Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,216
- High7,868
- Medium6,399
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22549—27.9%
——8——CVE-2024-6335—27.9%
——8——CVE-2026-4999—27.9%
——8——CVE-2026-1813—27.9%
——8——CVE-2025-14303—27.9%
——8——CVE-2024-10340—27.9%
——8——CVE-2025-55524—27.9%
——8——CVE-2025-6126—27.9%
——8——CVE-2025-22517—27.9%
——8——CVE-2025-22530—27.9%
——8——CVE-2026-54835—27.9%
——8——CVE-2024-39727—27.9%
——8——CVE-2016-11034—27.9%
——8——CVE-2024-55471—27.9%
——8——CVE-2026-61639—27.9%
——8Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension filter only applies to post-extraction logo copy step. This issue has been patched in version 4.9.6.8dCVE-2023-39742—27.9%
——8——CVE-2009-4080—27.9%
——8——CVE-2023-39741—27.9%
——8——CVE-2025-4069—27.9%
——8——CVE-2025-51459—27.9%
——8——CVE-2025-22546—27.9%
——8——CVE-2025-22545—27.9%
——8——CVE-2024-23517—27.9%
——8——CVE-2025-22518—27.9%
——8——CVE-2020-8911—27.9%
——8——CVE-2026-1176—27.9%
——8——CVE-2023-38514—27.9%
——8——CVE-2006-0769—27.9%
——8——CVE-2026-49079—27.9%
——8——CVE-2023-6946—27.9%
——8——CVE-2008-3898—27.9%
——8——CVE-2025-24638—27.9%
——8——CVE-2025-24675—27.9%
——8——CVE-2025-64280—27.9%
——8——CVE-2026-54828—27.9%
——8——CVE-2024-5872—27.9%
——8——CVE-2025-24687—27.9%
——8——CVE-2003-1056—27.9%
——8——CVE-2022-26807—27.9%
——8——CVE-2024-23557—27.9%
——8——