Vulnerabilities exploitable today
356,393in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,787
- High11,164
- Medium7,399
- Low700
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-7626—92.5%
——28——CVE-2008-6872—92.5%
——28——CVE-2007-5902—92.5%
——28——CVE-2019-5477—92.5%
——28——CVE-2008-1329—92.5%
——28——CVE-2008-6770—92.5%
——28——CVE-2008-0674—92.5%
——28——CVE-2022-0918—92.5%
——28——CVE-2013-4652—92.5%
——28——CVE-2012-1832—92.5%
——28——CVE-2007-4572—92.5%
——28——CVE-2018-20234—92.5%
——28——CVE-2021-24970—92.5%
——28——CVE-2021-24066—92.5%
——28——CVE-2013-4095—92.5%
——28——CVE-2008-6771—92.5%
——28——CVE-2017-16366—92.5%
——28——CVE-2015-0303—92.5%
——28——CVE-2013-0659—92.5%
——28——CVE-2025-52692—92.5%
——28——CVE-2023-23161—92.5%
——28——CVE-2009-3709—92.5%
——28——CVE-2024-355848.8 HIG92.5%
——28SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.32dCVE-2024-39762—92.5%
——28——CVE-2020-1416—92.5%
——28——CVE-2007-1691—92.5%
——28——CVE-2009-0349—92.5%
——28——CVE-2026-2227—92.5%
——28——CVE-2022-25356—92.5%
——28——CVE-2008-2430—92.5%
——28——CVE-2019-3931—92.5%
——28——CVE-2025-4755—92.5%
——28——CVE-2011-1702—92.5%
——28——CVE-2011-1703—92.5%
——28——CVE-1999-0274—92.5%
——28——CVE-2013-6193—92.5%
——28——CVE-2008-3552—92.5%
——28——CVE-2008-3553—92.5%
——28——CVE-2004-2375—92.5%
——28——CVE-2017-6683—92.5%
——28——