Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24210—25.0%
——8——CVE-2026-440687.6 HIG25.0%
——8Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.54dCVE-2021-45447—25.0%
——8——CVE-2024-4273—25.0%
——8——CVE-2025-23030—25.0%
——8——CVE-2007-4536—25.0%
——8——CVE-2025-11482—25.0%
——8——CVE-2016-1849—25.0%
——8——CVE-2024-5628—25.0%
——8——CVE-2020-0502—25.0%
——8——CVE-2026-367197.5 HIG25.0%
——8An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via enumerating user IDs.54dCVE-2026-1572—25.0%
——8——CVE-2023-44183—25.0%
——8——CVE-2026-655909.8 CRI25.0%
——8n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.50dCVE-2024-3307—25.0%
——8——CVE-2025-64516—25.0%
——8——CVE-2024-39150—25.0%
——8——CVE-2024-4626—25.0%
——8——CVE-2024-4667—25.0%
——8——CVE-2026-25449—25.0%
——8——CVE-2026-19317—25.0%
——8An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.12dCVE-2022-29483—25.0%
——8——CVE-2026-813788.2 HIG25.0%
——8Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.4dCVE-2026-55731—25.0%
——8Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID component.50dCVE-2001-1406—25.0%
——8——CVE-2026-813798.2 HIG25.0%
——8Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.4dCVE-2025-10276—25.0%
——8——CVE-2026-262367.5 HIG25.0%
——8A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.
We have already fixed the vulnerability in the following version:
QuMagie 2.9.0 and later54dCVE-2024-6282—25.0%
——8——CVE-2023-32587—25.0%
——8——CVE-2024-4087—25.0%
——8——CVE-2025-30155—25.0%
——8——CVE-2024-4553—25.0%
——8——CVE-2017-14610—25.0%
——8——CVE-2025-14930—25.0%
——8——CVE-2025-27109—25.0%
——8——CVE-2024-5327—25.0%
——8——CVE-2026-0399—25.0%
——8——CVE-2025-10987—25.0%
——8——CVE-2010-0271—25.0%
——8——