Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32078—33.0%
——10——CVE-2026-5000—33.0%
——10——CVE-2008-1473—33.0%
——10——CVE-2023-40665—33.0%
——10——CVE-2010-4343—33.0%
——10——CVE-2025-47148—33.0%
——10——CVE-2024-0246—33.0%
——10——CVE-2026-628436.8 MED33.0%
——10File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.69dCVE-2025-49552—33.0%
——10——CVE-2024-10208—33.0%
——10——CVE-2026-8912—33.0%
——10——CVE-2013-5885—33.0%
——10——CVE-2024-11840—33.0%
——10——CVE-2022-22168—33.0%
——10——CVE-2020-36387—33.0%
——10——CVE-2022-47021—33.0%
——10——CVE-2024-13314—33.0%
——10——CVE-2023-6425—33.0%
——10——CVE-2026-24052—33.0%
——10——CVE-2006-0181—33.0%
——10——CVE-2018-3666—33.0%
——10——CVE-2026-789654.3 MED33.0%
——10Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)22dCVE-2026-681188.2 HIG33.0%
——10In the Linux kernel, the following vulnerability has been resolved:
tcp: challenge ACK for non-exact RST in SYN-RECEIVED
The SYN-RECEIVED request-socket path in tcp_check_req() accepts an
in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A
non-exact RST therefore removes the request instead of eliciting a
challenge ACK.
RFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in
SYN-RECEIVED: an exact RST resets the connection, while a non-exact
in-window RST must trigger a challenge ACK and be dropped.
Apply that check before the ACK-field validation, following the RFC
sequence-number, RST, then ACK processing order. Factor the per-netns
challenge ACK quota out of tcp_send_challenge_ack() so request sockets
can share it. Use the request socket's send_ack() callback and its own
out-of-window ACK timestamp to send and rate-limit the response.30dCVE-2024-7868—33.0%
——10——CVE-2021-41273—33.0%
——10——CVE-2026-6577—33.0%
——10——CVE-2012-2010—33.0%
——10——CVE-2026-3151—33.0%
——10——CVE-2003-1265—33.0%
——10——CVE-2023-30148—33.0%
——10——CVE-2013-3765—33.0%
——10——CVE-2026-845714.3 MED33.0%
——10A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted image may lead to unexpected app termination.4dCVE-2019-16011—33.0%
——10——CVE-2022-36352—33.0%
——10——CVE-2024-47505—33.0%
——10——CVE-2023-42109—33.0%
——10——CVE-2026-82167.3 HIG33.0%
——10A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. Such manipulation leads to improper authentication. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.60dCVE-2026-576888.2 HIG33.0%
——10Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.82dCVE-2026-93014—33.0%
——10——CVE-2018-3672—33.0%
——10——