Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,645
- Medium5,598
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-199884.3 MED18.7%
——6A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the component Popup UI. Performing a manipulation results in basic cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.13dCVE-2026-174206.3 MED18.7%
——6IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements in an SQL parameter.20dCVE-2024-11416—18.7%
——6——CVE-2025-56215—18.7%
——6——CVE-2024-41697—18.7%
——6——CVE-2026-3124—18.7%
——6——CVE-2026-3610—18.7%
——6——CVE-2025-29628—18.7%
——6——CVE-2022-47446—18.7%
——6——CVE-2026-101857.3 HIG18.7%
——6A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.42dCVE-2024-45136—18.7%
——6——CVE-2026-138308.8 HIG18.7%
——6Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)62dCVE-2026-25811—18.7%
——6——CVE-2023-47354—18.7%
——6——CVE-2024-45137—18.7%
——6——CVE-2026-4877—18.7%
——6——CVE-2025-66469—18.7%
——6——CVE-2024-53309—18.7%
——6——CVE-2017-8265—18.7%
——6——CVE-2026-1947—18.7%
——6——CVE-2026-8117—18.7%
——6——CVE-2024-38703—18.7%
——6——CVE-2023-1660—18.7%
——6——CVE-2024-7594—18.7%
——6——CVE-2021-38206—18.7%
——6——CVE-2023-51305—18.7%
——6——CVE-2026-501036.5 MED18.7%
——6A NULL pointer dereference in the L2 GOOSE and R-GOOSE shared parser, which may allow a network-adjacent attacker to crash a subscribing application by sending a crafted GOOSE frame containing a malformed TLV value.34dCVE-2010-2397—18.7%
——6——CVE-2024-20741—18.7%
——6——CVE-2026-635878.6 HIG18.7%
——6The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliberately trigger this by submitting 5 or more invalid passwords, after which subsequent SMS commands are executed without requiring a password, resulting in potential limited configuration tampering, limited information leakage and potentially full loss of availability.6dCVE-2022-20492—18.7%
——6——CVE-2025-49404—18.7%
——6——CVE-2026-101867.3 HIG18.7%
——6A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.42dCVE-2024-41693—18.7%
——6——CVE-2025-50034—18.7%
——6——CVE-2026-22018—18.7%
——6——CVE-2010-1149—18.7%
——6——CVE-2026-3982—18.7%
——6——CVE-2025-1456—18.7%
——6——CVE-2025-59797—18.7%
——6——