Vulnerabilities exploitable today
356,780in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,545
- Medium6,712
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-32478—9.1%
——3——CVE-2024-57783—9.1%
——3——CVE-2026-7716—9.1%
——3——CVE-2023-53012—9.1%
——3——CVE-2026-4597—9.1%
——3——CVE-2025-31177—9.1%
——3——CVE-2026-5640—9.1%
——3——CVE-2023-54017—9.1%
——3——CVE-2026-4230—9.1%
——3——CVE-2026-5197—9.1%
——3——CVE-2026-563344.3 MED9.1%
——3Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted, leaving build_requests rows stuck in pending state with null last_error values.40dCVE-2023-53054—9.1%
——3——CVE-2026-42195—9.1%
——3——CVE-2026-93426.3 MED9.1%
——3A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.18dCVE-2026-7114—9.1%
——3——CVE-2025-68587—9.1%
——3——CVE-2026-4954—9.1%
——3——CVE-2025-1979—9.1%
——3——CVE-2026-187666.3 MED9.1%
——3A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.5dCVE-2025-59497—9.1%
——3——CVE-2025-380027.8 HIG9.1%
——3In the Linux kernel, the following vulnerability has been resolved:
io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo()
Not everything requires locking in there, which is why the 'has_lock'
variable exists. But enough does that it's a bit unwieldy to manage.
Wrap the whole thing in a ->uring_lock trylock, and just return
with no output if we fail to grab it. The existing trylock() will
already have greatly diminished utility/output for the failure case.
This fixes an issue with reading the SQE fields, if the ring is being
actively resized at the same time.11dCVE-2023-30571—9.1%
——3——CVE-2026-42592—9.1%
——3——CVE-2025-68364—9.1%
——3——CVE-2023-42540—9.1%
——3——CVE-2026-8097—9.1%
——3——CVE-2025-22791—9.1%
——3——CVE-2026-7143—9.1%
——3——CVE-2026-5196—9.1%
——3——CVE-2026-4593—9.1%
——3——CVE-2026-6335—9.1%
——3——CVE-2026-93056.3 MED9.1%
——3A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.18dCVE-2022-25334—9.1%
——3——CVE-2025-22678—9.1%
——3——CVE-2026-7745—9.1%
——3——CVE-2018-11942—9.1%
——3——CVE-2026-7266—9.1%
——3——CVE-2022-0636—9.1%
——3——CVE-2026-592617.1 HIG9.1%
——3OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.32dCVE-2026-6191—9.1%
——3——