Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-1439—31.8%
——10——CVE-2016-0434—31.8%
——10——CVE-2025-15186—31.8%
——10——CVE-2005-0991—31.8%
——10——CVE-2025-15353—31.8%
——10——CVE-2026-71309—31.8%
——10rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading parent path and passes it to GET, HEAD, POST, and DELETE handlers for configured backends including WebDAV, FTP, HTTP, Memory, and SFTP. An attacker who can access the REST endpoint may read, create, overwrite, or delete objects outside the path configured by the operator when the operator publishes a backend subdirectory and the backend credential can access parent or sibling objects. This issue is fixed in 1.75.0.12dCVE-2026-1456—31.8%
——10——CVE-2025-711617.5 HIG31.8%
——10In the Linux kernel, the following vulnerability has been resolved:
dm-verity: disable recursive forward error correction
There are two problems with the recursive correction:
1. It may cause denial-of-service. In fec_read_bufs, there is a loop that
has 253 iterations. For each iteration, we may call verity_hash_for_block
recursively. There is a limit of 4 nested recursions - that means that
there may be at most 253^4 (4 billion) iterations. Red Hat QE team
actually created an image that pushes dm-verity to this limit - and this
image just makes the udev-worker process get stuck in the 'D' state.
2. It doesn't work. In fec_read_bufs we store data into the variable
"fio->bufs", but fio bufs is shared between recursive invocations, if
"verity_hash_for_block" invoked correction recursively, it would
overwrite partially filled fio->bufs.53dCVE-2026-835517.2 HIG31.8%
——10Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.18dCVE-2025-15263—31.8%
——10——CVE-2024-12661—31.8%
——10——CVE-2026-1176—31.8%
——10——CVE-2025-29456—31.8%
——10——CVE-2025-32929—31.8%
——10——CVE-2025-0337—31.8%
——10——CVE-2026-919417.5 HIG31.8%
——10Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.2dCVE-2026-571268.5 HIG31.8%
——10PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname resolving to a loopback, private, link-local, or cloud-metadata address therefore bypasses the SSRF policy without a rebinding race and can expose internal responses to the agent. This issue is fixed in praisonaiagents 1.6.58.6dCVE-2026-0567—31.8%
——10——CVE-2005-0690—31.8%
——10——CVE-2002-1737—31.8%
——10——CVE-2005-1065—31.8%
——10——CVE-2016-0436—31.8%
——10——CVE-2025-15198—31.8%
——10——CVE-2026-0569—31.8%
——10——CVE-2025-15354—31.8%
——10——CVE-2021-2283—31.8%
——10——CVE-2015-1391—31.8%
——10——CVE-2025-29449—31.8%
——10——CVE-2023-47628—31.8%
——10——CVE-2026-1160—31.8%
——10——CVE-2025-62609—31.8%
——10——CVE-2025-65778—31.8%
——10——CVE-2025-41034—31.8%
——10——CVE-2026-22990—31.8%
——10——CVE-2020-2726—31.8%
——10——CVE-2009-3279—31.8%
——10——CVE-2016-0437—31.8%
——10——CVE-2026-537778.1 HIG31.8%
——10Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized path components in the artifact_name field of ArtifactReady WebSocket messages. Attackers controlling the server URL can deliver traversal payloads through the artifact_name or download_path fields, causing the client to overwrite sensitive files or expose arbitrary local files to an attacker-accessible location.69dCVE-2026-0544—31.8%
——10——CVE-2011-1837—31.8%
——10——