Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,540
- Medium7,074
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68473—34.9%
——10——CVE-2010-0883—34.9%
——10——CVE-2011-3618—34.9%
——10——CVE-2025-27670—34.9%
——10——CVE-2025-27676—34.9%
——10——CVE-2023-48404—34.9%
——10——CVE-2001-0094—34.9%
——10——CVE-2006-3500—34.9%
——10——CVE-2004-1374—34.9%
——10——CVE-2026-614587.5 HIG34.9%
——10PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense, making short or dictionary-derived passphrases practically recoverable within hours or days.71dCVE-2025-2672—34.9%
——10——CVE-2023-2561—34.9%
——10——CVE-2024-5369—34.9%
——10——CVE-2022-2226—34.9%
——10——CVE-2024-8057—34.9%
——10——CVE-2023-5423—34.9%
——10——CVE-2026-518337.5 HIG34.9%
——10Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.63dCVE-2026-53648—34.9%
——10FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as `md5(<original filename>)` under the uploads directory. Because the stored path depends only on the client-supplied filename, two different downloadable products, or product/order files, uploaded with the same original filename will resolve to the same stored file path. A later upload can overwrite an earlier upload, causing customers or administrators downloading the earlier product to receive the later file instead. Version 0.8.1 patches the issue. Some workarounds are available. Restrict the `servicedownloadable.manage` permission to fully trusted administrators only. As an operational mitigation, ensure downloadable product files use unique filenames before upload. This reduces accidental collisions but does not fully address the underlying issue.79dCVE-2017-3620—34.9%
——10——CVE-2011-1477—34.9%
——10——CVE-2024-13373—34.9%
——10——CVE-2025-56426—34.9%
——10——CVE-2024-54264—34.9%
——10——CVE-2021-35033—34.9%
——10——CVE-2026-9154—34.9%
——10——CVE-2026-77132—34.9%
——10It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.16dCVE-2024-11153—34.9%
——10——CVE-2016-7388—34.9%
——10——CVE-2018-14678—34.9%
——10——CVE-2026-57346—34.9%
——10——CVE-2022-24732—34.9%
——10——CVE-2019-2832—34.9%
——10——CVE-2016-9106—34.9%
——10——CVE-2025-49579—34.9%
——10——CVE-2019-3699—34.9%
——10——CVE-2026-633068.6 HIG34.9%
——10stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.70dCVE-2023-2426—34.9%
——10——CVE-2025-23208—34.9%
——10——CVE-2020-15145—34.9%
——10——CVE-2026-600857.5 HIG34.9%
——10PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.71d