Vulnerabilities exploitable today
368,208in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,147
- High7,679
- Medium5,506
- Low542
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-58054—19.3%
——6Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the basis that the permission system allows a limited administrator to grant privileges exceeding their own authorization scope, potentially constituting an insecure default configuration. Following a dispute, the MITRE TL-Root determined the behavior reflects documented and intended product design rather than a security vulnerability.41dCVE-2019-19345—19.3%
——6——CVE-2025-20917—19.3%
——6——CVE-2026-25178—19.3%
——6——CVE-2026-825544.3 MED19.3%
——6A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used.3dCVE-2025-20137—19.3%
——6——CVE-2025-20915—19.3%
——6——CVE-2025-7368—19.3%
——6——CVE-2025-20916—19.3%
——6——CVE-2026-24827—19.3%
——6——CVE-2025-20919—19.3%
——6——CVE-2020-5343—19.3%
——6——CVE-2025-398977.5 HIG19.3%
——6In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Add error handling for RX metadata pointer retrieval
Add proper error checking for dmaengine_desc_get_metadata_ptr() which
can return an error pointer and lead to potential crashes or undefined
behaviour if the pointer retrieval fails.
Properly handle the error by unmapping DMA buffer, freeing the skb and
returning early to prevent further processing with invalid data.36dCVE-2026-33002—19.3%
——6——CVE-2026-827004.3 MED19.3%
——6A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.4dCVE-2025-63441—19.3%
——6——CVE-2025-20914—19.3%
——6——CVE-2025-20918—19.3%
——6——CVE-2025-14080—19.3%
——6——CVE-2022-49335—19.3%
——6——CVE-2026-40543—19.3%
——6SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information.
This issue affects SOPlanning version 1.55 and below.44dCVE-2025-14840—19.3%
——6——CVE-2025-22581—19.3%
——6——CVE-2020-37224—19.3%
——6——CVE-2025-4405—19.3%
——6——CVE-2025-6945—19.3%
——6——CVE-2025-65046—19.3%
——6——CVE-2026-48599—19.3%
——6——CVE-2019-5307—19.3%
——6——CVE-2025-24089—19.3%
——6——CVE-2025-20920—19.3%
——6——CVE-2024-25701—19.3%
——6——CVE-2024-25702—19.3%
——6——CVE-2022-45376—19.3%
——6——CVE-2025-62275—19.3%
——6——CVE-2020-14480—19.3%
——6——CVE-2025-5811—19.3%
——6——CVE-2023-25449—19.3%
——6——CVE-2024-25694—19.3%
——6——CVE-2024-12575—19.3%
——6——