Vulnerabilities exploitable today
380,362in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,725
New KEV · 24H2
Exploit Today ≥ 701,642
Distribution · last window
- Critical2,263
- High8,418
- Medium6,834
- Low751
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-0055—35.6%
——11——CVE-2026-667775.9 MED35.6%
——11SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited modifications on protected resources, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.17dCVE-2024-30235—35.6%
——11——CVE-2025-9571—35.6%
——11——CVE-2024-449738.1 HIG35.6%
——11In the Linux kernel, the following vulnerability has been resolved:
mm, slub: do not call do_slab_free for kfence object
In 782f8906f805 the freeing of kfence objects was moved from deep
inside do_slab_free to the wrapper functions outside. This is a nice
change, but unfortunately it missed one spot in __kmem_cache_free_bulk.
This results in a crash like this:
BUG skbuff_head_cache (Tainted: G S B E ): Padding overwritten. 0xffff88907fea0f00-0xffff88907fea0fff @offset=3840
slab_err (mm/slub.c:1129)
free_to_partial_list (mm/slub.c:? mm/slub.c:4036)
slab_pad_check (mm/slub.c:864 mm/slub.c:1290)
check_slab (mm/slub.c:?)
free_to_partial_list (mm/slub.c:3171 mm/slub.c:4036)
kmem_cache_alloc_bulk (mm/slub.c:? mm/slub.c:4495 mm/slub.c:4586 mm/slub.c:4635)
napi_build_skb (net/core/skbuff.c:348 net/core/skbuff.c:527 net/core/skbuff.c:549)
All the other callers to do_slab_free appear to be ok.
Add a kfence_free check in __kmem_cache_free_bulk to avoid the crash.52dCVE-2019-25516—35.6%
——11——CVE-2023-1261—35.6%
——11——CVE-2026-239406.5 MED35.6%
——11Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.
Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.
This issue affects hex.pm: before 2026-03-10.17dCVE-2017-3605—35.6%
——11——CVE-2025-6700—35.6%
——11——CVE-2021-4030—35.6%
——11——CVE-2023-50101—35.6%
——11——CVE-2018-1636—35.6%
——11——CVE-2026-554668.7 HIG35.6%
——11Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content that is later served same-origin and executes JavaScript in a viewer’s browser. This issue is fixed in version 8.6.2.73dCVE-2026-389986.5 MED35.6%
——11A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.11dCVE-2026-44272—35.6%
——11——CVE-2024-31847—35.6%
——11——CVE-2020-15009—35.6%
——11——CVE-2022-30735—35.6%
——11——CVE-2023-5861—35.6%
——11——CVE-2026-34186—35.6%
——11——CVE-2026-44271—35.6%
——11——CVE-2026-41478—35.6%
——11——CVE-2023-42946—35.6%
——11——CVE-2023-1262—35.6%
——11——CVE-2023-31156—35.6%
——11——CVE-1999-0390—35.6%
——11——CVE-2025-32014—35.6%
——11——CVE-2023-1702—35.6%
——11——CVE-2026-148617.5 HIG35.6%
——11The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.37dCVE-2023-1701—35.6%
——11——CVE-2023-31153—35.6%
——11——CVE-2026-25907—35.6%
——11——CVE-2026-679727.5 HIG35.6%
——11An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.25dCVE-2025-52569—35.5%
——11——CVE-2026-40978—35.6%
——11——CVE-2024-5700—35.6%
——11——CVE-2023-31159—35.6%
——11——CVE-2025-20366—35.6%
——11——CVE-2020-25656—35.6%
——11——