Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-35709—34.0%
——10——CVE-2025-6585—34.0%
——10——CVE-2024-0334—34.0%
——10——CVE-2012-2753—34.0%
——10——CVE-2025-8326—34.0%
——10——CVE-2024-1363—34.0%
——10——CVE-2024-0871—34.0%
——10——CVE-2024-530597.1 HIG34.0%
——10In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd()
1. The size of the response packet is not validated.
2. The response buffer is not freed.
Resolve these issues by switching to iwl_mvm_send_cmd_status(),
which handles both size validation and frees the buffer.50dCVE-2025-40804—34.0%
——10——CVE-2026-32696—34.0%
——10——CVE-2026-417238.0 HIG34.0%
——10VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.62dCVE-2024-1948—34.0%
——10——CVE-2002-2083—34.0%
——10——CVE-2021-26356—33.9%
——10——CVE-2010-2059—33.9%
——10——CVE-1999-1388—33.9%
——10——CVE-2002-0941—33.9%
——10——CVE-2026-744369.8 CRI33.9%
——10In the Linux kernel, the following vulnerability has been resolved:
rxrpc: serialize kernel accept preallocation with socket teardown
rxrpc_kernel_charge_accept() reads rx->backlog without any
socket/backlog synchronization and passes that raw pointer into
rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()
sets rx->backlog = NULL and frees the backlog rings, so a kernel
preallocation worker can keep using a freed struct rxrpc_backlog
while updating *_backlog_head/tail and array slots.
Serialize the state check and backlog lookup with the socket lock,
and reject kernel preallocation once teardown has disabled
listening or discarded the service backlog.31dCVE-2018-6205—33.9%
——10——CVE-2026-893346.5 MED33.9%
——10The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.2dCVE-2026-637466.5 MED33.9%
——10SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.63dCVE-2014-2599—33.9%
——10——CVE-2001-1190—33.9%
——10——CVE-2024-23862—33.9%
——10——CVE-2005-0392—33.9%
——10——CVE-2024-53962—33.9%
——10——CVE-2010-4605—33.9%
——10——CVE-2024-23892—33.9%
——10——CVE-2018-9047—33.9%
——10——CVE-2018-9054—33.9%
——10——CVE-2018-8875—33.9%
——10——CVE-2026-31659—33.9%
——10——CVE-2025-109664.3 MED33.9%
——10curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.
This prevents curl from detecting MITM attackers and more.8dCVE-2025-63918—33.9%
——10——CVE-2004-2430—33.9%
——10——CVE-2026-492966.5 MED33.9%
——10Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-per-file deployments are not. Upgrade to apache-airflow 3.3.0 or later.7dCVE-2016-5486—33.9%
——10——CVE-2024-23857—33.9%
——10——CVE-2018-9007—33.9%
——10——CVE-2018-9042—33.9%
——10——