Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-48978—17.5%
——5oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.40dCVE-2025-49189—17.5%
——5——CVE-2000-0092—17.5%
——5——CVE-2025-699389.8 CRI17.5%
——5CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.32dCVE-2026-657956.7 MED17.5%
——5Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.11dCVE-2025-699319.8 CRI17.5%
——5CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.29dCVE-2025-699309.8 CRI17.5%
——5CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.32dCVE-2025-699419.8 CRI17.5%
——5SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.32dCVE-2022-49650—17.5%
——5——CVE-2022-49703—17.5%
——5——CVE-2026-37431—17.5%
——5——CVE-2024-20281—17.5%
——5——CVE-2022-49620—17.5%
——5——CVE-2022-26442—17.5%
——5——CVE-2024-49337—17.5%
——5——CVE-2025-13042—17.5%
——5——CVE-2026-35614—17.5%
——5——CVE-2025-11844—17.5%
——5——CVE-2026-759205.3 MED17.5%
——5phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.18hCVE-2023-49296—17.5%
——5——CVE-2021-3155—17.5%
——5——CVE-2022-49678—17.5%
——5——CVE-2024-30974—17.5%
——5——CVE-2026-42071—17.5%
——5——CVE-2025-5450—17.5%
——5——CVE-2020-9117—17.5%
——5——CVE-2022-26441—17.5%
——5——CVE-2022-49199—17.5%
——5——CVE-2022-26439—17.5%
——5——CVE-2026-12804—17.5%
——5——CVE-2026-657986.7 MED17.5%
——5Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.15dCVE-2021-36133—17.5%
——5——CVE-2024-11805—17.5%
——5——CVE-2026-790718.3 HIG17.5%
——5Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)5dCVE-2024-33536—17.5%
——5——CVE-2022-49656—17.5%
——5——CVE-2026-37339—17.5%
——5——CVE-2022-49729—17.5%
——5——CVE-2024-43949—17.5%
——5——CVE-2022-49649—17.5%
——5——