Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,696
- Medium6,987
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-9667—34.2%
——10——CVE-2010-5264—34.2%
——10——CVE-2007-4591—34.2%
——10——CVE-2023-34291—34.2%
——10——CVE-2001-1387—34.2%
——10——CVE-2010-2532—34.2%
——10——CVE-2023-34161—34.2%
——10——CVE-2023-37347—34.2%
——10——CVE-2025-49438—34.2%
——10——CVE-2023-3196—34.2%
——10——CVE-2025-0934—34.2%
——10——CVE-2008-3866—34.2%
——10——CVE-2011-2473—34.2%
——10——CVE-2023-34311—34.2%
——10——CVE-2024-2241—34.2%
——10——CVE-2021-41527—34.2%
——10——CVE-2019-14239—34.2%
——10——CVE-2023-29680—34.1%
——10——CVE-2026-21670—34.1%
——10——CVE-2026-545208.1 HIG34.1%
——10AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved workflow directory. An authenticated user who can create or modify workflow file steps can supply traversal segments to escape the intended workspace and read sensitive files or write and overwrite files accessible to the backend process, including application-adjacent files when process permissions allow. This issue is fixed in version 0.9.1.5dCVE-2023-5894—34.1%
——10——CVE-2019-0035—34.1%
——10——CVE-2024-11522—34.1%
——10——CVE-2023-47716—34.1%
——10——CVE-2023-0313—34.1%
——10——CVE-2022-41919—34.1%
——10——CVE-2023-27612—34.1%
——10——CVE-2023-39224—34.1%
——10——CVE-2024-11615—34.1%
——10——CVE-2024-11533—34.1%
——10——CVE-2026-334344.3 MED34.1%
——10Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to unconditionally overwrite the general rate limit result. When the global max_request_per_minute is exceeded, requests to /events still succeed if the events-specific counter (hardcoded 30/min) has not been reached. This allows event injection into analysisd beyond the admin-configured global rate limit. This issue has been fixed in version 4.14.5.65dCVE-2025-62055—34.1%
——10——CVE-2024-2404—34.1%
——10——CVE-2016-3834—34.1%
——10——CVE-2022-34323—34.1%
——10——CVE-2026-95217.3 HIG34.1%
——10A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this issue. The name of the patch is 66d16516e24893bebc1c8af52bf2fe9ad0735061. Upgrading the affected component is advised.62dCVE-2026-54523—34.1%
——10——CVE-2004-2414—34.1%
——10——CVE-2014-125109—34.1%
——10——CVE-2026-333908.1 HIG34.1%
——10An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.43d