Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-39017—32.4%
——10——CVE-2022-36044—32.4%
——10——CVE-2023-49860—32.4%
——10——CVE-2024-36208—32.4%
——10——CVE-2023-49149—32.4%
——10——CVE-2024-36213—32.4%
——10——CVE-2026-26019—32.4%
——10——CVE-2023-24409—32.4%
——10——CVE-2025-54117—32.4%
——10——CVE-2026-40785—32.4%
——10——CVE-2026-147944.3 MED32.4%
——10A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried out remotely. Upgrading to version 4.18.1 addresses this issue. Patch name: 9ee53efc1314e6aba32771c66a13e072a246f4ce. It is suggested to upgrade the affected component.77dCVE-2026-592057.5 HIG32.4%
——10Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.69dCVE-2021-47801—32.4%
——10——CVE-2024-36829—32.4%
——10——CVE-2026-22460—32.4%
——10——CVE-2024-36185—32.4%
——10——CVE-2012-3407—32.4%
——10——CVE-2022-34394—32.4%
——10——CVE-2024-36202—32.4%
——10——CVE-2024-36205—32.4%
——10——CVE-2024-36187—32.4%
——10——CVE-2023-37356—32.4%
——10——CVE-2015-1598—32.4%
——10——CVE-2026-71847—32.4%
——10Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released storage. When partial_value reconstructs an incomplete object containing duplicate keys, the duplicate-key warning path calls cursor_position, which dereferences those stale pointers. This results in a heap-use-after-free and can terminate the Ruby process. An attacker who can supply JSON stream data to an application using JSON::ResumableParser may cause process termination when the application calls partial_value on incomplete attacker-controlled input containing duplicate object keys. This issue has been fixed in version 2.21.2.3dCVE-2024-2066—32.4%
——10——CVE-2026-4675—32.4%
——10——CVE-2004-0596—32.4%
——10——CVE-2023-48749—32.4%
——10——CVE-2024-4468—32.4%
——10——CVE-2013-0241—32.4%
——10——CVE-2023-47853—32.4%
——10——CVE-2024-10001—32.4%
——10——CVE-2024-36186—32.4%
——10——CVE-2026-2957—32.4%
——10——CVE-2024-8404—32.4%
——10——CVE-2025-20384—32.4%
——10——CVE-2026-591627.5 HIG32.4%
——10Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice, allowing an XLSX file containing a shared-string cell with -1 to trigger sharedStrings[-1] and panic when read through GetCellValue or GetRows. This issue is fixed in version 2.11.0.67dCVE-2026-457338.3 HIG32.4%
——10Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.3dCVE-2018-253687.5 HIG32.4%
——10Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.60dCVE-2022-509546.2 MED32.4%
——10WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the controller parameter in tblight.php. Attackers can supply path traversal sequences through the controller GET parameter to include arbitrary files outside the intended controllers directory.59d