Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,539
- Medium7,072
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-1518—35.0%
——10——CVE-2022-30688—35.0%
——10——CVE-2025-27593—35.0%
——10——CVE-2022-29810—35.0%
——10——CVE-2026-31239—35.0%
——10——CVE-2026-540597.5 HIG35.0%
——10Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.79dCVE-2017-3590—35.0%
——10——CVE-2024-47212—35.0%
——10——CVE-2026-33322—35.0%
——10——CVE-2004-1149—35.0%
——10——CVE-2026-935607.5 HIG35.0%
——10A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS) by exhausting memory and CPU resources.2dCVE-2023-6270—35.0%
——10——CVE-2024-56528—35.0%
——10——CVE-2016-9921—35.0%
——10——CVE-2025-56379—35.0%
——10——CVE-2026-7788—35.0%
——10——CVE-2017-10237—35.0%
——10——CVE-2017-10238—35.0%
——10——CVE-2026-28929—35.0%
——10——CVE-2026-844417.3 HIG35.0%
——10A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.20dCVE-2025-59790—35.0%
——10——CVE-2022-36223—35.0%
——10——CVE-2025-55739—35.0%
——10——CVE-2021-34150—35.0%
——10——CVE-2025-20252—34.9%
——10——CVE-2024-8602—35.0%
——10——CVE-2026-72147.3 HIG35.0%
——10A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/server.py. The manipulation of the argument WORKSPACE_PATH leads to path traversal. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2024-8141—35.0%
——10——CVE-2026-32889—35.0%
——10——CVE-2021-42375—35.0%
——10——CVE-2020-36657—35.0%
——10——CVE-2026-44543—35.0%
——10——CVE-2026-194247.5 HIG35.0%
——10Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.29dCVE-2026-45083—35.0%
——10——CVE-2024-11083—35.0%
——10——CVE-2026-73147.3 HIG35.0%
——10A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2026-0885—35.0%
——10——CVE-2025-54103—35.0%
——10——CVE-2026-28806—35.0%
——10——CVE-2022-26827—35.0%
——10——