Vulnerabilities exploitable today
375,890in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,708
- Medium6,690
- Low725
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-3585—28.3%
——9——CVE-2026-45033—28.3%
——9——CVE-2020-2647—28.3%
——9——CVE-2025-50105—28.3%
——9——CVE-2024-4739—28.3%
——9——CVE-2017-11076—28.3%
——9——CVE-2024-56236—28.3%
——9——CVE-2025-23407—28.3%
——9——CVE-2026-7651—28.3%
——9——CVE-2014-3953—28.3%
——9——CVE-2025-53923—28.3%
——9——CVE-2023-41071—28.3%
——9——CVE-2025-58734—28.3%
——9——CVE-2019-17345—28.3%
——9——CVE-2024-30415—28.3%
——9——CVE-2012-1720—28.3%
——9——CVE-2025-58730—28.3%
——9——CVE-2020-37143—28.3%
——9——CVE-2026-5361—28.3%
——9——CVE-2011-1474—28.3%
——9——CVE-2012-0808—28.3%
——9——CVE-2013-1928—28.3%
——9——CVE-2024-54241—28.3%
——9——CVE-2016-3992—28.3%
——9——CVE-2024-12329—28.3%
——9——CVE-2025-6516—28.3%
——9——CVE-2024-48936—28.3%
——9——CVE-2019-6170—28.3%
——9——CVE-2025-1231—28.3%
——9——CVE-2013-4425—28.3%
——9——CVE-2026-414538.8 HIG28.3%
——9Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.7dCVE-2025-11893—28.3%
——9——CVE-2023-52715—28.3%
——9——CVE-2024-57426—28.3%
——9——CVE-2026-34455—28.3%
——9——CVE-2023-44112—28.3%
——9——CVE-2020-0528—28.3%
——9——CVE-2022-43042—28.3%
——9——CVE-2026-608266.6 MED28.3%
——9Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).47dCVE-2024-30512—28.3%
——9——