Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-7450—32.7%
——10——CVE-2007-4354—32.7%
——10——CVE-2026-629496.5 MED32.7%
——10AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asyncssh/connection.py accept a peer-supplied send_pktsize value of zero. When channel data reaches SSHChannel._flush_send_buf in asyncssh/channel.py, the zero value causes each loop iteration to slice and remove zero bytes without reducing the send window, leaving the synchronous loop permanently true with no await point. A malicious SSH server can trigger the client path through SSH_MSG_CHANNEL_OPEN_CONFIRMATION before the first channel write, while an authenticated client can trigger the server path through SSH_MSG_CHANNEL_OPEN and freeze every current and future connection handled by the process. This vulnerability is fixed in 2.24.0.6dCVE-2018-18363—32.7%
——10——CVE-2024-8386—32.7%
——10——CVE-2024-37630—32.7%
——10——CVE-2026-474198.3 HIG32.7%
——10PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `agent_id` through `AgentService.get(agent_id)` which is a primary-key lookup with no workspace constraint. A user who is a member of any workspace `W1` can read, modify, or delete agents that belong to a different workspace `W2` by guessing or harvesting an agent UUID and calling `…/workspaces/W1/agents/<W2-agent-id>`. PraisonAI Platform version 0.1.4 patches the issue.62dCVE-2025-66560—32.7%
——10——CVE-2019-16638—32.7%
——10——CVE-2026-29047—32.7%
——10——CVE-2026-540529.9 CRI32.7%
——10n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destroy other tenants' stored backups, including full node definitions, credential references, and authorization headers. This issue is fixed in version 2.56.1.66dCVE-2023-41171—32.7%
——10——CVE-2018-6628—32.7%
——10——CVE-2022-4638—32.7%
——10——CVE-2026-24857—32.7%
——10——CVE-2013-3433—32.7%
——10——CVE-2020-5384—32.7%
——10——CVE-2026-726766.5 MED32.7%
——10Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration without restricting it to safe characters. That identifier is later placed into a server-side script that Fleet Server builds as part of routine agent policy processing, so script syntax embedded in the identifier became part of the script that was executed rather than being treated as data.18dCVE-2023-5460—32.7%
——10——CVE-2026-855069.8 CRI32.7%
——10ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).13dCVE-2014-8651—32.7%
——10——CVE-2023-24521—32.7%
——10——CVE-2026-855099.8 CRI32.7%
——10FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.14dCVE-2017-17853—32.7%
——10——CVE-2018-6201—32.7%
——10——CVE-2018-21269—32.7%
——10——CVE-2007-4791—32.7%
——10——CVE-2024-33507—32.7%
——10——CVE-2017-9961—32.7%
——10——CVE-2011-2484—32.7%
——10——CVE-2016-8944—32.7%
——10——CVE-2026-9678—32.7%
——10——CVE-2025-11252—32.7%
——10——CVE-2008-0587—32.7%
——10——CVE-2023-46206—32.7%
——10——CVE-2026-24481—32.7%
——10——CVE-2021-21731—32.7%
——10——CVE-2018-8993—32.7%
——10——CVE-2018-8994—32.7%
——10——CVE-2018-11279—32.7%
——10——