Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,385
- High8,759
- Medium6,801
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-13335—29.3%
——9——CVE-2025-11563—29.3%
——9——CVE-2026-81673—29.3%
——9The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and disrupt the execution of queries, causing database errors and potentially manipulating visit tracking records. Given the nature of the endpoint, this could also affect the integrity of analytics and the accuracy of records.20dCVE-2026-574339.8 CRI29.3%
——9Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.
retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.
A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.65dCVE-2026-537155.3 MED29.3%
——9Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer.Get writes the same map during EnvoyExtensionPolicy translation. An attacker with pod-network access to unauthenticated port 18002 and tenant permission to churn policies with distinct Wasm URLs can flood GET requests until a per-request reader overlaps a writer. Go's concurrent map read and write detection invokes runtime.throw, which the net/http connection recovery cannot catch, terminating the controller process and causing a timing-dependent, cross-tenant control-plane denial of service until Kubernetes restarts the pod. This issue is fixed in versions 1.7.4 and 1.8.1.3dCVE-2022-42393—29.3%
——9——CVE-2022-42385—29.3%
——9——CVE-2026-3730—29.3%
——9——CVE-2015-5890—29.3%
——9——CVE-2026-13710—29.3%
——9——CVE-2022-42800—29.3%
——9——CVE-2026-47261—29.3%
——9——CVE-2026-1546—29.3%
——9——CVE-2024-13218—29.3%
——9——CVE-2024-9641—29.3%
——9——CVE-2025-712147.8 HIG29.3%
——9An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).56dCVE-2024-11461—29.3%
——9——CVE-2006-0526—29.3%
——9——CVE-2024-47060—29.3%
——9——CVE-2022-42392—29.3%
——9——CVE-2021-32455—29.3%
——9——CVE-2024-27715—29.3%
——9——CVE-2023-32237—29.3%
——9——CVE-2017-1733—29.3%
——9——CVE-2018-4052—29.3%
——9——CVE-2022-39877—29.3%
——9——CVE-2021-38537—29.3%
——9——CVE-2018-20888—29.3%
——9——CVE-2025-27807—29.3%
——9——CVE-2015-5888—29.3%
——9——CVE-2022-42397—29.3%
——9——CVE-2022-41145—29.3%
——9——CVE-2023-28952—29.3%
——9——CVE-2025-37125—29.3%
——9——CVE-2024-3978—29.3%
——9——CVE-2019-1731—29.3%
——9——CVE-2026-540838.1 HIG29.3%
——9Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ip-customblock active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the srcip field taken from alert JSON directly onto the fixed /ipblock/ base directory, without validating that the value is a well-formed IP address. Because the extraction routine returns the raw string unchecked, an attacker who can trigger alert-matching log events with a crafted srcip containing ../ sequences can escape the base directory. The block action opens the resulting path in append mode, creating an empty file at an arbitrary location, while the unblock action passes it to remove(), deleting an arbitrary file; since the active response daemon runs as root, this includes sensitive files such as system credentials and Wazuh configuration. Unlike the sibling scripts host-deny.c, default-firewall-drop.c, and firewalld-drop.c, which reject non-IP input via get_ip_version(), ip-customblock.c omits this validation. This issue is fixed in version 4.14.7.2dCVE-2018-252467.5 HIG29.3%
——9Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.59dCVE-2023-47513—29.3%
——9——CVE-2009-0167—29.3%
——9——