Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,415
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34195—25.8%
——8——CVE-2026-760507.3 HIG25.8%
——8A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.26dCVE-2025-40985—25.8%
——8——CVE-2026-33666—25.8%
——8——CVE-2026-760497.3 HIG25.8%
——8A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.25dCVE-2024-21031—25.8%
——8——CVE-2024-11338—25.8%
——8——CVE-2025-48081—25.8%
——8——CVE-2023-31920—25.8%
——8——CVE-1999-0464—25.8%
——8——CVE-2011-3541—25.8%
——8——CVE-2023-30309—25.8%
——8——CVE-2024-30423—25.8%
——8——CVE-2026-767647.3 HIG25.8%
——8A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.25dCVE-2021-26313—25.8%
——8——CVE-2024-35206—25.8%
——8——CVE-2026-4062—25.8%
——8——CVE-2025-0677—25.8%
——8——CVE-2001-1225—25.8%
——8——CVE-1999-1118—25.8%
——8——CVE-2025-55075—25.8%
——8——CVE-2023-47838—25.8%
——8——CVE-2024-56410—25.8%
——8——CVE-2026-612058.2 HIG25.8%
——8Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).40dCVE-2026-759867.3 HIG25.8%
——8A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.22dCVE-2024-12752—25.8%
——8——CVE-2020-4338—25.8%
——8——CVE-2026-760487.3 HIG25.8%
——8A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.25dCVE-2024-12538—25.8%
——8——CVE-2024-21018—25.8%
——8——CVE-2024-32147—25.8%
——8——CVE-2024-41829—25.8%
——8——CVE-2021-25987—25.8%
——8——CVE-2024-29926—25.8%
——8——CVE-2007-0773—25.8%
——8——CVE-2026-40948—25.8%
——8——CVE-2023-51399—25.8%
——8——CVE-2024-10970—25.8%
——8——CVE-2024-21039—25.8%
——8——CVE-2022-4850—25.8%
——8——