Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51321—26.6%
——8——CVE-2025-3871—26.6%
——8——CVE-2024-43025—26.6%
——8——CVE-2024-12990—26.6%
——8——CVE-2024-56254—26.6%
——8——CVE-2001-1146—26.6%
——8——CVE-2023-37530—26.6%
——8——CVE-2025-0935—26.6%
——8——CVE-2025-27714—26.6%
——8——CVE-2022-29201—26.6%
——8——CVE-2000-0271—26.6%
——8——CVE-2026-129795.5 MED26.6%
——8The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).62dCVE-2026-6594—26.6%
——8——CVE-2024-1689—26.6%
——8——CVE-2003-1289—26.6%
——8——CVE-2019-18824—26.6%
——8——CVE-2024-28174—26.6%
——8——CVE-2026-144706.5 MED26.6%
——8IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.5dCVE-2024-28197—26.6%
——8——CVE-2025-1632—26.6%
——8——CVE-2025-47111—26.6%
——8——CVE-2026-687527.2 HIG26.6%
——8A Project Resource Manager may gain broader administrative privileges under specific conditions.13dCVE-2018-12188—26.6%
——8——CVE-2022-22479—26.6%
——8——CVE-2005-4701—26.6%
——8——CVE-2024-0774—26.6%
——8——CVE-2002-1676—26.6%
——8——CVE-2026-150817.4 HIG26.6%
——8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.41dCVE-2026-109767.4 HIG26.6%
——8Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)55dCVE-2026-73411—26.6%
——8Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when Dash is the default, and interpolate the result into an assignment prefixed to a command. An attacker who controls the input can supply a value such as :~ to disclose the home-directory path and may change the location on which the command operates. This issue is fixed in versions 2.1.14 and 3.0.1.6dCVE-2026-55867—26.6%
——8——CVE-2020-27225—26.6%
——8——CVE-2015-6645—26.6%
——8——CVE-2012-3126—26.6%
——8——CVE-2026-30835—26.6%
——8——CVE-2019-5647—26.6%
——8——CVE-2016-8289—26.6%
——8——CVE-2020-5826—26.6%
——8——CVE-2017-0728—26.6%
——8——CVE-2004-2400—26.6%
——8——