Vulnerabilities exploitable today
380,233in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,640
Distribution · last window
- Critical2,277
- High8,407
- Medium6,864
- Low755
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-37183—35.1%
——11——CVE-2021-44421—35.1%
——11——CVE-2019-11850—35.1%
——11——CVE-2023-6551—35.1%
——11——CVE-2026-909286.5 MED35.1%
——11File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.20hCVE-2006-5173—35.1%
——11——CVE-2026-143838.8 HIG35.1%
——11Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)85dCVE-2021-47846—35.1%
——11——CVE-2026-568316.5 MED35.1%
——11Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.9dCVE-2021-24805—35.1%
——11——CVE-2026-146768.8 HIG35.1%
——11Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.27dCVE-2020-37181—35.1%
——11——CVE-2026-146708.8 HIG35.1%
——11Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.27dCVE-2025-11557—35.1%
——11——CVE-2025-10033—35.1%
——11——CVE-2024-9809—35.1%
——11——CVE-2022-0616—35.1%
——11——CVE-2018-2580—35.1%
——11——CVE-2024-12183—35.1%
——11——CVE-2026-47149—35.1%
——11——CVE-2023-40548—35.1%
——11——CVE-2020-37184—35.1%
——11——CVE-2022-41417.8 HIG35.1%
——11Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.1dCVE-2024-3210—35.1%
——11——CVE-2026-99388.8 HIG35.1%
——11Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)66dCVE-2026-800506.5 MED35.1%
——11ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.20hCVE-2026-47153—35.1%
——11——CVE-2001-1329—35.1%
——11——CVE-2024-6879—35.1%
——11——CVE-2025-51859—35.1%
——11——CVE-2026-579574.7 MED35.1%
——11Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based viewer upload endpoint reflecting arbitrary request Origins with Access-Control-Allow-Credentials set to true. Attackers can lure authenticated victims to malicious pages that silently issue credentialed cross-origin requests to upload arbitrary files into victim datarooms and read credentialed responses.73dCVE-2026-919706.5 MED35.1%
——11Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.9dCVE-2026-47145—35.1%
——11——CVE-2026-179228.8 HIG35.1%
——11Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)53dCVE-2021-29081—35.1%
——11——CVE-2024-22334—35.1%
——11——CVE-2024-34431—35.1%
——11——CVE-2026-26003—35.1%
——11——CVE-2021-31424—35.1%
——11——CVE-2025-57146—35.1%
——11——