Vulnerabilities exploitable today
369,690in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,132
- High7,667
- Medium5,751
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3800—21.6%
——6——CVE-2017-202798.2 HIG21.6%
——6Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information using boolean-based blind or time-based blind techniques.20dCVE-2021-1853—21.6%
——6——CVE-2024-20128—21.6%
——6——CVE-2026-131225.3 MED21.6%
——6OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled61dCVE-2026-49355—21.6%
——6——CVE-2026-45750—21.6%
——6——CVE-2017-202748.2 HIG21.6%
——6Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and task=learningPath parameters to extract sensitive database information.20dCVE-2021-44235—21.6%
——6——CVE-1999-0976—21.6%
——6——CVE-2026-341849.1 CRI21.6%
——6AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database.
This issue was fixed in AlanWeb SCADA version 9.8.526dCVE-2017-202808.2 HIG21.6%
——6Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid endpoint to extract sensitive database information.20dCVE-2025-43948—21.6%
——6——CVE-2018-20942—21.6%
——6——CVE-2025-638967.6 HIG21.6%
——6An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device.66dCVE-2025-8784—21.6%
——6——CVE-2026-710086.8 MED21.6%
——6Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).15dCVE-2016-6430—21.6%
——6——CVE-2025-66499—21.6%
——6——CVE-2005-0985—21.6%
——6——CVE-2025-8788—21.6%
——6——CVE-1999-0694—21.6%
——6——CVE-2025-2131—21.6%
——6——CVE-2025-54973—21.6%
——6——CVE-2025-22316—21.6%
——6——CVE-2026-67364—21.6%
——6Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.18dCVE-2015-4505—21.6%
——6——CVE-2022-38307—21.6%
——6——CVE-2025-65223—21.6%
——6——CVE-2024-1439—21.6%
——6——CVE-2017-2322—21.6%
——6——CVE-2018-20943—21.6%
——6——CVE-2023-41232—21.6%
——6——CVE-2020-10782—21.6%
——6——CVE-2025-27099—21.6%
——6——CVE-2023-21227—21.6%
——6——CVE-2026-32525—21.6%
——6——CVE-2023-51517—21.6%
——6——CVE-2025-4378—21.6%
——6——CVE-2022-493437.8 HIG21.6%
——6In the Linux kernel, the following vulnerability has been resolved:
ext4: avoid cycles in directory h-tree
A maliciously corrupted filesystem can contain cycles in the h-tree
stored inside a directory. That can easily lead to the kernel corrupting
tree nodes that were already verified under its hands while doing a node
split and consequently accessing unallocated memory. Fix the problem by
verifying traversed block numbers are unique.35d