Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,291
- High9,346
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-792744.3 MED16.7%
——5Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-194544.4 MED16.7%
——5The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared webroot.1dCVE-2026-538276.5 MED16.7%
——5OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can intercept Gateway tokens and action payloads by providing malicious loopback targets through model-controlled action metadata.38dCVE-2026-7076—16.7%
——5——CVE-2025-58765—16.7%
——5——CVE-2025-31532—16.7%
——5——CVE-2023-6137—16.7%
——5——CVE-2026-7075—16.7%
——5——CVE-2025-31562—16.7%
——5——CVE-2024-35504—16.7%
——5——CVE-2025-48253—16.7%
——5——CVE-2026-189587.3 HIG16.7%
——5A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2026-6151—16.7%
——5——CVE-2026-189707.3 HIG16.7%
——5A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2026-4625—16.7%
——5——CVE-2026-169678.5 HIG16.7%
——5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.13dCVE-2024-56680—16.7%
——5——CVE-2023-48330—16.7%
——5——CVE-2026-767837.3 HIG16.7%
——5A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.9dCVE-2025-31592—16.7%
——5——CVE-2025-31557—16.7%
——5——CVE-2022-45873—16.7%
——5——CVE-2026-7072—16.7%
——5——CVE-2026-4237—16.7%
——5——CVE-2025-48256—16.7%
——5——CVE-2025-65014—16.7%
——5——CVE-2025-30342—16.7%
——5——CVE-2026-4175—16.7%
——5——CVE-2024-23385—16.7%
——5——CVE-2026-4632—16.7%
——5——CVE-2026-58057.3 HIG16.7%
——5A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.37dCVE-2025-31543—16.7%
——5——CVE-2026-762088.2 HIG16.7%
——5phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.11dCVE-2026-95847.3 HIG16.7%
——5A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.37dCVE-2026-33313—16.7%
——5——CVE-2025-22065—16.7%
——5——CVE-2025-31549—16.7%
——5——CVE-2026-7077—16.7%
——5——CVE-2026-93567.3 HIG16.7%
——5A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.38dCVE-2019-16207—16.7%
——5——