Vulnerabilities exploitable today
356,780in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,532
- High10,545
- Medium6,712
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45493—9.1%
——3——CVE-2023-54010—9.1%
——3——CVE-2026-40891—9.1%
——3——CVE-2026-2963—9.1%
——3——CVE-2025-22789—9.1%
——3——CVE-2025-44952—9.1%
——3——CVE-2026-52066.3 MED9.1%
——3A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.16dCVE-2026-4241—9.1%
——3——CVE-2026-7115—9.1%
——3——CVE-2026-115096.3 MED9.1%
——3A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote.18dCVE-2025-24884—9.1%
——3——CVE-2024-32911—9.1%
——3——CVE-2020-4604—9.1%
——3——CVE-2026-187196.3 MED9.1%
——3A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of the argument Search results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.5dCVE-2022-27592—9.1%
——3——CVE-2025-59025—9.1%
——3——CVE-2026-96076.3 MED9.1%
——3A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.17dCVE-2023-27734—9.1%
——3——CVE-2026-142076.1 MED9.1%
——3The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, allowing users with a course-editing role to inject JavaScript that executes in the session of an administrator who views the course.11dCVE-2025-0796—9.1%
——3——CVE-2025-22792—9.1%
——3——CVE-2018-11840—9.1%
——3——CVE-2026-102026.3 MED9.1%
——3A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.19dCVE-2026-102046.3 MED9.1%
——3A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.19dCVE-2018-11827—9.1%
——3——CVE-2025-22790—9.1%
——3——CVE-2023-46115—9.1%
——3——CVE-2026-4614—9.1%
——3——CVE-2025-68577—9.1%
——3——CVE-2025-29088—9.1%
——3——CVE-2025-22687—9.1%
——3——CVE-2026-7118—9.1%
——3——CVE-2026-7744—9.1%
——3——CVE-2019-14116—9.1%
——3——CVE-2018-11832—9.1%
——3——CVE-2023-31008—9.1%
——3——CVE-2026-1230—9.1%
——3——CVE-2018-11261—9.1%
——3——CVE-2024-7881—9.1%
——3——CVE-2026-2294—9.1%
——3——