Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,294
- Medium6,569
- Low706
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-5159—30.3%
——9——CVE-2015-3767—30.3%
——9——CVE-2026-56276—30.3%
——9——CVE-2026-90107.5 HIG30.3%
——9The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL queries. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.57dCVE-2026-37979—30.3%
——9——CVE-2025-30803—30.3%
——9——CVE-2025-5696—30.3%
——9——CVE-2026-762106.5 MED30.3%
——9phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an <img> tag whose src references a local file under the web root's content/ directory (e.g., content/core/config/database.php). When the PDF is generated, phpMyFAQ attempts to read the referenced file; because it is not a valid image the resulting error is converted into an uncaught exception whose stack trace discloses part of the file's contents to any user who triggers the PDF export. By default the disclosed portion is truncated (zend.exception_string_param_max_len), but a larger configured value can result in disclosure of entire files, including database credentials.17dCVE-2017-0670—30.3%
——9——CVE-2026-188285.4 MED30.3%
——9IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow.24dCVE-2025-20755—30.3%
——9——CVE-2025-20792—30.3%
——9——CVE-2020-26601—30.3%
——9——CVE-2024-21515—30.3%
——9——CVE-2024-25893—30.3%
——9——CVE-2020-25056—30.3%
——9——CVE-2026-456029.1 CRI30.3%
——9No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.60dCVE-2025-4497—30.3%
——9——CVE-2025-55731—30.3%
——9——CVE-2025-24972—30.3%
——9——CVE-2025-7970—30.3%
——9——CVE-2026-6591—30.3%
——9——CVE-2025-59828—30.3%
——9——CVE-2025-26009—30.3%
——9——CVE-2026-707498.1 HIG30.3%
——9Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).24dCVE-2024-41614—30.3%
——9——CVE-2024-203635.8 MED30.3%
——9Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.38dCVE-2019-11110—30.3%
——9——CVE-2021-43548—30.3%
——9——CVE-2025-52894—30.3%
——9——CVE-2026-625018.1 HIG30.3%
——9Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).22dCVE-2026-856647.5 HIG30.3%
——9Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction.8dCVE-2025-66078—30.3%
——9——CVE-2013-0309—30.3%
——9——CVE-2026-47345—30.3%
——9Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.57dCVE-2013-0219—30.3%
——9——CVE-2024-39736—30.3%
——9——CVE-2020-36881—30.3%
——9——CVE-2024-49060—30.3%
——9——CVE-2020-1799—30.3%
——9——