Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8076—26.6%
——8——CVE-2024-41865—26.6%
——8——CVE-2026-718519.0 CRI26.6%
——8crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release. Nominal requests for 128 or 256 bits of entropy through this function produce effective search spaces of approximately 2 to the 39th and 2 to the 47th possibilities, small enough to enumerate on commodity hardware. Downstream wallet applications that used CryptoJS.lib.WordArray.random() as the entropy source for BIP39 recovery phrases are affected, and an attacker who enumerates the reduced output space can recover the resulting private keys and control the associated funds. This issue is fixed in version 4.0.0.6dCVE-2023-31919—26.6%
——8——CVE-2024-51553—26.6%
——8——CVE-2025-10780—26.6%
——8——CVE-2023-40152—26.6%
——8——CVE-2025-12297—26.6%
——8——CVE-2020-2297—26.6%
——8——CVE-2024-36795—26.6%
——8——CVE-2020-0501—26.6%
——8——CVE-2024-1508—26.6%
——8——CVE-2025-46405—26.6%
——8——CVE-2019-5106—26.6%
——8——CVE-2024-41851—26.6%
——8——CVE-2025-52585—26.6%
——8——CVE-2007-2467—26.6%
——8——CVE-2025-11600—26.6%
——8——CVE-2026-464778.8 HIG26.6%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. This issue has been patched in version 3.1.2.55dCVE-2014-2486—26.6%
——8——CVE-2025-24736—26.6%
——8——CVE-2026-456997.5 HIG26.6%
——8Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction. copydir() is a utility function called when a file operation crosses a device boundary inside an AFP shared volume, which the standard library's renameat() cannot handle. The function attempts to track available buffer space using srem and drem for source and destination paths. Incorrect arithmetic causes both srem and drem to underflow to SIZE_MAX. Consequently, boundary checks against strlen(de->d_name) always pass, allowing strcpy() to append filenames into nearly full stack buffers. Version 4.4.3 patches the issue. As a workaround, configure each AFP shared volume to be structured as a single file system, in other words no subdirectory of a shared volume should be a mount point for a different file system.29dCVE-2006-4614—26.6%
——8——CVE-2019-11106—26.6%
——8——CVE-2024-47612—26.6%
——8——CVE-2025-68997—26.6%
——8——CVE-2023-37301—26.6%
——8——CVE-2016-1760—26.6%
——8——CVE-2023-45844—26.6%
——8——CVE-2026-448828.1 HIG26.6%
——8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33., Portainer proxies requests to Kubernetes clusters through a middleware layer (kubeClientMiddleware) that validates the requesting user's token before forwarding traffic to the cluster. When security.RetrieveTokenData returned an error, the middleware wrote an HTTP 403 response but was missing a return statement — execution continued into the handler with a nil tokenData value. The Kubernetes endpoints sit behind Portainer's outer AuthenticatedAccess bouncer, so an attacker requires a valid Portainer session. However, a user whose secondary token validation fails in kubeClientMiddleware — for example a user without permission to access a given Kubernetes endpoint — would have their request forwarded to the cluster anyway, bypassing the authorization check. The same defect was present in both the CE and EE codebases. This vulnerability is fixed in 2.33.8.57dCVE-2024-34113—26.6%
——8——CVE-2007-4492—26.6%
——8——CVE-2025-10594—26.6%
——8——CVE-2008-7256—26.6%
——8——CVE-2024-25086—26.6%
——8——CVE-2008-3548—26.6%
——8——CVE-2023-31916—26.6%
——8——CVE-2012-1993—26.6%
——8——CVE-2026-33493—26.6%
——8——CVE-2022-0516—26.6%
——8——