Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,291
- High9,346
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-7225—16.7%
——5——CVE-2026-8129—16.7%
——5——CVE-2020-36932—16.7%
——5——CVE-2024-35763—16.7%
——5——CVE-2019-25382—16.7%
——5——CVE-2021-1371—16.7%
——5——CVE-2023-6960—16.7%
——5——CVE-2026-4289—16.7%
——5——CVE-2026-71947.3 HIG16.7%
——5A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.37dCVE-2025-25927—16.7%
——5——CVE-2026-37536—16.7%
——5——CVE-2018-12205—16.7%
——5——CVE-2026-712046.2 MED16.7%
——5changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.1dCVE-2025-31595—16.7%
——5——CVE-2024-38403—16.7%
——5——CVE-2025-48252—16.7%
——5——CVE-2026-0739—16.7%
——5——CVE-2026-93837.3 HIG16.7%
——5A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.38dCVE-2026-4955—16.7%
——5——CVE-2025-23480—16.7%
——5——CVE-2026-775064.8 MED16.7%
——5Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.4dCVE-2024-44915—16.7%
——5——CVE-2026-27191—16.7%
——5——CVE-2026-96067.3 HIG16.7%
——5A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.37dCVE-2026-7087—16.7%
——5——CVE-2024-52584—16.7%
——5——CVE-2026-58297.3 HIG16.7%
——5A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.37dCVE-2026-470103.7 LOW16.7%
——5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).30dCVE-2025-31598—16.7%
——5——CVE-2026-27346—16.7%
——5——CVE-2024-22809—16.7%
——5——CVE-2026-191102.4 LOW16.7%
——5A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRenderer.java of the component Chart Name Handler. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2025-31589—16.7%
——5——CVE-2026-7074—16.7%
——5——CVE-2025-12621—16.7%
——5——CVE-2024-57360—16.7%
——5——CVE-2025-64339—16.7%
——5——CVE-2025-31559—16.7%
——5——CVE-2024-38405—16.7%
——5——CVE-2024-44914—16.7%
——5——