Vulnerabilities exploitable today
380,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,640
Distribution · last window
- Critical2,265
- High8,376
- Medium6,848
- Low754
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-2831—35.2%
——11——CVE-2021-25262—35.2%
——11——CVE-2024-11513—35.2%
——11——CVE-2022-26555—35.2%
——11——CVE-2009-1935—35.1%
——11——CVE-2025-11557—35.1%
——11——CVE-2018-2580—35.1%
——11——CVE-2025-10033—35.1%
——11——CVE-2024-12183—35.1%
——11——CVE-2024-9809—35.1%
——11——CVE-2022-0616—35.1%
——11——CVE-2026-862556.5 MED35.1%
——11wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.7dCVE-2017-4934—35.1%
——11——CVE-2026-622376.5 MED35.1%
——11Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_content.process_enabled: true, disabled by default), an authenticated page editor can supply a catastrophically backtracking PCRE pattern that is passed directly to PHP's preg_replace(), causing unbounded CPU consumption and denial of service to the web server process.67dCVE-2022-39814—35.1%
——11——CVE-2026-47152—35.1%
——11——CVE-2024-9808—35.1%
——11——CVE-2024-10987—35.1%
——11——CVE-2014-8399—35.1%
——11——CVE-2024-2663—35.1%
——11——CVE-2026-4526—35.1%
——11——CVE-2024-5360—35.1%
——11——CVE-2024-6011—35.1%
——11——CVE-2026-862046.5 MED35.1%
——11PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.16dCVE-2026-489876.5 MED35.1%
——11pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated getEvents API endpoint, but get_events does not invoke the available clean method to remove inactive clients. An authenticated user can repeatedly submit unique UUID values, causing retained client objects and process memory to grow without bound even after requests stop. The resulting memory exhaustion can trigger an operating-system out-of-memory termination of pyLoad or host-wide instability and denial of service. This issue is fixed in version 0.5.0b3.dev101.9dCVE-2026-47146—35.1%
——11——CVE-2019-6488—35.1%
——11——CVE-2025-2517—35.1%
——11——CVE-2026-714289.3 CRI35.1%
——11The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An attacker who controls that URL can make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints through direct targets, redirects, or DNS rebinding. The response body is returned as Element text, allowing internal response disclosure, and side-effecting GET endpoints may also be triggered. This issue is fixed in version 0.24.0.7dCVE-2026-47149—35.1%
——11——CVE-2023-40548—35.1%
——11——CVE-2026-146768.8 HIG35.1%
——11Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.27dCVE-2026-568316.5 MED35.1%
——11Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.9dCVE-2026-146708.8 HIG35.1%
——11Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.27dCVE-2021-24805—35.1%
——11——CVE-2020-37181—35.1%
——11——CVE-2021-47846—35.1%
——11——CVE-2023-43746—35.1%
——11——CVE-2026-43574—35.1%
——11——CVE-2022-3096—35.1%
——11——