Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-57911—17.9%
——5——CVE-2022-49188—17.9%
——5——CVE-2026-770197.3 HIG17.9%
——5A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.7dCVE-2022-49424—17.9%
——5——CVE-2026-0521—17.9%
——5——CVE-2022-49121—17.9%
——5——CVE-2025-2565—17.9%
——5——CVE-2026-114727.3 HIG17.9%
——5A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.41dCVE-2026-782017.3 HIG17.9%
——5A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.6dCVE-2024-29170—17.9%
——5——CVE-2026-12318—17.9%
——5——CVE-2026-102527.3 HIG17.9%
——5A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.42dCVE-2026-770207.3 HIG17.9%
——5A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.8dCVE-2025-25735—17.9%
——5——CVE-2026-102087.3 HIG17.9%
——5A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.42dCVE-2026-140408.8 HIG17.9%
——5Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)61dCVE-2026-483535.5 MED17.9%
——5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.5dCVE-2022-49226—17.9%
——5——CVE-2022-49537—17.9%
——5——CVE-2024-13874—17.9%
——5——CVE-2022-49157—17.9%
——5——CVE-2022-49207—17.9%
——5——CVE-2022-49239—17.9%
——5——CVE-2020-37115—17.9%
——5——CVE-2025-28879—17.9%
——5——CVE-2025-28870—17.9%
——5——CVE-2022-49583—17.9%
——5——CVE-2022-49721—17.9%
——5——CVE-2022-49271—17.9%
——5——CVE-2023-25611—17.9%
——5——CVE-2024-57912—17.9%
——5——CVE-2024-50433—17.9%
——5——CVE-2026-190217.3 HIG17.9%
——5A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.20dCVE-2026-102267.3 HIG17.9%
——5A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.42dCVE-2022-22516—17.9%
——5——CVE-2022-49310—17.9%
——5——CVE-2022-492945.5 MED17.9%
——5In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check if modulo is 0 before dividing.
[How & Why]
If a value of 0 is read, then this will cause a divide-by-0 panic.20dCVE-2022-49192—17.9%
——5——CVE-2026-193847.3 HIG17.9%
——5A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.20dCVE-2022-49627—17.9%
——5——