Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-52112—26.6%
——8——CVE-2024-22296—26.6%
——8——CVE-2025-1917—26.6%
——8——CVE-2018-20909—26.6%
——8——CVE-2022-22217—26.6%
——8——CVE-2026-1962—26.6%
——8——CVE-2025-58015—26.6%
——8——CVE-2023-37530—26.6%
——8——CVE-2026-6594—26.6%
——8——CVE-2003-1289—26.6%
——8——CVE-2024-1689—26.6%
——8——CVE-2022-29201—26.6%
——8——CVE-2025-27714—26.6%
——8——CVE-2019-18824—26.6%
——8——CVE-2000-0271—26.6%
——8——CVE-2026-129795.5 MED26.6%
——8The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal, which can disable other FunnelKit WordPress plugin before 3.15.0.6 or (denial of service).62dCVE-2026-626637.5 HIG26.6%
——8Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization, canonicalization, or directory restriction. An attacker who controls template variables passed to a banks Prompt can use path traversal (../) to read arbitrary files accessible to the Python process—including .env files, SSH keys, cloud credentials, source code, /etc/passwd, and /etc/shadow—with the content returned base64-encoded in the rendered prompt output, making exfiltration trivial. This is particularly dangerous for applications that use banks to process user-provided template variables before sending prompts to an LLM. This issue has been fixed in version 2.4.4.47dCVE-2025-15135—26.6%
——8——CVE-2024-0774—26.6%
——8——CVE-2026-150817.4 HIG26.6%
——8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.41dCVE-2002-1676—26.6%
——8——CVE-2026-109767.4 HIG26.6%
——8Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)55dCVE-2024-51321—26.6%
——8——CVE-2024-10112—26.6%
——8——CVE-2013-5229—26.6%
——8——CVE-2025-3871—26.6%
——8——CVE-2005-4701—26.6%
——8——CVE-2026-30835—26.6%
——8——CVE-2024-43024—26.6%
——8——CVE-2026-73411—26.6%
——8Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when Dash is the default, and interpolate the result into an assignment prefixed to a command. An attacker who controls the input can supply a value such as :~ to disclose the home-directory path and may change the location on which the command operates. This issue is fixed in versions 2.1.14 and 3.0.1.6dCVE-2016-8289—26.6%
——8——CVE-2026-55867—26.6%
——8——CVE-2020-27225—26.6%
——8——CVE-2019-5647—26.6%
——8——CVE-2015-6645—26.6%
——8——CVE-2012-3126—26.6%
——8——CVE-2025-7577—26.6%
——8——CVE-2023-44229—26.6%
——8——CVE-2026-888965.3 MED26.6%
——8EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recognize IPv6 transition addresses that embed private IPv4 addresses: NAT64 (64:ff9b::), 6to4 (2002::), and Teredo (2001:0000::). An attacker who controls a domain with AAAA records pointing to such transition addresses can bypass both the internal-host validation and the CURLOPT_RESOLVE IP-pinning check, causing EspoCRM to issue outbound requests to internal network services. Affected paths include POST /Attachment/fromImageUrl, reachable by any authenticated user with attachment access, and outbound webhook delivery, which requires an admin or API user.12hCVE-2022-34043—26.6%
——8——