Vulnerabilities exploitable today
368,208in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,147
- High7,679
- Medium5,506
- Low542
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-15340—19.3%
——6——CVE-2022-49663—19.3%
——6——CVE-2025-27500—19.3%
——6——CVE-2026-708878.2 HIG19.3%
——6Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).14dCVE-2024-22880—19.3%
——6——CVE-2026-5252—19.3%
——6——CVE-2022-42331—19.3%
——6——CVE-2024-7963—19.3%
——6——CVE-2026-822398.1 HIG19.3%
——6Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.6dCVE-2021-29415—19.3%
——6——CVE-2024-27814—19.3%
——6——CVE-2024-4546—19.3%
——6——CVE-2020-36431—19.3%
——6——CVE-2020-9855—19.3%
——6——CVE-2022-49723—19.3%
——6——CVE-2020-33525.5 MED19.3%
——6A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access hidden commands. The vulnerability is due to the presence of undocumented configuration commands. An attacker could exploit this vulnerability by performing specific steps that make the hidden commands accessible. A successful exploit could allow the attacker to make configuration changes to various sections of an affected device that should not be exposed to CLI access.23dCVE-2026-42725—19.3%
——6——CVE-2025-24117—19.3%
——6——CVE-2020-2154—19.3%
——6——CVE-2020-27211—19.3%
——6——CVE-2025-58249—19.3%
——6——CVE-2024-37408—19.3%
——6——CVE-2026-45301—19.3%
——6——CVE-2026-137005.9 MED19.3%
——6The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials to every such request, allowing unauthenticated attackers to perform Server-Side Request Forgery and to disclose the configured integration credentials when the relevant data-sync feature is enabled.9dCVE-2026-29069—19.3%
——6——CVE-2022-32877—19.3%
——6——CVE-2019-25605—19.3%
——6——CVE-2022-39199—19.3%
——6——CVE-2024-21456—19.3%
——6——CVE-2024-45679—19.3%
——6——CVE-2024-2115—19.3%
——6——CVE-2022-49063—19.3%
——6——CVE-2025-27914—19.3%
——6——CVE-2023-49883—19.3%
——6——CVE-2025-58252—19.3%
——6——CVE-2026-64536.5 MED19.3%
——6The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient input sanitization in the cubewp_remove_relation() AJAX function, specifically the use of wp_unslash() on the relation_id parameter before interpolating it directly into a raw SQL query without using $wpdb->prepare(). The wp_unslash() call explicitly removes the backslash escaping that WordPress's wp_magic_quotes() adds to all $_POST data, neutralizing the only layer of SQL injection protection. The sanitize_text_field() function applied afterward offers no SQL protection. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries to the existing query.22dCVE-2025-50866—19.3%
——6——CVE-2024-39643—19.3%
——6——CVE-2021-1071—19.3%
——6——CVE-2025-0865—19.3%
——6——