Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41161—26.3%
——8——CVE-2024-2045—26.3%
——8——CVE-2012-5065—26.3%
——8——CVE-2024-31802—26.3%
——8——CVE-2021-43849—26.3%
——8——CVE-2026-5256—26.3%
——8——CVE-2011-0178—26.3%
——8——CVE-2026-109936.5 MED26.3%
——8Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)55dCVE-2026-53687.3 HIG26.3%
——8A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.53dCVE-2026-665866.6 MED26.3%
——8Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.26dCVE-2026-3068—26.3%
——8——CVE-2026-109788.8 HIG26.3%
——8Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)55dCVE-2026-31851—26.3%
——8——CVE-2025-26773—26.3%
——8——CVE-2026-5257—26.3%
——8——CVE-2024-1692—26.3%
——8——CVE-2026-704088.8 HIG26.3%
——8An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.18dCVE-2024-36775—26.3%
——8——CVE-2024-3889—26.3%
——8——CVE-2025-6353—26.3%
——8——CVE-2026-1476—26.3%
——8——CVE-2026-4784—26.3%
——8——CVE-2004-1224—26.3%
——8——CVE-2026-1482—26.3%
——8——CVE-2011-0008—26.3%
——8——CVE-2026-156726.3 MED26.3%
——8A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.php. This manipulation of the argument fname causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.62dCVE-2019-1950—26.3%
——8——CVE-2024-3491—26.3%
——8——CVE-2024-3559—26.3%
——8——CVE-2020-0507—26.3%
——8——CVE-2018-6556—26.3%
——8——CVE-2026-40474—26.3%
——8——CVE-2026-2865—26.3%
——8——CVE-2026-154776.3 MED26.3%
——8A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1 and 2.0.1 mitigates this issue. Upgrading the affected component is recommended.64dCVE-2021-21088—26.3%
——8——CVE-2026-3069—26.3%
——8——CVE-2020-3971—26.3%
——8——CVE-2026-30967—26.3%
——8——CVE-2024-29171—26.3%
——8——CVE-2026-3406—26.3%
——8——