Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-25029—32.9%
——10——CVE-2026-79754—32.9%
——10Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.tempDir field before using it to construct a shell command. When the Kaniko container builder is enabled, a user with function-create permission can inject shell metacharacters into this field and achieve arbitrary command execution inside the Dashboard container, which runs with a Kubernetes service account holding wildcard access to Secrets, Pods, Jobs, and Deployments in its namespace. This issue has been patched in version 1.17.2.20dCVE-2021-4400—32.9%
——10——CVE-2021-4405—32.9%
——10——CVE-2025-2250—32.9%
——10——CVE-2025-603069.9 CRI32.9%
——10code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.80dCVE-2022-42942—32.9%
——10——CVE-2024-2820—32.9%
——10——CVE-2008-4941—32.9%
——10——CVE-2026-8994—32.9%
——10——CVE-2026-781864.3 MED32.9%
——10A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.29dCVE-2022-41309—32.9%
——10——CVE-2008-4970—32.9%
——10——CVE-2021-32557—32.9%
——10——CVE-2020-29484—32.9%
——10——CVE-2015-0238—32.9%
——10——CVE-2023-31245—32.9%
——10——CVE-2023-25148—32.9%
——10——CVE-2008-4982—32.9%
——10——CVE-2025-1918—32.9%
——10——CVE-2026-3287—32.9%
——10——CVE-2023-47548—32.9%
——10——CVE-2021-4403—32.9%
——10——CVE-2024-43009—32.9%
——10——CVE-2008-4973—32.9%
——10——CVE-2022-42939—32.9%
——10——CVE-2024-7383—32.9%
——10——CVE-2023-46854—32.9%
——10——CVE-2024-0805—32.9%
——10——CVE-2024-45159—32.9%
——10——CVE-2022-40680—32.9%
——10——CVE-2026-384319.8 CRI32.9%
——10ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.60dCVE-2008-4964—32.9%
——10——CVE-2017-5957—32.9%
——10——CVE-2021-4398—32.9%
——10——CVE-2023-7038—32.9%
——10——CVE-2025-26304—32.9%
——10——CVE-2023-28416—32.9%
——10——CVE-2026-71393—32.9%
——10GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap allocation. A subsequent read() call writes beyond the buffer, causing a heap buffer overflow. An attacker can deliver a malicious font file via email, EWW (Emacs Web Wowser), or documents with custom faces, causing Emacs to load it. This can lead to heap memory corruption and potential code execution.
This issue was fixed in commit d51a4722316efe0960994d371e1859099894d1ca25dCVE-2023-50235—32.9%
——10——