Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,305
- High9,474
- Medium5,346
- Low516
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-4429—16.1%
——5——CVE-2025-28010—16.1%
——5——CVE-2025-21064—16.1%
——5——CVE-2024-21066—16.1%
——5——CVE-2026-781856.3 MED16.1%
——5A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.2dCVE-2025-52050—16.1%
——5——CVE-2025-43712—16.1%
——5——CVE-2026-40736—16.1%
——5——CVE-2025-564017.6 HIG16.1%
——5ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.56dCVE-2026-274635.3 MED16.1%
——5Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete iTop version. This issue has been fixed in version 3.2.3.8dCVE-2026-8125—16.1%
——5——CVE-2026-31919—16.1%
——5——CVE-2023-52708—16.1%
——5——CVE-2020-10932—16.1%
——5——CVE-2025-24700—16.1%
——5——CVE-2026-389306.5 MED16.1%
——5OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the name cookie parameter.55dCVE-2024-39522—16.1%
——5——CVE-2026-40756—16.1%
——5——CVE-2026-40757—16.1%
——5——CVE-2025-9329—16.1%
——5——CVE-2024-38496—16.1%
——5——CVE-2026-32176—16.1%
——5——CVE-2026-40754—16.1%
——5——CVE-2024-39523—16.1%
——5——CVE-2026-102426.3 MED16.1%
——5A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.38dCVE-2026-340037.8 HIG16.1%
——5A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, leading to a Denial of Service (DoS). In certain configurations, higher impact outcomes may be possible.46dCVE-2026-40760—16.1%
——5——CVE-2026-2803—16.1%
——5——CVE-2024-39524—16.1%
——5——CVE-2026-659817.1 HIG16.1%
——5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.24dCVE-2024-5815—16.1%
——5——CVE-2026-27701—16.1%
——5——CVE-2022-49651—16.1%
——5——CVE-2021-47360—16.1%
——5——CVE-2026-480785.3 MED16.1%
——5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false` are intended to be invisible to public callers; the dashboard creates them deliberately to hide internal-only services from the patient booking UI. The schedule endpoint ignores the flag entirely and discloses channel names, descriptions, IDs, agent associations, pause status, confirmation requirements, and computed slot availability for the requested date range. The asymmetry between `addAppointmentToTunnel` (which enforces `eq(channel.isPublic, true)`) and the schedule endpoint (which does not) confirms the design intent: private channels exist as a real access boundary in the booking flow, just not in the schedule disclosure. Version 1.0.5 patches the issue.22dCVE-2025-9328—16.1%
——5——CVE-2026-190686.3 MED16.1%
——5A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdetail.php. Executing a manipulation of the argument patientid can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.17dCVE-2025-4667—16.1%
——5——CVE-2022-21493—16.1%
——5——CVE-2023-48677—16.1%
——5——