Vulnerabilities exploitable today
379,306in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,374
- High8,531
- Medium7,087
- Low799
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12551—35.0%
——11——CVE-2009-2430—35.0%
——11——CVE-2013-6384—35.0%
——11——CVE-2017-10237—35.0%
——10——CVE-2026-28929—35.0%
——10——CVE-2025-56379—35.0%
——10——CVE-2026-844417.3 HIG35.0%
——10A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.20dCVE-2026-7788—35.0%
——10——CVE-2017-10238—35.0%
——10——CVE-2026-21926—35.0%
——10——CVE-2026-54211—35.0%
——10Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a
buffer overflow vulnerability in multiple form data parameters. By
submitting excessively long values in these parameters, an authenticated
attacker can trigger a server crash, resulting in denial of service.
Depending on the stack state or if a stack canary can be disclosed
through another vulnerability, this buffer overflow could potentially be
exploited for remote code execution, leading to full compromise of the
server. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.17dCVE-2026-45083—35.0%
——10——CVE-2020-36657—35.0%
——10——CVE-2026-194247.5 HIG35.0%
——10Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.29dCVE-2026-48376.6 MED35.0%
——10An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged access to the backend platform.62dCVE-2024-8141—35.0%
——10——CVE-2025-20252—34.9%
——10——CVE-2025-54103—35.0%
——10——CVE-2022-26827—35.0%
——10——CVE-2025-55739—35.0%
——10——CVE-2024-8602—35.0%
——10——CVE-2026-73147.3 HIG35.0%
——10A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2026-32889—35.0%
——10——CVE-2026-28806—35.0%
——10——CVE-2026-72147.3 HIG35.0%
——10A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/server.py. The manipulation of the argument WORKSPACE_PATH leads to path traversal. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2021-34150—35.0%
——10——CVE-2025-27593—35.0%
——10——CVE-2022-30688—35.0%
——10——CVE-2023-1518—35.0%
——10——CVE-2026-7810—35.0%
——10——CVE-2004-0395—35.0%
——10——CVE-2025-4644—35.0%
——10——CVE-2022-4350—35.0%
——10——CVE-2016-9921—35.0%
——10——CVE-2024-56528—35.0%
——10——CVE-2026-44543—35.0%
——10——CVE-2023-6270—35.0%
——10——CVE-2021-42375—35.0%
——10——CVE-2017-3590—35.0%
——10——CVE-2025-59790—35.0%
——10——