%
——9——CVE-2023-25485—30.8%
——9——CVE-2022-46861—30.8%
——9——