Vulnerabilities exploitable today
378,916in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,357
- High8,518
- Medium6,901
- Low784
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28084—34.4%
——10——CVE-2026-28089—34.4%
——10——CVE-2026-749449.8 CRI34.4%
——10Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.33dCVE-2026-25382—34.4%
——10——CVE-2026-6876—34.4%
——10ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended.
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.22dCVE-2026-27988—34.4%
——10——CVE-2023-6141—34.4%
——10——CVE-2026-27047—34.4%
——10——CVE-2026-28088—34.4%
——10——CVE-2024-49657—34.4%
——10——CVE-2025-4514—34.4%
——10——CVE-2024-21167—34.4%
——10——CVE-2026-25381—34.4%
——10——CVE-2026-28017—34.4%
——10——CVE-2026-33554—34.4%
——10——CVE-2024-23154—34.4%
——10——CVE-2014-9137—34.4%
——10——CVE-2025-24956—34.4%
——10——CVE-2026-32505—34.4%
——10——CVE-2026-27990—34.4%
——10——CVE-2025-9012—34.4%
——10——CVE-2024-39890—34.4%
——10——CVE-2025-8952—34.4%
——10——CVE-2026-570795.3 MED34.4%
——10Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata.
Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and magnet metadata path (_on_metadata_received, reached from the BEP09 ut_metadata extension) passes attacker-supplied file names straight to Storage::add_file and Storage::_parse_file_tree, where Path::Tiny's child() does not collapse "..". A v2 file tree key, a v1 files[].path element, or a single-file name containing ".." segments therefore resolves outside the download directory.
Because the peer also controls the piece hashes and the served bytes, content verification passes, so a malicious magnet or peer writes attacker-chosen content to an attacker-chosen path on the downloading host.65dCVE-2026-25457—34.4%
——10——CVE-2026-106573.7 LOW34.4%
——10Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".local", 7), which always reads a fixed 7 bytes from the suffix pointer. When the resolved hostname's final label is shorter than 7 bytes (e.g. names ending in .org, .com, .net, .io, or a trailing dot), the comparison reads 1-2 bytes past the string's NUL terminator.
The hostname (query) is the caller-supplied name passed through the standard getaddrinfo()/dns_get_addr_info()/dns_resolve_name() path and is influenceable by operators or remote inputs (server names from configuration, parsed URLs, or app-facing interfaces).
On a tightly-sized buffer with no slack (for example a userspace getaddrinfo call where the hostname is copied with k_usermode_string_alloc_copy to exactly strlen+1 bytes), the over-read crosses the allocation boundary; if that boundary is unmapped (guard page, memory-domain boundary under MPU, or an address sanitizer) the over-read faults, causing a denial of service. The over-read bytes are never returned, so there is no information disclosure.
The flaw is compiled only when CONFIG_MDNS_RESOLVER is enabled, exists since v1.10.0, and is fixed by replacing the fixed-length memcmp with a NUL-safe strcmp(ptr, ".local").71dCVE-2014-9136—34.4%
——10——CVE-2025-9024—34.4%
——10——CVE-2026-28091—34.4%
——10——CVE-2016-7091—34.4%
——10——CVE-2024-5074—34.4%
——10——CVE-2026-630336.5 MED34.4%
——10A crafted IEC 60870-5-104 I-frame with a declared object count exceeding
what fits in the ASDU body causes InformationObject_ParseObjectAddress
to read one byte past the end of the heap-allocated message buffer.15dCVE-2024-9538—34.4%
——10——CVE-2014-3639—34.4%
——10——CVE-2026-28058—34.4%
——10——CVE-2026-28013—34.4%
——10——CVE-2026-25380—34.4%
——10——CVE-2025-58077—34.4%
——10——CVE-2026-25464—34.4%
——10——CVE-2026-27985—34.4%
——10——