Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,539
- Medium7,072
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-540597.5 HIG35.0%
——10Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.79dCVE-2022-29810—35.0%
——10——CVE-2026-220688.2 HIG35.0%
——10Regular Expression without Anchors vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.50dCVE-2026-935607.5 HIG35.0%
——10A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS) by exhausting memory and CPU resources.2dCVE-2004-1149—35.0%
——10——CVE-2024-47214—35.0%
——10——CVE-2026-934947.5 HIG35.0%
——10A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.6dCVE-2025-29192—35.0%
——10——CVE-2024-21491—35.0%
——10——CVE-2024-47213—35.0%
——10——CVE-2026-73157.3 HIG35.0%
——10A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.62dCVE-2026-53648—34.9%
——10FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as `md5(<original filename>)` under the uploads directory. Because the stored path depends only on the client-supplied filename, two different downloadable products, or product/order files, uploaded with the same original filename will resolve to the same stored file path. A later upload can overwrite an earlier upload, causing customers or administrators downloading the earlier product to receive the later file instead. Version 0.8.1 patches the issue. Some workarounds are available. Restrict the `servicedownloadable.manage` permission to fully trusted administrators only. As an operational mitigation, ensure downloadable product files use unique filenames before upload. This reduces accidental collisions but does not fully address the underlying issue.79dCVE-2017-3620—34.9%
——10——CVE-2023-5423—34.9%
——10——CVE-2024-5369—34.9%
——10——CVE-2023-2561—34.9%
——10——CVE-2026-614587.5 HIG34.9%
——10PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense, making short or dictionary-derived passphrases practically recoverable within hours or days.71dCVE-2024-8057—34.9%
——10——CVE-2022-3714—34.9%
——10——CVE-2024-1044—34.9%
——10——CVE-2024-9285—34.9%
——10——CVE-2026-21726—34.9%
——10——CVE-2026-584516.5 MED34.9%
——10Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding traversal sequences after a CKEditor path prefix in img src URLs. Attackers can bypass the stripos() prefix validation by appending sequences such as traversal segments after the matching prefix, causing file_get_contents() to read sensitive files whose contents are then exfiltrated as MIME parts in outgoing email; unauthenticated exploitation is also achievable via CSRF against an active authenticated session.72dCVE-2023-45767—34.9%
——10——CVE-2019-19523—34.9%
——10——CVE-2024-56525—34.9%
——10——CVE-2014-3645—34.9%
——10——CVE-2026-60032—34.9%
——10Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.63dCVE-2023-45768—34.9%
——10——CVE-2026-47365—34.9%
——10——CVE-2004-1374—34.9%
——10——CVE-2001-0094—34.9%
——10——CVE-2023-48404—34.9%
——10——CVE-2025-23208—34.9%
——10——CVE-2006-3500—34.9%
——10——CVE-2020-15145—34.9%
——10——CVE-2023-2426—34.9%
——10——CVE-2019-3699—34.9%
——10——CVE-2026-633068.6 HIG34.9%
——10stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access internal infrastructure.70dCVE-2009-3101—34.9%
——10——