Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,453
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1481—26.3%
——8——CVE-2026-1480—26.3%
——8——CVE-2026-146396.3 MED26.3%
——8A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.71dCVE-2024-2798—26.3%
——8——CVE-2025-66487—26.3%
——8——CVE-2026-13525—26.3%
——8——CVE-2007-3124—26.3%
——8——CVE-2026-1474—26.3%
——8——CVE-2026-155366.3 MED26.3%
——8A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.62dCVE-2002-0701—26.3%
——8——CVE-2007-0253—26.3%
——8——CVE-2009-4314—26.3%
——8——CVE-2000-0802—26.3%
——8——CVE-2003-0381—26.3%
——8——CVE-2026-147996.3 MED26.3%
——8A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.71dCVE-2026-797489.9 CRI26.3%
——8MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is required, but there is no authorization check restricting these endpoints to admins, and there is no allowlist/sanitization on the command and args fields. As a result, any authenticated non-admin user can submit a server configuration with command:"/bin/sh" (or any other binary) and arbitrary args, causing MCPHub to execute the attacker-controlled process as the MCPHub server's OS user (commonly root in the published Docker image and in npx/systemd deployments). This issue has been patched in version 0.12.15.7dCVE-2026-146576.3 MED26.3%
——8A flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. This manipulation of the argument squestions[] causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.71dCVE-2026-146386.3 MED26.3%
——8A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.71dCVE-2026-1475—26.3%
——8——CVE-2026-1479—26.3%
——8——CVE-2026-1058—26.3%
——8——CVE-2026-1478—26.3%
——8——CVE-2024-1144—26.3%
——8——CVE-2025-8052—26.3%
——8——CVE-2017-3801—26.3%
——8——CVE-2026-13497—26.3%
——8——CVE-2014-1264—26.3%
——8——CVE-1999-1589—26.3%
——8——CVE-2024-34141—26.3%
——8——CVE-2025-6694—26.3%
——8——CVE-2026-3135—26.3%
——8——CVE-2024-1438—26.3%
——8——CVE-2026-790313.1 LOW26.3%
——8Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)18dCVE-2026-1477—26.3%
——8——CVE-2026-26194.3 MED26.3%
——8GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization.57dCVE-2026-155586.3 MED26.3%
——8A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.64dCVE-2026-54600—26.3%
——8Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire database. This issue has been patched in version 4.9.4.7dCVE-2026-692255.9 MED26.3%
——8There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.4dCVE-2026-904725.3 MED26.3%
——8msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.1dCVE-2026-1472—26.3%
——8——