Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-0084—23.7%
——7——CVE-2021-0635—23.7%
——7——CVE-2024-7042—23.7%
——7——CVE-2026-46935—23.7%
——7——CVE-2025-2911—23.7%
——7——CVE-2025-3728—23.7%
——7——CVE-2024-25572—23.7%
——7——CVE-2024-13618—23.7%
——7——CVE-2019-256698.2 HIG23.7%
——7qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.49dCVE-2025-54497—23.7%
——7——CVE-2013-5892—23.7%
——7——CVE-2019-256988.2 HIG23.7%
——7Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive database information.49dCVE-2026-707067.5 HIG23.7%
——7Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales. Successful attacks of this vulnerability can result in takeover of Oracle Sales. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).11dCVE-2021-33442—23.7%
——7——CVE-2021-33437—23.7%
——7——CVE-2025-3014—23.7%
——7——CVE-2026-612128.5 HIG23.7%
——7Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).18dCVE-2017-16882—23.7%
——7——CVE-2023-24785—23.7%
——7——CVE-2023-24920—23.7%
——7——CVE-2024-39118—23.7%
——7——CVE-2026-707188.5 HIG23.7%
——7Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).11dCVE-2025-3644—23.7%
——7——CVE-2026-711607.5 HIG23.7%
——7Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18 and 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).15dCVE-2026-778926.8 MED23.7%
——7No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.3dCVE-2026-709377.5 HIG23.7%
——7Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).18dCVE-2026-33119—23.7%
——7——CVE-2024-26469—23.7%
——7——CVE-2019-17201—23.7%
——7——CVE-2026-42348—23.7%
——7——CVE-2025-30966—23.7%
——7——CVE-2026-1567—23.7%
——7——CVE-2026-24661—23.7%
——7——CVE-2005-1111—23.7%
——7——CVE-2023-45316—23.7%
——7——CVE-2025-58442—23.7%
——7——CVE-2020-10781—23.7%
——7——CVE-2026-30926—23.7%
——7——CVE-2016-9038—23.7%
——7——CVE-2026-46401—23.7%
——7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerability where authentication tokens remain valid after user logout. This allows attackers who obtain valid tokens to maintain persistent access to authenticated CMS functionality, bypassing the intended session termination mechanism and enabling unauthorized access to CMS metadata and administrative functions. Version 26.0.0 fixes the issue.51d