Vulnerabilities exploitable today
4,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-33891—99.8%
KEV—80Apache Spark Command Injection Vulnerability—CVE-2021-27905—99.8%
——30——CVE-2023-0992—99.8%
——30——CVE-2018-10561—99.8%
KEV—80Dasan GPON Routers Authentication Bypass Vulnerability—CVE-2016-4437—99.8%
KEV—80Apache Shiro Code Execution Vulnerability—CVE-2024-2389—99.8%
——30——CVE-2021-40870—99.8%
KEV—80Aviatrix Controller Unrestricted Upload of File—CVE-2005-1983—99.8%
——30——CVE-2024-6670—99.8%
KEVR80Progress WhatsUp Gold SQL Injection Vulnerability—CVE-2021-2190—99.8%
——30——CVE-2018-14912—99.8%
——30——CVE-2016-4010—99.8%
——30——CVE-2021-37539—99.8%
——30——CVE-2026-435007.8 HIG99.8%
——30In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE
handler in rxrpc_verify_response() copy the skb to a linear one before
calling into the security ops only when skb_cloned() is true. An skb
that is not cloned but still carries externally-owned paged fragments
(e.g. SKBFL_SHARED_FRAG set by splice() into a UDP socket via
__ip_append_data, or a chained skb_has_frag_list()) falls through to
the in-place decryption path, which binds the frag pages directly into
the AEAD/skcipher SGL via skb_to_sgvec().
Extend the gate to also unshare when skb_has_frag_list() or
skb_has_shared_frag() is true. This catches the splice-loopback vector
and other externally-shared frag sources while preserving the
zero-copy fast path for skbs whose frags are kernel-private (e.g. NIC
page_pool RX, GRO). The OOM/trace handling already in place is reused.7dCVE-2019-15976—99.8%
——30——CVE-2025-47812—99.8%
KEV—80Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability—CVE-2026-398089.8 CRI99.8%
KEV—80Fortinet FortiSandbox OS Command Injection Vulnerability45dCVE-2023-35628—99.8%
——30——CVE-2022-21907—99.8%
——30——CVE-2020-2096—99.8%
——30——CVE-2016-7547—99.8%
——30——CVE-2022-1329—99.8%
——30——CVE-2022-21371—99.8%
——30——CVE-2019-8943—99.8%
——30——CVE-2023-28302—99.8%
——30——CVE-2023-41892—99.8%
——30——CVE-2023-21758—99.8%
——30——CVE-2007-0071—99.8%
——30——CVE-2018-16509—99.8%
——30——CVE-2012-1429—99.8%
——30——CVE-2022-3786—99.8%
——30——CVE-2025-2747—99.8%
KEV—80Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability—CVE-2022-40022—99.8%
——30——CVE-2023-23488—99.8%
——30——CVE-2023-0050—99.8%
——30——CVE-2022-24706—99.8%
KEV—80Apache CouchDB Insecure Default Initialization of Resource Vulnerability—CVE-2021-25282—99.8%
——30——CVE-2006-2369—99.8%
——30——CVE-2022-41622—99.8%
——30——CVE-2016-3427—99.8%
KEV—80Oracle Java SE and JRockit Unspecified Vulnerability—