Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-14641—33.1%
——10——CVE-2023-25978—33.1%
——10——CVE-2024-10605—33.1%
——10——CVE-2024-45408—33.1%
——10——CVE-2024-5764—33.1%
——10——CVE-2024-43146—33.1%
——10——CVE-2025-401688.1 HIG33.1%
——10In the Linux kernel, the following vulnerability has been resolved:
smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
smc_clc_prfx_match() is called from smc_listen_work() and
not under RCU nor RTNL.
Using sk_dst_get(sk)->dev could trigger UAF.
Let's use __sk_dst_get() and dst_dev_rcu().
Note that the returned value of smc_clc_prfx_match() is not
used in the caller.20dCVE-2024-53621—33.1%
——10——CVE-2024-21099—33.1%
——10——CVE-2021-47699—33.1%
——10——CVE-2024-25638—33.1%
——10——CVE-2003-0652—33.1%
——10——CVE-2025-31720—33.1%
——10——CVE-2017-6386—33.1%
——10——CVE-2024-9385—33.1%
——10——CVE-2025-57325—33.1%
——10——CVE-2024-8917—33.1%
——10——CVE-2024-8803—33.1%
——10——CVE-2026-21948—33.1%
——10——CVE-2024-13132—33.1%
——10——CVE-2024-6052—33.1%
——10——CVE-2025-31494—33.1%
——10——CVE-2016-10121—33.1%
——10——CVE-2026-491438.8 HIG33.1%
——10BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with eval(). Attackers can escape the Node.js vm sandbox by leveraging a host-context Function reference through util.format to access the host process via this.constructor.constructor, achieving full remote code execution on the underlying system without any authentication.62dCVE-2025-57328—33.1%
——10——CVE-2023-5411—33.1%
——10——CVE-2024-11995—33.1%
——10——CVE-2025-44044—33.1%
——10——CVE-2025-52425—33.1%
——10——CVE-2022-50584—33.1%
——10——CVE-2026-88304.3 MED33.1%
——10A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public key algorithms, match the realm's configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.61dCVE-2026-904906.3 MED33.1%
——10A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.8dCVE-2026-35605—33.1%
——10——CVE-2024-7485—33.1%
——10——CVE-2025-3103—33.1%
——10——CVE-2024-24552—33.1%
——10——CVE-2010-3875—33.1%
——10——CVE-2026-23665—33.1%
——10——CVE-2016-10120—33.1%
——10——CVE-2025-15440—33.1%
——10——