Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54523—35.5%
——11——CVE-2022-23995—35.5%
——11——CVE-2024-11515—35.5%
——11——CVE-2025-52967—35.5%
——11——CVE-2023-1736—35.5%
——11——CVE-2020-11779—35.5%
——11——CVE-2016-3939—35.5%
——11——CVE-2023-50268—35.5%
——11——CVE-2024-8810—35.5%
——11——CVE-2025-27795—35.5%
——11——CVE-2024-39658—35.5%
——11——CVE-2022-39402—35.5%
——11——CVE-2025-28980—35.5%
——11——CVE-2025-31791—35.5%
——11——CVE-2026-52056.3 MED35.5%
——11A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.63dCVE-2024-57433—35.5%
——11——CVE-2019-20671—35.5%
——11——CVE-2017-3752—35.5%
——11——CVE-2019-20674—35.5%
——11——CVE-2017-7373—35.5%
——11——CVE-2024-35151—35.5%
——11——CVE-2020-21685—35.5%
——11——CVE-2022-42884—35.5%
——11——CVE-2025-31757—35.5%
——11——CVE-2023-39484—35.5%
——11——CVE-2001-0983—35.5%
——11——CVE-2019-20660—35.5%
——11——CVE-2019-25340—35.5%
——11——CVE-2004-2477—35.5%
——11——CVE-2024-54503—35.5%
——11——CVE-2025-33202—35.4%
——11——CVE-2015-2577—35.5%
——11——CVE-2026-762088.2 HIG35.5%
——11phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.24dCVE-2023-3111—35.5%
——11——CVE-2025-64898—35.5%
——11——CVE-2005-4412—35.5%
——11——CVE-2024-0895—35.5%
——11——CVE-2026-42735—35.5%
——11——CVE-2025-47204—35.5%
——11——CVE-2024-46488—35.5%
——11——