Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3497—26.5%
——8——CVE-2018-253988.2 HIG26.5%
——8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the frm_passwd parameter. Attackers can send POST requests to main.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.56dCVE-2026-22731—26.5%
——8——CVE-2003-1065—26.5%
——8——CVE-2018-16160—26.5%
——8——CVE-2018-253958.2 HIG26.5%
——8Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the feature_id parameter of boards_buttons/update_feature.php. The feature_id value is concatenated directly into SQL statements without sanitization, allowing attackers to send a crafted GET request with a UNION-based payload to extract sensitive database information including the current user, database name, and DBMS version.56dCVE-2005-3250—26.5%
——8——CVE-2021-2464—26.5%
——8——CVE-2026-562813.8 LOW26.5%
——8Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template literals. An attacker with platform admin credentials can inject SQL fragments to enumerate dataset schemas, extract analytics data, or cause denial-of-service against the analytics backend.64dCVE-2025-13163—26.5%
——8——CVE-2024-9503—26.5%
——8——CVE-2024-48648—26.5%
——8——CVE-2024-57438—26.5%
——8——CVE-2025-55199—26.5%
——8——CVE-2024-5408—26.5%
——8——CVE-2004-1069—26.5%
——8——CVE-2005-0114—26.5%
——8——CVE-2004-1323—26.5%
——8——CVE-2025-54959—26.5%
——8——CVE-2022-31661—26.5%
——8——CVE-2016-3002—26.5%
——8——CVE-2024-52467—26.5%
——8——CVE-2025-1154—26.5%
——8——CVE-2018-253418.2 HIG26.5%
——8Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and database names.55dCVE-2009-0518—26.5%
——8——CVE-2003-1077—26.5%
——8——CVE-2025-4006—26.5%
——8——CVE-2007-0737—26.5%
——8——CVE-2024-50701—26.5%
——8——CVE-2012-0100—26.5%
——8——CVE-2024-54247—26.5%
——8——CVE-2005-3238—26.5%
——8——CVE-2023-48398—26.5%
——8——CVE-2024-42904—26.5%
——8——CVE-2026-622268.5 HIG26.5%
——8OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust access or configured input paths can perform actions requiring stronger authorization or policy checks.56dCVE-2004-0137—26.5%
——8——CVE-2006-7191—26.5%
——8——CVE-2018-254018.2 HIG26.5%
——8The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the p1 parameter. Attackers can send GET requests to sever_graph.php with crafted SQL payloads to extract sensitive database information including schema names and other data.56dCVE-2026-34587—26.5%
——8——CVE-2026-647257.1 HIG26.5%
——8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.29d