Vulnerabilities exploitable today
378,819in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,414
- High8,704
- Medium6,988
- Low790
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2003-0933—34.1%
——10——CVE-2025-62067—34.1%
——10——CVE-2025-31035—34.1%
——10——CVE-2024-9530—34.1%
——10——CVE-2024-11534—34.1%
——10——CVE-2023-39369—34.1%
——10——CVE-2025-32134—34.1%
——10——CVE-2026-41149—34.1%
——10Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed <iframe>.62dCVE-2023-40193—34.1%
——10——CVE-2023-40702—34.1%
——10——CVE-2023-29681—34.1%
——10——CVE-2025-32136—34.1%
——10——CVE-2025-57430—34.1%
——10——CVE-2017-2596—34.1%
——10——CVE-2025-45994—34.1%
——10——CVE-2026-21670—34.1%
——10——CVE-2026-545208.1 HIG34.1%
——10AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting path for read or write operations without checking that it remains in an approved workflow directory. An authenticated user who can create or modify workflow file steps can supply traversal segments to escape the intended workspace and read sensitive files or write and overwrite files accessible to the backend process, including application-adjacent files when process permissions allow. This issue is fixed in version 0.9.1.5dCVE-2023-5894—34.1%
——10——CVE-2015-3286—34.1%
——10——CVE-2023-29680—34.1%
——10——CVE-2024-5373—34.1%
——10——CVE-2016-3834—34.1%
——10——CVE-2026-775285.3 MED34.1%
——10Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message size before delivery. A remote unauthenticated client can send a valid compressed frame below the configured wire-size limit that expands beyond the application message limit, causing oversized data to be allocated, joined, validated, and passed to application callbacks. This can create resource-exhaustion pressure, but the advisory does not establish confidentiality or integrity impact. This issue is fixed in version 26.7.1.4dCVE-2022-34323—34.1%
——10——CVE-2026-706348.1 HIG34.1%
——10TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a reverse-order scan. With a pass-by-value column type the out-of-bounds Datum is returned to the client as a normal column value, disclosing backend memory including the shared buffer pool, which SQL access control does not cover.22dCVE-2005-3321—34.1%
——10——CVE-2024-40865—34.1%
——10——CVE-2025-32483—34.1%
——10——CVE-2025-714185.3 MED34.1%
——10PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints.14dCVE-2025-32129—34.1%
——10——CVE-2025-26852—34.1%
——10——CVE-2015-0875—34.1%
——10——CVE-2025-32130—34.1%
——10——CVE-2024-1267—34.1%
——10——CVE-2024-1333—34.1%
——10——CVE-2024-5372—34.1%
——10——CVE-2023-37221—34.1%
——10——CVE-2025-11380—34.1%
——10——CVE-2019-11483—34.1%
——10——CVE-2013-1920—34.1%
——10——