Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,699
- High11,576
- Medium7,298
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-102443.5 LOW10.5%
——3A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used.22dCVE-2019-14066—10.5%
——3——CVE-2022-50850—10.5%
——3——CVE-2018-9543—10.5%
——3——CVE-2018-25132—10.5%
——3——CVE-2019-14117—10.5%
——3——CVE-2025-64358—10.5%
——3——CVE-2019-257174.3 MED10.5%
——3Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection. Attackers can retrieve device internals, location information, and wired network configuration details from the exposed log files.22dCVE-2024-50214—10.5%
——3——CVE-2019-10527—10.5%
——3——CVE-2020-29503—10.5%
——3——CVE-2021-29513—10.5%
——3——CVE-2025-27508—10.5%
——3——CVE-2026-58062—10.5%
——3In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).9dCVE-2025-48139—10.5%
——3——CVE-2022-50112—10.4%
——3——CVE-2026-12130—10.5%
——3——CVE-2024-31813—10.5%
——3——CVE-2025-48339—10.5%
——3——CVE-2025-217347.8 HIG10.5%
——3In the Linux kernel, the following vulnerability has been resolved:
misc: fastrpc: Fix copy buffer page size
For non-registered buffer, fastrpc driver copies the buffer and
pass it to the remote subsystem. There is a problem with current
implementation of page size calculation which is not considering
the offset in the calculation. This might lead to passing of
improper and out-of-bounds page size which could result in
memory issue. Calculate page start and page end using the offset
adjusted address instead of absolute address.14dCVE-2026-5372—10.5%
——3——CVE-2025-674067.3 HIG10.5%
——3https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is interpolated directly into an SQL query, allowing attackers to infer or extract data and, in some cases, execute stacked/time-based payloads. ¶¶ Affected Component & Parameter Affected Endpoint URL: http://localhost/advocate/kortex_lite/control/activate_case.php?id=1 HTTP Method: GET Vulnerable File: activate_case.php Parameter: id Vector Location: GET Injection Techniques (as identified by sqlmap) Type: error-based Title: MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE) Payload: id=1 AND EXTRACTVALUE(6268,CONCAT(0x5c,0x71766b6a71,(SELECT (ELT(6268=6268,1))),0x716a7a6b71)) Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: id=1 AND (SELECT 4464 FROM (SELECT(SLEEP(5)))aHqo) Proof of Concept (Burp Repeater)14dCVE-2023-2637—10.5%
——3——CVE-2019-13998—10.5%
——3——CVE-2006-5303—10.5%
——3——CVE-2026-98819.0 CRI10.5%
——3Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)23dCVE-2022-0131—10.5%
——3——CVE-2023-54178—10.5%
——3——CVE-2025-64382—10.5%
——3——CVE-2022-50866—10.5%
——3——CVE-2026-44437—10.5%
——3——CVE-2025-70795—10.5%
——3——CVE-2019-13995—10.5%
——3——CVE-2026-147523.5 LOW10.5%
——3A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. Such manipulation of the argument reference leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.38dCVE-2023-5519—10.5%
——3——CVE-2025-42981—10.5%
——3——CVE-2022-50194—10.5%
——3——CVE-2023-54300—10.5%
——3——CVE-2026-309633.9 LOW10.5%
——3Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.22dCVE-2020-11175—10.5%
——3——