Vulnerabilities exploitable today
379,275in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,654
Distribution · last window
- Critical2,375
- High8,541
- Medium7,075
- Low796
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-44038—34.9%
——10——CVE-2024-6878—34.9%
——10——CVE-2026-584204.4 MED34.9%
——10Local File Inclusion via file:// URI in Migration Restore29dCVE-2026-713486.8 MED34.9%
——10Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.9dCVE-2023-5467—34.9%
——10——CVE-2021-418647.8 HIG34.9%
——10prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.50dCVE-2024-30278—34.9%
——10——CVE-2024-5769—34.9%
——10——CVE-2023-51067—34.9%
——10——CVE-2025-7773—34.9%
——10——CVE-2019-25525—34.9%
——10——CVE-2022-23182—34.9%
——10——CVE-2024-39874—34.9%
——10——CVE-2023-24975—34.9%
——10——CVE-2006-6013—34.9%
——10——CVE-2024-47358—34.9%
——10——CVE-2022-33213—34.9%
——10——CVE-2026-19672—34.9%
——10The tarfile module's tar and data
extraction filters created directories outside the destination for
members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.
Only
empty directories are created outside the destination. Member contents
are still extracted inside it. To return to the destination the member's
name must contain the destination directory's own final component, so
extraction into a secure randomised directory is not affected.
This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.27dCVE-2024-28584—34.9%
——10——CVE-2024-34432—34.9%
——10——CVE-2026-196589.8 CRI34.9%
——10The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. This vulnerability is only reachable when the "Allow Multiple Recipients" option is enabled for the donation form, as the single-recipient code path applies sanitize_textarea_field() which would neutralize the payload. Exploitation additionally requires the eCard "Custom Message" option to be disabled, which is the plugin default: when it is enabled the personalized message becomes a required field and GiveWP's give_clean() blanks serialized input during validation, causing the donation to be rejected before it is stored.2dCVE-2019-14412—34.9%
——10——CVE-2024-32568—34.9%
——10——CVE-2026-736588.2 HIG34.8%
——10Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses findResource: async () => 1 without per-resource ownership validation. WHATWG path normalization collapses .. segments before signing, allowing a caller with a valid environment API key to obtain presigned URLs for another tenant's object-store keys and read or overwrite task payloads. This issue is fixed in version 4.5.0-rc.5.16dCVE-2017-16644—34.9%
——10——CVE-2026-4351—34.9%
——10——CVE-2026-815748.2 HIG34.9%
——10In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format
specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory
and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and
remotely when combined with CVE-2026-81573 by setting General.ProxyServer and then triggering this
vulnerability.23dCVE-2025-41744—34.9%
——10——CVE-2026-667388.8 HIG34.9%
——10SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an internal quoted string context when evaluated as PHP. An authenticated attacker with at minimum editor (redacteur) privileges can submit a single crafted GET request to /ecrire/?exec=navigation to execute arbitrary OS commands in the web server process. MySQL-backed installations are not affected.15dCVE-2024-3699—34.9%
——10——CVE-2020-0082—34.9%
——10——CVE-2024-9412—34.9%
——10——CVE-2026-1178—34.9%
——10——CVE-2026-91506.5 MED34.9%
——10A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.23dCVE-2026-7051—34.9%
——10——CVE-2024-4680—34.9%
——10——CVE-2022-38447—34.9%
——10——CVE-2024-45249—34.9%
——10——CVE-2024-1228—34.9%
——10——CVE-2024-11112—34.9%
——10——