Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44729—17.2%
——5——CVE-2025-62800—17.2%
——5——CVE-2025-50926—17.2%
——5——CVE-2026-2451—17.2%
——5——CVE-2023-46051—17.2%
——5——CVE-2025-7390—17.2%
——5——CVE-2026-45622—17.2%
——5——CVE-2026-32155—17.2%
——5——CVE-2025-62412—17.2%
——5——CVE-2026-40282—17.2%
——5——CVE-2024-44194—17.2%
——5——CVE-2024-26715—17.2%
——5——CVE-2025-9225—17.2%
——5——CVE-2026-54040—17.2%
——5——CVE-2025-48811—17.2%
——5——CVE-2024-2288—17.2%
——5——CVE-2026-94464.7 MED17.2%
——5A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.39dCVE-2025-66470—17.2%
——5——CVE-2026-9806—17.2%
——5——CVE-2026-77989—17.2%
——5Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.3dCVE-2024-48233—17.2%
——5——CVE-2026-343722.7 LOW17.2%
——5Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.38dCVE-2026-40931—17.2%
——5——CVE-2022-42261—17.2%
——5——CVE-2021-26324—17.2%
——5——CVE-2024-56258—17.2%
——5——CVE-2023-49076—17.2%
——5——CVE-2024-49819—17.2%
——5——CVE-2025-21763—17.2%
——5——CVE-2024-42749—17.2%
——5——CVE-2026-493866.5 MED17.2%
——5In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas40dCVE-2024-20312—17.2%
——5——CVE-2026-763948.3 HIG17.2%
——5In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization checks. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.5dCVE-2024-35145—17.2%
——5——CVE-2025-11004—17.2%
——5——CVE-2024-56263—17.2%
——5——CVE-2025-14183—17.2%
——5——CVE-2025-24525—17.2%
——5——CVE-2026-164447.5 HIG17.2%
——5Improper
neutralization of path traversal sequences in TeamViewer Desktop Clients prior
Version 15.81.5 allows an authenticated remote session participant to write files
to unintended locations on the local file system via file transfer or virtual
file clipboard mechanisms. An attacker can leverage this behavior to achieve
arbitrary file write and potentially execute code with the privileges of the
affected user.4dCVE-2024-56241—17.2%
——5——