Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,380
- High8,734
- Medium6,772
- Low724
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-33929—29.9%
——9——CVE-2023-46653—29.9%
——9——CVE-2020-37110—29.9%
——9——CVE-2024-8920—29.9%
——9——CVE-2022-45306—29.9%
——9——CVE-2025-46149—29.9%
——9——CVE-2021-31795—29.9%
——9——CVE-2023-41335—29.9%
——9——CVE-2022-45304—29.9%
——9——CVE-2022-43997—29.9%
——9——CVE-2024-6019—29.9%
——9——CVE-2026-585427.8 HIG29.9%
——9Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.58dCVE-2026-239425.4 MED29.9%
——9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal.
This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:is_within_root/2.
The SFTP server uses string prefix matching via lists:prefix/2 rather than proper path component validation when checking if a path is within the configured root directory. This allows authenticated users to access sibling directories that share a common name prefix with the configured root directory. For example, if root is set to /home/user1, paths like /home/user10 or /home/user1_backup would incorrectly be considered within the root.
This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14.56dCVE-2024-46327—29.9%
——9——CVE-2024-35172—29.9%
——9——CVE-2026-29783—29.9%
——9——CVE-2025-681524.9 MED29.9%
——9Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju controller can read any log file for any entity in any model at any level. This issue has been patched in versions 2.9.56 and 3.6.19.56dCVE-2024-50541—29.9%
——9——CVE-2021-2232—29.9%
——9——CVE-2026-22325—29.9%
——9——CVE-2026-464099.6 CRI29.9%
——9OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without server-side Origin validation, loopback authentication, or Content-Type enforcement, and with a wildcard CORS policy. Any webpage a user visits while OpenYak is running can issue cross-origin requests to this local server — the browser acts as a proxy into loopback, bypassing OS-level network isolation. Chained, this lets a malicious page execute arbitrary shell commands on the host (RCE) via the build agent with `permission_presets.bash=true`, shut down the service, and exfiltrate chat history and account PII — with no user interaction beyond opening the page. Version 1.1.3 patches the issue.39dCVE-2024-5955—29.9%
——9——CVE-2024-13351—29.9%
——9——CVE-2024-46450—29.9%
——9——CVE-2025-23587—29.9%
——9——CVE-2025-30445—29.9%
——9——CVE-2025-45609—29.9%
——9——CVE-2023-3853—29.9%
——9——CVE-2025-1367—29.9%
——9——CVE-2014-1845—29.9%
——9——CVE-2016-1418—29.9%
——9——CVE-2020-8026—29.9%
——9——CVE-2026-454885.4 MED29.9%
——9User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.73dCVE-2024-46055—29.9%
——9——CVE-2024-28775—29.9%
——9——CVE-2019-16355—29.9%
——9——CVE-2026-144097.5 HIG29.9%
——9Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)77dCVE-2024-6637—29.9%
——9——CVE-2026-8309910.0 CRI29.9%
——9Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).2dCVE-2023-46182—29.9%
——9——