Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,356
- Medium5,353
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-43123—17.4%
——5——CVE-2025-21484—17.4%
——5——CVE-2023-3301—17.4%
——5——CVE-2026-7545—17.4%
——5——CVE-2026-6142—17.4%
——5——CVE-2026-55647.3 HIG17.4%
——5A weakness has been identified in code-projects Simple Laundry System 1.0. Affected by this vulnerability is an unknown functionality of the file /searchguest.php of the component Parameter Handler. This manipulation of the argument searchServiceId causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.39dCVE-2024-49938—17.4%
——5——CVE-2024-43164—17.4%
——5——CVE-2023-41471—17.4%
——5——CVE-2025-6745—17.4%
——5——CVE-2026-2702—17.3%
——5——CVE-2024-34152—17.4%
——5——CVE-2026-6629—17.4%
——5——CVE-2024-43218—17.4%
——5——CVE-2022-50724—17.4%
——5——CVE-2024-43210—17.4%
——5——CVE-2016-20032—17.4%
——5——CVE-2026-23526—17.3%
——5——CVE-2026-4910—17.4%
——5——CVE-2026-134774.7 MED17.4%
——5IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.22dCVE-2024-52561—17.4%
——5——CVE-2026-5237—17.4%
——5——CVE-2022-49113—17.4%
——5——CVE-2026-58137.3 HIG17.4%
——5A weakness has been identified in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /check_availability.php. Executing a manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.39dCVE-2026-1965—17.4%
——5——CVE-2021-0705—17.4%
——5——CVE-2024-34548—17.4%
——5——CVE-2021-47277—17.4%
——5——CVE-2024-35982—17.3%
——5——CVE-2022-49693—17.4%
——5——CVE-2024-46685—17.4%
——5——CVE-2025-1953—17.4%
——5——CVE-2024-43938—17.4%
——5——CVE-2026-5322—17.4%
——5——CVE-2026-102154.3 MED17.4%
——5A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 23.0.2 is recommended to address this issue. The identifier of the patch is ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73. Upgrading the affected component is advised.41dCVE-2022-49131—17.4%
——5——CVE-2025-24474—17.4%
——5——CVE-2026-101117.3 HIG17.4%
——5A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.41dCVE-2022-49544—17.4%
——5——CVE-2024-386637.8 HIG17.4%
——5In the Linux kernel, the following vulnerability has been resolved:
blk-cgroup: fix list corruption from resetting io stat
Since commit 3b8cc6298724 ("blk-cgroup: Optimize blkcg_rstat_flush()"),
each iostat instance is added to blkcg percpu list, so blkcg_reset_stats()
can't reset the stat instance by memset(), otherwise the llist may be
corrupted.
Fix the issue by only resetting the counter part.28d