Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,382
- High8,758
- Medium6,800
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-0464—29.4%
——9——CVE-2023-47053—29.4%
——9——CVE-2026-3359—29.4%
——9——CVE-2026-57653—29.4%
——9——CVE-2025-27094—29.4%
——9——CVE-2026-194017.5 HIG29.4%
——9Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.9dCVE-2021-34729—29.4%
——9——CVE-2026-736046.5 MED29.4%
——9Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint.13dCVE-2026-703777.5 HIG29.4%
——9imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.20dCVE-2025-63914—29.4%
——9——CVE-2022-491148.8 HIG29.4%
——9In the Linux kernel, the following vulnerability has been resolved:
scsi: libfc: Fix use after free in fc_exch_abts_resp()
fc_exch_release(ep) will decrease the ep's reference count. When the
reference count reaches zero, it is freed. But ep is still used in the
following code, which will lead to a use after free.
Return after the fc_exch_release() call to avoid use after free.45dCVE-2026-545938.1 HIG29.3%
——9Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.49dCVE-2024-31975—29.4%
——9——CVE-2025-7572—29.4%
——9——CVE-2026-576878.5 HIG29.4%
——9Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.77dCVE-2023-27927—29.4%
——9——CVE-2026-57667—29.4%
——9——CVE-2025-46884—29.4%
——9——CVE-2025-25013—29.4%
——9——CVE-2024-22912—29.4%
——9——CVE-2026-24696—29.4%
——9——CVE-2022-3519—29.4%
——9——CVE-2022-35713—29.4%
——9——CVE-2010-2198—29.4%
——9——CVE-2015-4808—29.4%
——9——CVE-2026-22037—29.4%
——9——CVE-2021-34725—29.4%
——9——CVE-2026-165315.3 MED29.4%
——9An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.28dCVE-2026-191649.6 CRI29.4%
——9Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)41dCVE-2026-254058.5 HIG29.4%
——9Contributor SQL Injection in eRoom <= 1.7.1 versions.57dCVE-2026-22235—29.4%
——9——CVE-2014-5233—29.4%
——9——CVE-2020-23738—29.4%
——9——CVE-2024-7296—29.4%
——9——CVE-2024-13119—29.4%
——9——CVE-2004-2410—29.4%
——9——CVE-2026-56012—29.4%
——9——CVE-2015-7076—29.4%
——9——CVE-2017-15129—29.4%
——9——CVE-2023-47054—29.4%
——9——