Vulnerabilities exploitable today
360,723in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,504
- High11,047
- Medium7,089
- Low639
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-624948.1 HIG11.7%
——4Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).19dCVE-2023-42853—11.7%
——4——CVE-2026-187226.3 MED11.7%
——4A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.4dCVE-2023-32635—11.7%
——4——CVE-2026-192918.8 HIG11.7%
——4Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.3dCVE-2023-32639—11.7%
——4——CVE-2026-281826.5 MED11.7%
——4Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.2dCVE-2024-42237—11.7%
——4——CVE-2024-40830—11.7%
——4——CVE-2023-42538—11.7%
——4——CVE-2022-23922—11.7%
——4——CVE-2026-664716.5 MED11.7%
——4Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.2dCVE-2026-349475.3 MED11.7%
——4Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, staged user custom fields and username are exposed on public invite pages without email verification. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.23dCVE-2026-72750—11.7%
——4n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.2dCVE-2025-21681—11.7%
——4——CVE-2023-26264—11.7%
——4——CVE-2026-169495.8 MED11.7%
——4The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.5dCVE-2025-54533—11.7%
——4——CVE-2025-50005—11.7%
——4——CVE-2024-39473—11.7%
——4——CVE-2024-42248—11.7%
——4——CVE-2023-43297—11.7%
——4——CVE-2026-40546—11.7%
——4SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database.
This issue affects SOPlanning version 1.55 and below.25dCVE-2026-21862—11.7%
——4——CVE-2026-624978.1 HIG11.7%
——4Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).19dCVE-2025-24698—11.7%
——4——CVE-2024-35946—11.7%
——4——CVE-2026-188186.3 MED11.7%
——4A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.4dCVE-2025-3793—11.7%
——4——CVE-2025-6175—11.7%
——4——CVE-2024-43899—11.7%
——4——CVE-2025-31253—11.7%
——4——CVE-2020-2032—11.7%
——4——CVE-2026-468237.7 HIG11.7%
——4Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials (International) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).26dCVE-2026-53408—11.7%
——4——CVE-2026-664566.5 MED11.7%
——4Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.2dCVE-2026-48897—11.7%
——4——CVE-2025-54532—11.7%
——4——CVE-2026-480525.4 MED11.7%
——4Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags belonging to a different organization, given the target tag's ID. The route handler verifies the caller's membership of the ":organizationId" in the URL, but the repository write filters on tag.id alone, so the URL-level org scope never reaches the database. This issue has been patched in version 26.5.0.17dCVE-2023-28457—11.7%
——4——