Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8680—29.4%
——9——CVE-2024-25446—29.4%
——9——CVE-2026-654518.5 HIG29.4%
——9Contributor SQL Injection in MapSVG <= 8.14.0 versions.57dCVE-2026-654548.5 HIG29.4%
——9Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.57dCVE-2020-23738—29.4%
——9——CVE-2015-7076—29.4%
——9——CVE-2024-13119—29.4%
——9——CVE-2017-15129—29.4%
——9——CVE-2026-22235—29.4%
——9——CVE-2014-5233—29.4%
——9——CVE-2026-56012—29.4%
——9——CVE-2026-909825.3 MED29.4%
——9@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segment. The route matcher is case-sensitive while the filesystem is not, so a request that changes the case of a protected segment does not match the guarded route and falls through to the static handler, yet the filesystem resolves it to the same protected file. As a result, an unauthenticated request can read a file that a route guard or allowedPath was configured to protect. The issue does not affect case-sensitive filesystems and is not a directory traversal, since nothing is served from outside the configured root. The issue is fixed in @fastify/static 10.1.4, which validates the requested path against its actual on-disk spelling and rejects case-aliased paths before authorization. As a workaround, serve static files from a case-sensitive filesystem, or ensure route guards and allowedPath rules account for every letter-case variant of the protected paths.21hCVE-2025-15423—29.4%
——9——CVE-2025-46911—29.4%
——9——CVE-2026-784274.3 MED29.4%
——9The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by naming their image path after one of these sidecar images.18hCVE-2026-165315.3 MED29.4%
——9An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.28dCVE-2026-191649.6 CRI29.4%
——9Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41dCVE-2021-34725—29.4%
——9——CVE-2026-254058.5 HIG29.4%
——9Contributor SQL Injection in eRoom <= 1.7.1 versions.57dCVE-2020-3417—29.4%
——9——CVE-2026-578108.5 HIG29.4%
——9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.66dCVE-2025-32164—29.4%
——9——CVE-2003-1295—29.4%
——9——CVE-2025-27094—29.4%
——9——CVE-2023-2171—29.4%
——9——CVE-2023-47054—29.4%
——9——CVE-2012-2384—29.4%
——9——CVE-2022-25667—29.4%
——9——CVE-2026-22037—29.4%
——9——CVE-2026-576878.5 HIG29.4%
——9Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.77dCVE-2026-57667—29.4%
——9——CVE-2022-491148.8 HIG29.4%
——9In the Linux kernel, the following vulnerability has been resolved:
scsi: libfc: Fix use after free in fc_exch_abts_resp()
fc_exch_release(ep) will decrease the ep's reference count. When the
reference count reaches zero, it is freed. But ep is still used in the
following code, which will lead to a use after free.
Return after the fc_exch_release() call to avoid use after free.45dCVE-2026-703777.5 HIG29.4%
——9imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.20dCVE-2025-46884—29.4%
——9——CVE-2025-63914—29.4%
——9——CVE-2026-545938.1 HIG29.3%
——9Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.49dCVE-2023-27927—29.4%
——9——CVE-2025-7572—29.4%
——9——CVE-2024-31975—29.4%
——9——CVE-2025-690948.5 HIG29.4%
——9Subscriber SQL Injection in Unicamp <= 2.2.2 versions.78d