Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-16927—32.8%
——10——CVE-2019-3830—32.8%
——10——CVE-2026-109028.8 HIG32.8%
——10Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)62dCVE-2024-8811—32.8%
——10——CVE-2000-0008—32.8%
——10——CVE-2005-1765—32.8%
——10——CVE-2014-1347—32.8%
——10——CVE-2025-670367.2 HIG32.8%
——10An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.18dCVE-2008-4747—32.8%
——10——CVE-2026-2880—32.8%
——10——CVE-2022-50896—32.8%
——10——CVE-2025-52557—32.8%
——10——CVE-2026-108958.8 HIG32.8%
——10Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)62dCVE-2025-9607—32.8%
——10——CVE-2025-9667—32.8%
——10——CVE-2015-3775—32.8%
——10——CVE-2022-40257—32.8%
——10——CVE-2019-2569—32.8%
——10——CVE-2024-20797—32.8%
——10——CVE-2023-2330—32.8%
——10——CVE-2025-9665—32.8%
——10——CVE-2020-24474—32.8%
——10——CVE-2024-21628—32.8%
——10——CVE-2023-2329—32.8%
——10——CVE-2023-1691—32.8%
——10——CVE-2025-38563—32.8%
——10——CVE-2026-571368.8 HIG32.8%
——10PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.7dCVE-2023-1695—32.8%
——10——CVE-2024-2319—32.8%
——10——CVE-2026-554858.8 HIG32.8%
——10Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is not secret. In deployments that add the Sessions and User tables to create_admin, a non-superuser administrator can call GET /api/tables/sessions/, obtain another user's live session token, replay it as the Cookie id value to impersonate a superuser, and permanently set superuser to true on the attacker's own row. This issue is fixed in version 1.14.0.22dCVE-2025-2881—32.8%
——10——CVE-2025-22403—32.8%
——10——CVE-2024-12614—32.8%
——10——CVE-2023-2628—32.8%
——10——CVE-2023-3179—32.8%
——10——CVE-2026-2251—32.8%
——10——CVE-2018-9840—32.8%
——10——CVE-2025-9755—32.8%
——10——CVE-2026-751117.5 HIG32.8%
——10Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.33dCVE-2024-8429—32.8%
——10——