Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-21767—26.6%
——8——CVE-2026-11917—26.6%
——8A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.63dCVE-2024-12430—26.6%
——8——CVE-2019-18577—26.6%
——8——CVE-2025-7591—26.6%
——8——CVE-2025-43519—26.6%
——8——CVE-2025-10856—26.6%
——8——CVE-2025-7588—26.6%
——8——CVE-2004-0087—26.6%
——8——CVE-1999-1348—26.6%
——8——CVE-2025-8839—26.6%
——8——CVE-2025-15497—26.6%
——8——CVE-2022-24939—26.6%
——8——CVE-2025-69822—26.6%
——8——CVE-2023-39301—26.6%
——8——CVE-2025-7600—26.6%
——8——CVE-2023-5911—26.6%
——8——CVE-2025-30974—26.6%
——8——CVE-2025-7585—26.6%
——8——CVE-2026-13511—26.6%
——8——CVE-2025-8254—26.6%
——8——CVE-2026-11839—26.6%
——8——CVE-2026-753337.5 HIG26.6%
——8yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.15dCVE-2026-85587—26.6%
——8phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.7dCVE-2025-11714—26.6%
——8——CVE-2026-5952—26.6%
——8——CVE-2025-12932—26.6%
——8——CVE-2025-12294—26.6%
——8——CVE-2026-63777.5 HIG26.6%
——8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal.
This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3.7dCVE-2024-32429—26.6%
——8——CVE-2025-10408—26.6%
——8——CVE-2025-11610—26.6%
——8——CVE-2025-7599—26.6%
——8——CVE-2012-3187—26.6%
——8——CVE-2025-10407—26.6%
——8——CVE-2026-753287.5 HIG26.6%
——8In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:6dCVE-2026-630965.8 MED26.6%
——8Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.60dCVE-2024-13639—26.6%
——8——CVE-2026-26060—26.6%
——8——CVE-2025-2298—26.6%
——8——