Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,704
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-46447—31.7%
——10——CVE-2015-8019—31.7%
——10——CVE-2026-21219—31.7%
——10——CVE-2024-10683—31.7%
——10——CVE-2025-29998—31.7%
——10——CVE-2024-39392—31.6%
——10——CVE-2025-0710—31.7%
——10——CVE-2019-19059—31.7%
——10——CVE-2026-10820—31.7%
——10——CVE-2024-9214—31.7%
——10——CVE-2024-11746—31.7%
——10——CVE-2026-556686.3 MED31.7%
——10File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.75dCVE-2021-25755—31.7%
——10——CVE-2026-864844.6 MED31.7%
——10In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS13dCVE-2006-4994—31.7%
——10——CVE-2025-82914.3 MED31.7%
——10The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.
Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.52dCVE-2023-2679—31.7%
——10——CVE-2024-13591—31.7%
——10——CVE-2013-4482—31.7%
——10——CVE-2022-32759—31.7%
——10——CVE-2026-189528.1 HIG31.7%
——10Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.31dCVE-2025-24735—31.7%
——10——CVE-2025-11554—31.7%
——10——CVE-2024-8285—31.7%
——10——CVE-2026-31467—31.7%
——10——CVE-2022-44646—31.7%
——10——CVE-2023-36126—31.7%
——10——CVE-2025-11436—31.7%
——10——CVE-2024-9896—31.7%
——10——CVE-2011-0995—31.7%
——10——CVE-2020-10722—31.7%
——10——CVE-2026-4076—31.7%
——10——CVE-2026-28991—31.7%
——10——CVE-2025-11049—31.7%
——10——CVE-2025-40838—31.7%
——10——CVE-2013-5371—31.7%
——10——CVE-2025-52982—31.7%
——10——CVE-2023-51328—31.7%
——10——CVE-2025-11050—31.7%
——10——CVE-2026-347847.5 HIG31.7%
——10Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS adapter). This allows access to files that should be protected by afterFind trigger authorization logic or built-in validators such as requireUser. This issue has been patched in versions 8.6.71 and 9.7.1-alpha.1.59d