Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-0922—33.6%
——10——CVE-2025-22961—33.6%
——10——CVE-2023-38217—33.6%
——10——CVE-2024-27716—33.6%
——10——CVE-2026-896309.1 CRI33.6%
——10In the Linux kernel, the following vulnerability has been resolved:
smb: client: restore the data_offset bound in is_valid_oplock_break()
Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr")
changed the quantity this bound is measured against. It used to be
srv->total_read minus the 4-byte RFC1002 preamble that total_read then
included, so it was the SMB message length. The same commit stopped
counting the preamble, and the mechanical substitution to
srv->total_read - srv->pdu_size left an expression that is identically
zero: standard_receive3() reads MID_HEADER_SIZE() bytes and then exactly
pdu_length - MID_HEADER_SIZE() more, adding both to total_read.
len is therefore 0, the subtraction below it wraps, and no __u32
DataOffset can exceed the result, so the check from commit 097f5863b1a0
("cifs: read overflow in is_valid_oplock_break()") no longer rejects
anything. Use total_read, which is now the message length on its own.10dCVE-2008-0051—33.6%
——10——CVE-2021-39257—33.6%
——10——CVE-2025-23515—33.6%
——10——CVE-2026-279556.6 MED33.6%
——10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() helper wraps commands in bash -c '{$command}' without escaping single quotes. User-controlled docker_compose_custom_build_command and docker_compose_custom_start_command fields are interpolated directly, allowing a single quote to break out of the bash -c argument and execute commands on the managed server host (outside the intended Docker container context). This vulnerability is fixed in 4.0.0-beta.464.84dCVE-2026-2198—33.6%
——10——CVE-2026-608626.8 MED33.6%
——10Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).54dCVE-2024-32691—33.6%
——10——CVE-2020-10028—33.6%
——10——CVE-2026-845366.5 MED33.6%
——10An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to unexpected system termination.6dCVE-2010-4171—33.6%
——10——CVE-2025-445287.5 HIG33.6%
——10An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a crafted LL_Pause_Enc_Req packet during the authentication and connection phase, causing a Denial of Service (DoS).79dCVE-2021-22400—33.6%
——10——CVE-2023-25042—33.6%
——10——CVE-2023-32580—33.6%
——10——CVE-2023-2736—33.6%
——10——CVE-2022-40490—33.6%
——10——CVE-2020-11607—33.6%
——10——CVE-2023-27618—33.6%
——10——CVE-2023-27347—33.6%
——10——CVE-2016-8659—33.6%
——10——CVE-2025-49234—33.6%
——10——CVE-2020-14712—33.6%
——10——CVE-2023-36678—33.6%
——10——CVE-2016-0454—33.6%
——10——CVE-2025-24648—33.6%
——10——CVE-2026-28839—33.6%
——10——CVE-2026-44844—33.6%
——10eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly crafted EML file with approximately 120 nested message/rfc822 parts triggers an unhandled RecursionError and aborts parsing of the message. A 12 KB EML file is enough to crash a worker. Though this causes the parser to crash, it is an unlikely scenario as the suggested EML that crashes the parser would not pass basic RFC compliance tests. This vulnerability is fixed in 3.0.1.62dCVE-2024-37411—33.6%
——10——CVE-2022-41735—33.6%
——10——CVE-2025-59554—33.6%
——10——CVE-2026-2190—33.6%
——10——CVE-2025-29771—33.6%
——10——CVE-2023-41591—33.6%
——10——CVE-2023-25459—33.6%
——10——CVE-2011-2504—33.6%
——10——