Vulnerabilities exploitable today
356,780in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,545
- Medium6,712
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48701—9.1%
——3——CVE-2026-5282—9.1%
——3——CVE-2025-0567—9.1%
——3——CVE-2023-23632—9.1%
——3——CVE-2025-3677—9.1%
——3——CVE-2022-49912—9.1%
——3——CVE-2026-2420—9.1%
——3——CVE-2022-42464—9.1%
——3——CVE-2025-54999—9.1%
——3——CVE-2025-13705—9.1%
——3——CVE-2017-12306—9.1%
——3——CVE-2026-2233—9.1%
——3——CVE-2021-47873—9.1%
——3——CVE-2026-2553—9.1%
——3——CVE-2025-22562—9.1%
——3——CVE-2022-48689—9.1%
——3——CVE-2026-33862—9.1%
——3——CVE-2024-39020—9.1%
——3——CVE-2022-35868—9.1%
——3——CVE-2026-7391—9.1%
——3——CVE-2026-58236.3 MED9.1%
——3A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.17dCVE-2026-6190—9.1%
——3——CVE-2025-68588—9.1%
——3——CVE-2021-34390—9.1%
——3——CVE-2026-188966.3 MED9.1%
——3A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.5dCVE-2024-10405—9.1%
——3——CVE-2026-7741—9.1%
——3——CVE-2026-7410—9.1%
——3——CVE-2026-7746—9.1%
——3——CVE-2024-48916—9.1%
——3——CVE-2026-4507—9.1%
——3——CVE-2017-15818—9.1%
——3——CVE-2026-7392—9.1%
——3——CVE-2025-14956—9.1%
——3——CVE-2026-56756.3 MED9.1%
——3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.17dCVE-2026-348354.8 MED9.1%
——3Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted in RFC-compliant hostnames, including /, ?, #, and @. Because req.host returns the full parsed value, applications that validate hosts using naive prefix or suffix checks can be bypassed. This can lead to host header poisoning in applications that use req.host, req.url, or req.base_url for link generation, redirects, or origin validation. This issue has been patched in versions 3.1.21 and 3.2.6.16dCVE-2026-4234—9.1%
——3——CVE-2023-54007—9.1%
——3——CVE-2023-54006—9.1%
——3——CVE-2026-3672—9.1%
——3——