Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-11417—25.4%
——8——CVE-2022-28389—25.4%
——8——CVE-2026-1467—25.4%
——8——CVE-2025-504867.1 HIG25.4%
——8Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.72dCVE-2025-68897—25.4%
——8——CVE-2024-9395—25.4%
——8——CVE-2026-27607—25.4%
——8——CVE-2025-47601—25.4%
——8——CVE-2026-41066—25.4%
——8——CVE-2007-5906—25.4%
——8——CVE-2025-29524—25.4%
——8——CVE-2016-4649—25.4%
——8——CVE-2017-18384—25.4%
——8——CVE-2025-23984—25.4%
——8——CVE-2018-20936—25.4%
——8——CVE-2017-8083—25.4%
——8——CVE-2020-8240—25.4%
——8——CVE-2026-692628.1 HIG25.4%
——8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.18hCVE-2018-20927—25.4%
——8——CVE-2025-22679—25.4%
——8——CVE-2024-2499—25.4%
——8——CVE-2026-2090—25.4%
——8——CVE-2026-867337.2 HIG25.4%
——8Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST /admin/backups/restore/{filename}) without the optional `clean` sanitizer parameter — which is not applied by default because DB_SANITIZE_BY_DEFAULT is false — can execute arbitrary OS commands as the web application's operating-system user, exposing application secrets (including database credentials and APP_KEY) and allowing modification of application-writable files and data. Version 8.7.0 adds the --binary-mode flag to the client invocation.6dCVE-2025-64713—25.4%
——8——CVE-2025-2271—25.4%
——8——CVE-2024-2542—25.4%
——8——CVE-2023-2872—25.4%
——8——CVE-2026-28791—25.4%
——8——CVE-2025-45862—25.4%
——8——CVE-2026-6490—25.4%
——8——CVE-2026-591986.5 MED25.4%
——8Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.63dCVE-2025-25767—25.4%
——8——CVE-2005-0134—25.4%
——8——CVE-2010-5313—25.4%
——8——CVE-2001-1477—25.4%
——8——CVE-2025-9841—25.4%
——8——CVE-2025-34323—25.4%
——8——CVE-2023-6854—25.4%
——8——CVE-2017-1773—25.4%
——8——CVE-2025-26984—25.4%
——8——