Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,321
- High8,309
- Medium6,574
- Low708
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-14293—30.2%
——9——CVE-2024-35661—30.2%
——9——CVE-2025-53639—30.2%
——9——CVE-2020-8712—30.2%
——9——CVE-2022-38855—30.2%
——9——CVE-2026-271348.1 HIG30.2%
——9Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS authentication on the internal as well as user-configured listeners. All CAs from the CA chain will be trusted. And users with certificates signed by any of the CAs in the chain will be able to authenticate. This issue affects only users using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs. It does not affect users using the Strimzi-managed Cluster and Clients CAs. It also does not affect users using custom Cluster or Clients CA with only a single CA (i.e., no CA chain with multiple CAs). This issue has been fixed in version 0.50.1. To workaround this issue, instead of providing the full CA chain as the custom CA, users can provide only the single CA that should be used.66dCVE-2018-16837—30.2%
——9——CVE-2013-3713—30.2%
——9——CVE-2022-38858—30.2%
——9——CVE-2025-12347—30.2%
——9——CVE-2019-19694—30.2%
——9——CVE-2021-40388—30.2%
——9——CVE-2004-0913—30.2%
——9——CVE-2023-52274—30.2%
——9——CVE-2026-322279.8 CRI30.2%
——9SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recommended to upgrade to version 2.9.0, which fixes the issue.32dCVE-2024-33545—30.2%
——9——CVE-2025-62863—30.2%
——9——CVE-2025-56226—30.2%
——9——CVE-2025-52910—30.2%
——9——CVE-2026-154508.1 HIG30.2%
——9The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target 'location' column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site's server, including wp-config. When the plugin's user-level option is configured to something else, this may be exploitable with lower privileges.37dCVE-2023-38885—30.2%
——9——CVE-2026-22984—30.2%
——9——CVE-2019-14822—30.2%
——9——CVE-2026-10835—30.2%
——9——CVE-2025-63416—30.2%
——9——CVE-2022-23038—30.2%
——9——CVE-2021-30781—30.2%
——9——CVE-2026-600817.5 HIG30.2%
——9DBI::ProfileData versions before 1.651 for Perl do not limit the path index.
The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.65dCVE-2022-36477—30.2%
——9——CVE-2026-86504.5 MED30.2%
——9Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.71dCVE-2024-57409—30.2%
——9——CVE-2017-10725—30.2%
——9——CVE-2026-29646—30.2%
——9——CVE-2018-14992—30.1%
——9——CVE-2017-15322—30.2%
——9——CVE-2026-26309—30.2%
——9——CVE-2020-29368—30.2%
——9——CVE-2026-2469—30.2%
——9——CVE-2024-7745—30.2%
——9——CVE-2008-1594—30.2%
——9——