Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,356
- Medium5,353
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-40179—17.4%
——5——CVE-2026-95747.3 HIG17.4%
——5A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.40dCVE-2026-95757.3 HIG17.4%
——5A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.40dCVE-2026-73643.1 LOW17.4%
——5IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.33dCVE-2026-592274.3 MED17.4%
——5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user image-generation permission, allowing a non-admin user to invoke server-side image editing with administrator-configured provider credentials. This issue is fixed in version 0.10.0.49dCVE-2026-7550—17.4%
——5——CVE-2022-49464—17.4%
——5——CVE-2025-6745—17.4%
——5——CVE-2026-7545—17.4%
——5——CVE-2023-3301—17.4%
——5——CVE-2026-6629—17.4%
——5——CVE-2026-2702—17.3%
——5——CVE-2026-4624—17.4%
——5——CVE-2024-40942—17.3%
——5——CVE-2025-12782—17.3%
——5——CVE-2024-56615—17.3%
——5——CVE-2022-27575—17.3%
——5——CVE-2019-3938—17.3%
——5——CVE-2023-41986—17.3%
——5——CVE-2026-23809—17.3%
——5——CVE-2023-5772—17.3%
——5——CVE-2024-48046—17.3%
——5——CVE-2025-378227.8 HIG17.3%
——5In the Linux kernel, the following vulnerability has been resolved:
riscv: uprobes: Add missing fence.i after building the XOL buffer
The XOL (execute out-of-line) buffer is used to single-step the
replaced instruction(s) for uprobes. The RISC-V port was missing a
proper fence.i (i$ flushing) after constructing the XOL buffer, which
can result in incorrect execution of stale/broken instructions.
This was found running the BPF selftests "test_progs:
uprobe_autoattach, attach_probe" on the Spacemit K1/X60, where the
uprobes tests randomly blew up.33dCVE-2024-26615—17.3%
——5——CVE-2021-1126—17.3%
——5——CVE-2024-13859—17.3%
——5——CVE-2022-1107—17.3%
——5——CVE-2024-3507—17.3%
——5——CVE-2023-6242—17.3%
——5——CVE-2026-5847—17.3%
——5——CVE-2021-42711—17.3%
——5——CVE-2025-15083—17.3%
——5——CVE-2022-42264—17.3%
——5——CVE-2023-29126—17.3%
——5——CVE-2021-25348—17.3%
——5——CVE-2024-23283—17.3%
——5——CVE-2021-27637—17.3%
——5——CVE-2024-49230—17.3%
——5——CVE-2010-1775—17.3%
——5——CVE-2026-5960—17.3%
——5——