Vulnerabilities exploitable today
353,240in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,348
- High8,119
- Medium7,274
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-341764.3 MED96.1%
——29In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file existence check operation. While the contents of the file cannot be read, the server reveals whether the file exists, which enables an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.13dCVE-2007-0444—96.1%
——29——CVE-2009-1902—96.1%
——29——CVE-2015-2380—96.1%
——29——CVE-2016-3330—96.1%
——29——CVE-2015-8668—96.1%
——29——CVE-2016-1908—96.1%
——29——CVE-2018-5015—96.1%
——29——CVE-2023-50071—96.1%
——29——CVE-2018-5041—96.1%
——29——CVE-2022-36969—96.1%
——29——CVE-2023-33831—96.1%
——29——CVE-2022-23409—96.1%
——29——CVE-2017-16353—96.1%
——29——CVE-2018-4913—96.1%
——29——CVE-2025-6978—96.1%
——29——CVE-2018-8179—96.1%
——29——CVE-2019-0828—96.1%
——29——CVE-2023-31475—96.1%
——29——CVE-2019-0945—96.1%
——29——CVE-2019-0946—96.1%
——29——CVE-2025-62725—96.1%
——29——CVE-2018-2636—96.1%
——29——CVE-2015-1743—96.1%
——29——CVE-2013-3631—96.1%
——29——CVE-2018-0476—96.1%
——29——CVE-2019-11415—96.1%
——29——CVE-2004-0173—96.1%
——29——CVE-2020-11531—96.1%
——29——CVE-2003-0078—96.1%
——29——CVE-2018-1218—96.1%
——29——CVE-2001-0522—96.1%
——29——CVE-2019-0822—96.1%
——29——CVE-2019-0900—96.1%
——29——CVE-2018-5052—96.1%
——29——CVE-2008-3465—96.1%
——29——CVE-2019-0890—96.1%
——29——CVE-2010-2918—96.1%
——29——CVE-2017-0093—96.1%
——29——CVE-2002-0814—96.1%
——29——