Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-21337—32.0%
——10——CVE-2026-197633.8 LOW32.0%
——10A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.35dCVE-2017-1000255—32.0%
——10——CVE-2020-10140—32.0%
——10——CVE-2025-9957—32.0%
——10——CVE-2023-28532—32.0%
——10——CVE-2012-0044—32.0%
——10——CVE-2025-59011—32.0%
——10——CVE-2017-0707—32.0%
——10——CVE-2026-32034—32.0%
——10——CVE-2010-3535—32.0%
——10——CVE-2026-8121—32.0%
——10——CVE-2024-0813—32.0%
——10——CVE-2025-7125—32.0%
——10——CVE-2025-47465—32.0%
——10——CVE-2023-46242—32.0%
——10——CVE-2022-4983—32.0%
——10——CVE-2026-228996.5 MED32.0%
——10A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5208 and later60dCVE-2022-34746—32.0%
——10——CVE-2025-55102—32.0%
——10——CVE-2017-0710—32.0%
——10——CVE-2025-2933—32.0%
——10——CVE-2026-75797—32.0%
——10——CVE-2024-53698—32.0%
——10——CVE-2026-27101—32.0%
——10——CVE-2024-43708—32.0%
——10——CVE-2026-552028.2 HIG32.0%
——10Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.69dCVE-2024-1554—32.0%
——10——CVE-2023-44116—32.0%
——10——CVE-2026-157666.5 MED32.0%
——10Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)68dCVE-2025-15463—32.0%
——10——CVE-2026-47137—32.0%
——10——CVE-2025-34238—32.0%
——10——CVE-2010-3363—32.0%
——10——CVE-2018-12190—32.0%
——10——CVE-2025-30609—32.0%
——10——CVE-2025-41019—32.0%
——10——CVE-2013-2015—32.0%
——10——CVE-2026-30878—32.0%
——10——CVE-2015-3759—32.0%
——10——