Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-650094.3 MED23.1%
——7OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endpoint to retrieve operational logs from all tenants, exposing asset IDs, agent connection details, rule names, and protocol errors across the multi-tenant deployment.50dCVE-2025-5820—23.1%
——7——CVE-2024-12216—23.1%
——7——CVE-2025-12384—23.1%
——7——CVE-2021-33117—23.1%
——7——CVE-2019-20872—23.1%
——7——CVE-2025-66260—23.1%
——7——CVE-2025-23034—23.1%
——7——CVE-2026-163787.5 HIG23.1%
——7Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.49dCVE-2025-32243—23.1%
——7——CVE-2020-11470—23.1%
——7——CVE-2025-547906.5 MED23.1%
——7Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10.9dCVE-2024-56292—23.1%
——7——CVE-2006-1601—23.1%
——7——CVE-2022-41727—23.1%
——7——CVE-2025-12750—23.1%
——7——CVE-2013-5666—23.1%
——7——CVE-2004-0880—23.1%
——7——CVE-2025-32244—23.1%
——7——CVE-2025-35021—23.1%
——7——CVE-2025-49292—23.1%
——7——CVE-2024-5602—23.1%
——7——CVE-2025-2336—23.1%
——7——CVE-2025-27447—23.1%
——7——CVE-2024-57338—23.1%
——7——CVE-2026-41419—23.1%
——7——CVE-2020-27122—23.1%
——7——CVE-2025-7021—23.1%
——7——CVE-2025-47555—23.1%
——7——CVE-2025-32961—23.1%
——7——CVE-2025-1457—23.1%
——7——CVE-2026-18656.5 MED23.1%
——7The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.49dCVE-2024-56225—23.1%
——7——CVE-2020-2218—23.1%
——7——CVE-2026-40322—23.1%
——7——CVE-2023-5984—23.1%
——7——CVE-2024-56293—23.1%
——7——CVE-2026-163649.1 CRI23.1%
——7Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.49dCVE-2025-67972—23.1%
——7——CVE-2006-1231—23.1%
——7——