Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-11453—29.5%
——9——CVE-2018-253518.2 HIG29.5%
——9Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL injection payloads in the username field to extract database information including user credentials and system details.59dCVE-2025-26065—29.5%
——9——CVE-2011-1946—29.5%
——9——CVE-2020-35511—29.5%
——9——CVE-2023-51737—29.5%
——9——CVE-2026-0679—29.5%
——9——CVE-2025-30740—29.5%
——9——CVE-2019-20648—29.5%
——9——CVE-2018-12385—29.5%
——9——CVE-2026-908066.3 MED29.5%
——9A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.3dCVE-2025-13022—29.5%
——9——CVE-2024-9258—29.5%
——9——CVE-2024-9276—29.5%
——9——CVE-2023-51739—29.5%
——9——CVE-2025-47612—29.5%
——9——CVE-2026-36539—29.5%
——9——CVE-2025-58448—29.5%
——9——CVE-2026-46636—29.5%
——9Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.9dCVE-2024-8840—29.5%
——9——CVE-2023-41687—29.5%
——9——CVE-2023-51738—29.5%
——9——CVE-2025-40650—29.5%
——9——CVE-2023-51724—29.5%
——9——CVE-2025-47628—29.5%
——9——CVE-2024-9334—29.5%
——9——CVE-2016-2424—29.5%
——9——CVE-2024-47262—29.5%
——9——CVE-2014-0676—29.5%
——9——CVE-2023-51735—29.5%
——9——CVE-2022-50800—29.5%
——9——CVE-2024-8827—29.5%
——9——CVE-2005-3270—29.5%
——9——CVE-2016-8579—29.4%
——9——CVE-2003-0175—29.4%
——9——CVE-2023-20248—29.5%
——9——CVE-2015-0717—29.5%
——9——CVE-2000-1190—29.5%
——9——CVE-2020-15076—29.5%
——9——CVE-2026-48050—29.5%
——9Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The auth middleware short-circuits before the token check on prefix match, so the endpoints are reachable without any authentication. Version 26.06.1 contains a patch. Some workarounds are available. Block `/debug/pprof*` at a reverse proxy / load balancer in front of Arc, restrict Arc's API port to known-trusted networks via firewall rules, and/or patch the running build: comment out `app.Use(pprof.New())` in `internal/api/server.go` and rebuild.8d