Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,224
- High7,944
- Medium6,436
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-256647.1 HIG27.4%
——8SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.54dCVE-2025-9025—27.4%
——8——CVE-2020-3702—27.4%
——8——CVE-2018-6433—27.4%
——8——CVE-2025-24003—27.4%
——8——CVE-2019-256637.1 HIG27.4%
——8SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.54dCVE-2020-27212—27.4%
——8——CVE-2024-7231—27.4%
——8——CVE-2024-5438—27.4%
——8——CVE-2026-190086.3 MED27.4%
——8A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. Such manipulation leads to link following. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.35dCVE-2026-1010—27.4%
——8——CVE-2024-4641—27.4%
——8——CVE-2026-645228.8 HIG27.4%
——8In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
mlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating
software state and skipping hardware offload setup.
That path jumps to the common success label before taking the eswitch mode
block. After tunnel-mode validation was moved earlier, the common success
label unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs,
this decrements esw->offloads.num_block_mode without a matching increment.
Return directly after installing the acquire SA offload handle, so only the
paths that successfully called mlx5_eswitch_block_mode() call the matching
unblock.51dCVE-2014-1265—27.4%
——8——CVE-2026-634285.8 MED27.4%
——8HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim in `submission.hiddenFields`, without validating the supplied `id`/`name` against the form's declared `form.hiddenFields` schema. An anonymous form submitter can therefore inject arbitrary key/value pairs (including XSS payloads, fake authorization metadata, integration-relevant values) into the stored submission. These fields are subsequently forwarded as-is to every webhook integration registered on the form. Version 3.0.0-rc.9 contains a patch for the issue.56dCVE-2026-168637.7 HIG27.4%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.34dCVE-2026-539026.5 MED27.4%
——8MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation.
An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.72dCVE-2025-45326—27.4%
——8——CVE-2023-21596—27.4%
——8——CVE-2024-43005—27.4%
——8——CVE-2022-0646—27.4%
——8——CVE-2022-37824—27.4%
——8——CVE-2024-11133—27.4%
——8——CVE-2026-53816—27.4%
——8——CVE-2024-12026—27.4%
——8——CVE-2024-10786—27.4%
——8——CVE-2026-498467.5 HIG27.4%
——8libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.19hCVE-2022-37823—27.4%
——8——CVE-2024-32512—27.4%
——8——CVE-2024-23979—27.4%
——8——CVE-2026-42229—27.4%
——8——CVE-2020-9260—27.4%
——8——CVE-2024-7230—27.4%
——8——CVE-2025-22377—27.4%
——8——CVE-2020-10635—27.4%
——8——CVE-2024-3711—27.4%
——8——CVE-2024-8667—27.4%
——8——CVE-2026-841146.3 MED27.4%
——8A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the argument Email leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.8.1.11 is recommended to address this issue. Upgrading the affected component is recommended.15dCVE-2023-25651—27.4%
——8——CVE-2026-53761—27.4%
——8Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0.12d