Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,639
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-29099—33.8%
——10——CVE-2016-6349—33.8%
——10——CVE-2001-1562—33.8%
——10——CVE-2017-0777—33.8%
——10——CVE-2024-29117—33.8%
——10——CVE-2026-33027—33.8%
——10——CVE-2023-29755—33.8%
——10——CVE-2022-46305—33.8%
——10——CVE-2023-51558—33.8%
——10——CVE-2026-339847.5 HIG33.8%
——10FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libfreerdp/codec/clear.c, vBarEntry->size is updated to vBarEntry->count before the winpr_aligned_recalloc() call. If realloc fails, size is inflated while pixels still points to the old, smaller buffer. On a subsequent call where count <= size (the inflated value), realloc is skipped. The caller then writes count * bpp bytes of attacker-controlled pixel data into the undersized buffer, causing a heap buffer overflow. This issue has been patched in version 3.24.2.70dCVE-2017-0776—33.8%
——10——CVE-2024-0659—33.8%
——10——CVE-2026-845966.5 MED33.8%
——10An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted font may result in the disclosure of process memory.7dCVE-2024-29094—33.8%
——10——CVE-2015-8709—33.8%
——10——CVE-2025-709997.5 HIG33.8%
——10A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID.80dCVE-2010-5245—33.8%
——10——CVE-2026-3474—33.8%
——10——CVE-2026-28944—33.8%
——10——CVE-2005-3179—33.8%
——10——CVE-2004-2276—33.8%
——10——CVE-2026-632999.9 CRI33.8%
——10An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.11dCVE-2023-40550—33.8%
——10——CVE-2023-39973—33.8%
——10——CVE-2021-23167—33.8%
——10——CVE-2005-2681—33.8%
——10——CVE-2024-274357.5 HIG33.8%
——10In the Linux kernel, the following vulnerability has been resolved:
nvme: fix reconnection fail due to reserved tag allocation
We found a issue on production environment while using NVMe over RDMA,
admin_q reconnect failed forever while remote target and network is ok.
After dig into it, we found it may caused by a ABBA deadlock due to tag
allocation. In my case, the tag was hold by a keep alive request
waiting inside admin_q, as we quiesced admin_q while reset ctrl, so the
request maked as idle and will not process before reset success. As
fabric_q shares tagset with admin_q, while reconnect remote target, we
need a tag for connect command, but the only one reserved tag was held
by keep alive command which waiting inside admin_q. As a result, we
failed to reconnect admin_q forever. In order to fix this issue, I
think we should keep two reserved tags for admin queue.50dCVE-2005-3886—33.8%
——10——CVE-2026-1069—33.8%
——10——CVE-2019-10239—33.8%
——10——CVE-2024-36112—33.8%
——10——CVE-2026-4678—33.8%
——10——CVE-2025-3831—33.8%
——10——CVE-2024-30550—33.8%
——10——CVE-2024-29092—33.8%
——10——CVE-2026-92138.1 HIG33.8%
——10A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.62dCVE-2023-42036—33.8%
——10——CVE-2025-12599—33.8%
——10——CVE-2023-49554—33.8%
——10——CVE-2024-58336—33.8%
——10——