Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2003-0136—32.9%
——10——CVE-2019-14939—32.9%
——10——CVE-2005-3582—32.9%
——10——CVE-2006-0951—32.9%
——10——CVE-2026-758558.7 HIG32.9%
——10ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configured database directory. Attackers can supply database names containing ../ sequences to create databases at arbitrary filesystem paths or recursively delete directories the server process can access.14dCVE-2016-8667—32.9%
——10——CVE-2017-7979—32.9%
——10——CVE-2023-0770—32.9%
——10——CVE-2014-8521—32.9%
——10——CVE-2015-3702—32.9%
——10——CVE-2008-4949—32.9%
——10——CVE-2018-12168—32.9%
——10——CVE-2023-538278.8 HIG32.9%
——10In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
Similar to commit d0be8347c623 ("Bluetooth: L2CAP: Fix use-after-free
caused by l2cap_chan_put"), just use l2cap_chan_hold_unless_zero to
prevent referencing a channel that is about to be destroyed.49dCVE-2025-1014—32.9%
——10——CVE-2026-32966—32.9%
——10——CVE-2021-25417—32.9%
——10——CVE-2006-2967—32.9%
——10——CVE-2018-12271—32.9%
——10——CVE-2023-22080—32.9%
——10——CVE-1999-0862—32.9%
——10——CVE-2020-27779—32.9%
——10——CVE-2026-8793—32.9%
——10PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.13dCVE-2020-24457—32.9%
——10——CVE-2008-4944—32.9%
——10——CVE-2026-875049.6 CRI32.9%
——10Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)13dCVE-2008-4947—32.9%
——10——CVE-2014-4325—32.9%
——10——CVE-2025-46889—32.9%
——10——CVE-2025-10410—32.9%
——10——CVE-2025-62492—32.9%
——10——CVE-2026-8802—32.9%
——10——CVE-2026-450706.5 MED32.9%
——10Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.68dCVE-2026-84148—32.9%
——10This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information belonging to other users on the targeted system.21dCVE-2008-5153—32.9%
——10——CVE-2023-49501—32.9%
——10——CVE-2022-22496—32.9%
——10——CVE-2025-70304—32.9%
——10——CVE-2020-8199—32.9%
——10——CVE-2021-3620—32.9%
——10——CVE-2018-25158—32.9%
——10——