Vulnerabilities exploitable today
379,234in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,390
- High8,612
- Medium7,064
- Low795
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-14738—34.7%
——10——CVE-2010-3298—34.7%
——10——CVE-2025-51472—34.7%
——10——CVE-2025-411189.1 CRI34.7%
——10Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).
If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API.
To exploit this vulnerability, an attacker needs direct access to the Pyroscope API. We highly recommend limiting the public internet exposure of all our databases, such that they are only accessible by trusted users or internal systems.
This vulnerability is fixed in versions:
1.15.x: 1.15.2 and above.
1.16.x: 1.16.1 and above.
1.17.x: 1.17.0 and above (i.e. all versions).
Thanks to Théo Cusnir for reporting this vulnerability to us via our bug bounty program.31dCVE-2025-2393—34.7%
——10——CVE-2024-4911—34.7%
——10——CVE-2025-52187—34.7%
——10——CVE-2026-480823.7 LOW34.7%
——10OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work. Modern hardware solves this in under 200 milliseconds, providing essentially no friction against automated abuse of the patient booking flow. Proof-of-work is used in the booking flow as a rate-limiter for unauthenticated clients establishing tunnels and submitting appointments. At 16 bits of difficulty, the construct is decorative rather than effective. An attacker can solve PoW challenges as fast as the server can issue them, defeating the rate-limiting purpose. The handler also calls `challengeThrottleService.checkThrottle(binding, "passkey")`, but the binding includes attacker-controlled values (`tunnelId`, `clientPublicKey`, and optional `emailHash`). For each fresh attempt, the attacker can supply new values, producing a new throttle key and bypassing the per-binding accumulation. Practical abuse friction is therefore the PoW difficulty itself, not a stable per-IP or per-email server-side throttle. Version 1.0.6 fixes the issue.15dCVE-2026-15806—34.7%
——10The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.
Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.
Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.22dCVE-2024-5231—34.7%
——10——CVE-2026-585475.5 MED34.7%
——10Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.64dCVE-2026-372348.2 HIG34.7%
——10FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned up; subsequent xapp_ids and their subscriptions remain as stale entries. A remote attacker can exploit this to leak subscription state in the iApp, potentially causing resource exhaustion or state corruption over time.64dCVE-2023-45202—34.7%
——10——CVE-2025-6008—34.7%
——10——CVE-2026-12327—34.7%
——10——CVE-2010-3861—34.7%
——10——CVE-2024-5528—34.7%
——10——CVE-2025-55848—34.7%
——10——CVE-2023-3230—34.7%
——10——CVE-2024-42055—34.7%
——10——CVE-2025-46627—34.7%
——10——CVE-2020-8585—34.7%
——10——CVE-2014-9730—34.7%
——10——CVE-2024-5237—34.7%
——10——CVE-2025-6005—34.7%
——10——CVE-2016-6674—34.7%
——10——CVE-2023-37511—34.7%
——10——CVE-2023-37829—34.7%
——10——CVE-2025-7616—34.7%
——10——CVE-2021-25145—34.7%
——10——CVE-2023-47097—34.7%
——10——CVE-2024-9342—34.7%
——10——CVE-2023-23562—34.7%
——10——CVE-2026-26056—34.7%
——10——CVE-2024-5107—34.7%
——10——CVE-2025-30076—34.7%
——10——CVE-2025-14947—34.7%
——10——CVE-2024-5240—34.7%
——10——CVE-2005-1970—34.7%
——10——CVE-2022-41913—34.7%
——10——