Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-256928.2 HIG23.7%
——7Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive database information or modify data.49dCVE-2026-46870—23.7%
——7——CVE-2026-625908.5 HIG23.7%
——7Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. While the vulnerability is in Siebel CRM Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).22dCVE-2026-44327—23.7%
——7——CVE-2021-0636—23.7%
——7——CVE-2026-25052—23.7%
——7——CVE-2021-1090—23.7%
——7——CVE-2017-7761—23.7%
——7——CVE-2026-118896.5 MED23.7%
——7SALTO ProAccess Space software using the tenancy feature / logical
partition is vulnerable to a privilege escalation attack that could
allow an authorized attacker to access any space managed by the affected
product.56dCVE-2025-52873—23.7%
——7——CVE-2018-6319—23.7%
——7——CVE-2023-33333—23.7%
——7——CVE-2025-4218—23.7%
——7——CVE-2025-62224—23.7%
——7——CVE-2026-626957.8 HIG23.7%
——7Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.29dCVE-2023-38683—23.7%
——7——CVE-2026-90898.8 HIG23.7%
——7The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.50dCVE-2025-713976.5 MED23.7%
——7SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops. Although a single loop's iteration count is constrained, nesting multiple loops (e.g., each with 1,000,000 iterations) is not, so an attacker can execute a function that consumes all server CPU time. Configured timeouts do not stop the execution, rendering the server unresponsive to other queries and connections until it is manually restarted.29dCVE-2026-591277.8 HIG23.7%
——7Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.25dCVE-2026-503104.7 MED23.7%
——7Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.51dCVE-2026-5848—23.7%
——7——CVE-2023-3352—23.7%
——7——CVE-2024-37552—23.7%
——7——CVE-2025-713966.5 MED23.7%
——7SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). An authenticated attacker can submit long-running JavaScript functions to exhaust server resources and cause a denial of service. Scripting is disabled by default.29dCVE-2024-10105—23.7%
——7——CVE-2025-62478—23.7%
——7——CVE-2026-839857.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-627107.8 HIG23.7%
——7Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.26dCVE-2018-18653—23.7%
——7——CVE-2025-1490—23.7%
——7——CVE-2024-456183.9 LOW23.7%
——7A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs.
Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.74dCVE-2024-37275—23.7%
——7——CVE-2026-1322—23.7%
——7——CVE-2025-67278—23.7%
——7——CVE-2024-10395—23.7%
——7——CVE-2025-29189—23.7%
——7——CVE-2025-14332—23.7%
——7——CVE-2020-35803—23.7%
——7——CVE-2026-40885—23.7%
——7——CVE-2026-21914—23.7%
——7——