Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32020—29.5%
——9——CVE-2023-51725—29.5%
——9——CVE-2003-0175—29.4%
——9——CVE-2000-1190—29.5%
——9——CVE-2023-51723—29.5%
——9——CVE-2026-48050—29.5%
——9Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The auth middleware short-circuits before the token check on prefix match, so the endpoints are reachable without any authentication. Version 26.06.1 contains a patch. Some workarounds are available. Block `/debug/pprof*` at a reverse proxy / load balancer in front of Arc, restrict Arc's API port to known-trusted networks via firewall rules, and/or patch the running build: comment out `app.Use(pprof.New())` in `internal/api/server.go` and rebuild.8dCVE-2020-15076—29.5%
——9——CVE-2023-28783—29.5%
——9——CVE-2023-23786—29.5%
——9——CVE-2026-890499.9 CRI29.5%
——9A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role credentials of a managed instance and acting with that role's permissions from outside the instance, via a crafted destination host value that uses an alternate representation of a denied link-local address.
To remediate this issue, users should upgrade to version 3.3.4851.0 or later.7dCVE-2024-11751—29.5%
——9——CVE-2023-51726—29.5%
——9——CVE-2023-51736—29.5%
——9——CVE-2009-4664—29.5%
——9——CVE-2015-0717—29.5%
——9——CVE-2023-20248—29.5%
——9——CVE-2025-15329—29.5%
——9——CVE-2019-5291—29.5%
——9——CVE-2026-190644.3 MED29.5%
——9A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.36dCVE-2024-8825—29.5%
——9——CVE-2026-790494.3 MED29.5%
——9Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)18dCVE-2025-10861—29.5%
——9——CVE-2026-43055—29.5%
——9——CVE-2023-51734—29.5%
——9——CVE-2025-47463—29.5%
——9——CVE-2023-27617—29.5%
——9——CVE-2018-253488.2 HIG29.5%
——9Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive database information.57dCVE-2024-8840—29.5%
——9——CVE-2026-36539—29.5%
——9——CVE-2026-46636—29.5%
——9Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.9dCVE-2025-47612—29.5%
——9——CVE-2025-58448—29.5%
——9——CVE-2016-8579—29.4%
——9——CVE-2005-3270—29.5%
——9——CVE-2023-51739—29.5%
——9——CVE-2020-4071—29.5%
——9——CVE-2024-8827—29.5%
——9——CVE-2018-6689—29.5%
——9——CVE-2022-50800—29.5%
——9——CVE-2022-4862—29.5%
——9——