Vulnerabilities exploitable today
368,208in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,147
- High7,679
- Medium5,506
- Low542
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32641—19.3%
——6——CVE-2025-0062—19.3%
——6——CVE-2024-2295—19.3%
——6——CVE-2026-580386.1 MED19.3%
——6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline.
This vulnerability is associated with program files includes/Timeline.Php, scripts/EasyTimeline.Pl.
This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.56dCVE-2022-49726—19.3%
——6——CVE-2022-1247—19.3%
——6——CVE-2026-399146.5 MED19.3%
——6TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.8dCVE-2024-45679—19.3%
——6——CVE-2019-25605—19.3%
——6——CVE-2022-32877—19.3%
——6——CVE-2022-39199—19.3%
——6——CVE-2026-78919.1 CRI19.3%
——6A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications.52dCVE-2024-21456—19.3%
——6——CVE-2025-24489—19.3%
——6——CVE-2006-4233—19.3%
——6——CVE-2025-27420—19.3%
——6——CVE-2024-27814—19.3%
——6——CVE-2020-35499—19.3%
——6——CVE-2026-58054—19.3%
——6Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the basis that the permission system allows a limited administrator to grant privileges exceeding their own authorization scope, potentially constituting an insecure default configuration. Following a dispute, the MITRE TL-Root determined the behavior reflects documented and intended product design rather than a security vulnerability.41dCVE-2023-5138—19.3%
——6——CVE-2026-11857—19.3%
——6——CVE-2026-4168—19.3%
——6——CVE-2025-14080—19.3%
——6——CVE-2020-8316—19.3%
——6——CVE-2022-45076—19.3%
——6——CVE-2023-24414—19.3%
——6——CVE-2026-708256.5 MED19.3%
——6Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).10dCVE-2024-7819—19.3%
——6——CVE-2024-25042—19.3%
——6——CVE-2018-254317.1 HIG19.3%
——6No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint that allows authenticated attackers to manipulate database queries. Attackers can submit POST requests to /nocms/main/manage_privilege/index/export with malicious SQL code in the order_by[0] parameter to extract sensitive database information.44dCVE-2026-103014.3 MED19.3%
——6A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.43dCVE-2019-19345—19.3%
——6——CVE-2020-16007—19.3%
——6——CVE-2023-2270—19.3%
——6——CVE-2023-20233—19.3%
——6——CVE-2022-49697—19.3%
——6——CVE-2025-22574—19.3%
——6——CVE-2026-1407—19.3%
——6——CVE-2025-12043—19.3%
——6——CVE-2026-7095—19.3%
——6——