Vulnerabilities exploitable today
377,896in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,337
- High8,543
- Medium6,730
- Low747
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-10747—31.2%
——9——CVE-2017-14296—31.2%
——9——CVE-2024-8241—31.2%
——9——CVE-2017-14553—31.2%
——9——CVE-2024-11936—31.2%
——9——CVE-2017-14690—31.2%
——9——CVE-2025-9368—31.2%
——9——CVE-2017-14556—31.2%
——9——CVE-2017-14567—31.2%
——9——CVE-2024-12129—31.2%
——9——CVE-2025-23054—31.2%
——9——CVE-2024-13947—31.2%
——9——CVE-2025-6073—31.2%
——9——CVE-2017-14299—31.2%
——9——CVE-2017-14272—31.2%
——9——CVE-2025-25195—31.2%
——9——CVE-2017-14548—31.2%
——9——CVE-2017-10750—31.2%
——9——CVE-2017-14575—31.2%
——9——CVE-2023-38047—31.2%
——9——CVE-2017-14538—31.2%
——9——CVE-2017-14290—31.2%
——9——CVE-2022-21745—31.2%
——9——CVE-2026-177904.3 MED31.2%
——9Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)48dCVE-2015-3803—31.2%
——9——CVE-2021-37183—31.2%
——9——CVE-2023-45600—31.2%
——9——CVE-2016-5879—31.2%
——9——CVE-2026-449703.1 LOW31.2%
——9dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through dbtlabs_vortex.producer.log_proto without redaction, including sql_query from show, vars from run, build, and test, and node_selection from compile, while usage_tracking_enabled in settings.py enabled telemetry by default unless DBT_SEND_ANONYMOUS_USAGE_STATS=false or DO_NOT_TRACK=1 was set. This issue is fixed in version 1.17.1.60dCVE-2022-24537—31.2%
——9——CVE-2026-542604.3 MED31.2%
——9Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.79dCVE-2016-6224—31.2%
——9——CVE-2020-36770—31.2%
——9——CVE-2025-25274—31.2%
——9——CVE-2017-8831—31.2%
——9——CVE-2025-44594—31.2%
——9——CVE-2026-600757.5 HIG31.2%
——9Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.
_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.
Any caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service.18dCVE-2024-53983—31.2%
——9——CVE-2026-25493—31.2%
——9——CVE-2026-648266.5 MED31.2%
——9rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration.10d