Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,224
- High7,944
- Medium6,436
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23107—27.5%
——8——CVE-2024-30150—27.5%
——8——CVE-2018-20029—27.5%
——8——CVE-2023-39223—27.5%
——8——CVE-2024-9967—27.5%
——8——CVE-2024-5576—27.4%
——8——CVE-2016-6910—27.4%
——8——CVE-2006-5706—27.4%
——8——CVE-2023-5873—27.4%
——8——CVE-2024-4160—27.4%
——8——CVE-2023-45372—27.4%
——8——CVE-2001-1378—27.4%
——8——CVE-2021-26100—27.4%
——8——CVE-2023-4839—27.4%
——8——CVE-2024-42497—27.4%
——8——CVE-2024-3663—27.4%
——8——CVE-2024-3602—27.4%
——8——CVE-2026-567028.8 HIG27.4%
——8Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.8dCVE-2026-168637.7 HIG27.4%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.34dCVE-2007-5498—27.4%
——8——CVE-2024-11133—27.4%
——8——CVE-2023-21596—27.4%
——8——CVE-2025-45326—27.4%
——8——CVE-2012-3211—27.4%
——8——CVE-2020-27212—27.4%
——8——CVE-2024-7231—27.4%
——8——CVE-2019-256637.1 HIG27.4%
——8SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.54dCVE-2023-33684—27.4%
——8——CVE-2015-4874—27.4%
——8——CVE-2024-7229—27.4%
——8——CVE-2024-5438—27.4%
——8——CVE-2026-4328—27.4%
——8——CVE-2019-256647.1 HIG27.4%
——8SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.54dCVE-2020-12933—27.4%
——8——CVE-2026-48064—27.4%
——8——CVE-2026-19716—27.4%
——8Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.15dCVE-2026-41143—27.4%
——8——CVE-2025-58595—27.4%
——8——CVE-2025-64423—27.4%
——8——CVE-2007-5664—27.4%
——8——