Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-21897—25.5%
——8——CVE-2001-0713—25.5%
——8——CVE-2026-48813—25.5%
——8Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape sequences can end up being included in flawfinder's standard terminal output, with many effects. Untrusted fields (such as filenames, categories, or code context text) were not properly sanitized when generating structured reports. An attacker could exploit this to corrupt CSV formats or inject arbitrary XML attributes into SonarQube outputs via output_sonar(). It impacts those who use flawfinder to evaluate intentionally malicious filenames or file contents. This issue has been fully patched in Version 2.0.20 (released 2026-05-16). There is no configuration-based workaround within older versions of flawfinder. If an immediate upgrade is not possible, users can mitigate the risk by pre-scanning filenames, inspecting raw output, and/or restricting untrusted inputs.6dCVE-2022-22412—25.5%
——8——CVE-2002-0498—25.5%
——8——CVE-2026-555547.5 HIG25.5%
——8Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with realpath() . Because normalization strips the trailing directory separator from $chrootPath , the check only verifies that $chrootPath is a string prefix of $realfile, so a chroot of /var/www also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16.41dCVE-2021-3595—25.5%
——8——CVE-2025-68020—25.5%
——8——CVE-1999-1337—25.5%
——8——CVE-2006-1378—25.5%
——8——CVE-2024-46995—25.5%
——8——CVE-2024-5501—25.5%
——8——CVE-2025-48447—25.5%
——8——CVE-2023-4434—25.5%
——8——CVE-2026-48965—25.5%
——8——CVE-2026-23799—25.5%
——8——CVE-2026-281816.5 MED25.5%
——8Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.32dCVE-2002-0225—25.5%
——8——CVE-2023-20169—25.5%
——8——CVE-2001-0768—25.5%
——8——CVE-2021-3593—25.5%
——8——CVE-2026-753299.8 CRI25.5%
——8The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.15dCVE-2024-9304—25.5%
——8——CVE-2024-573706.1 MED25.5%
——8Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.73dCVE-2022-4134—25.5%
——8——CVE-2024-11451—25.5%
——8——CVE-2001-1324—25.5%
——8——CVE-2025-41756—25.5%
——8——CVE-2024-8734—25.5%
——8——CVE-2024-54044—25.5%
——8——CVE-2025-41006—25.5%
——8——CVE-2024-54045—25.5%
——8——CVE-2025-125063.5 LOW25.5%
——8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution.68dCVE-2024-48870—25.5%
——8——CVE-2026-5166—25.5%
——8——CVE-2021-47783—25.5%
——8——CVE-2024-54047—25.5%
——8——CVE-2025-30288—25.5%
——8——CVE-2024-54043—25.5%
——8——CVE-2026-815767.7 HIG25.5%
——8If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read
license information belonging to another handle.14d