Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,330
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-14712—32.7%
——10——CVE-2026-315339.8 CRI32.7%
——10In the Linux kernel, the following vulnerability has been resolved:
net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
The -EBUSY handling in tls_do_encryption(), introduced by commit
859054147318 ("net: tls: handle backlogging of crypto requests"), has
a use-after-free due to double cleanup of encrypt_pending and the
scatterlist entry.
When crypto_aead_encrypt() returns -EBUSY, the request is enqueued to
the cryptd backlog and the async callback tls_encrypt_done() will be
invoked upon completion. That callback unconditionally restores the
scatterlist entry (sge->offset, sge->length) and decrements
ctx->encrypt_pending. However, if tls_encrypt_async_wait() returns an
error, the synchronous error path in tls_do_encryption() performs the
same cleanup again, double-decrementing encrypt_pending and
double-restoring the scatterlist.
The double-decrement corrupts the encrypt_pending sentinel (initialized
to 1), making tls_encrypt_async_wait() permanently skip the wait for
pending async callbacks. A subsequent sendmsg can then free the
tls_rec via bpf_exec_tx_verdict() while a cryptd callback is still
pending, resulting in a use-after-free when the callback fires on the
freed record.
Fix this by skipping the synchronous cleanup when the -EBUSY async
wait returns an error, since the callback has already handled
encrypt_pending and sge restoration.70dCVE-2026-21653—32.7%
——10Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.
This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.54dCVE-2026-457137.5 HIG32.7%
——10Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body is decoded with json.NewDecoder(r.Body) and no http.MaxBytesReader. Because Mailpit's default listeners bind [::]:1025 (SMTP) and [::]:8025 (HTTP), with no authentication required on either, a single network-reachable attacker can push an arbitrarily large message into Mailpit and watch RAM consumption spike with a ~7-10× amplification factor (raw frame → enmime envelope tree → search-text index → zstd-encoded write to SQLite). Repeating the attack — or running it concurrently from multiple connections — drives the process to OOM-kill. Version 1.30.0 contains a patch.56dCVE-2023-33025—32.7%
——10——CVE-2025-7722—32.7%
——10——CVE-2026-457779.8 CRI32.7%
——10OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. This could allow an attacker to read or modify application data, alter system configuration, or disrupt service availability. All deployments of Open XDMoD versions 9.5.0 through 11.0.2 (inclusive) are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.61dCVE-2017-9969—32.7%
——10——CVE-2024-8705—32.7%
——10——CVE-2001-0030—32.7%
——10——CVE-2019-25363—32.7%
——10——CVE-2020-35904—32.7%
——10——CVE-2025-7954—32.7%
——10——CVE-2023-43502—32.7%
——10——CVE-2026-334897.5 HIG32.7%
——10CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.60dCVE-2025-30864—32.7%
——10——CVE-2026-26310—32.7%
——10——CVE-2014-3716—32.7%
——10——CVE-2014-0615—32.7%
——10——CVE-2005-2510—32.7%
——10——CVE-2022-22551—32.7%
——10——CVE-2024-10861—32.7%
——10——CVE-2022-24886—32.7%
——10——CVE-2002-0088—32.7%
——10——CVE-2026-528707.6 HIG32.7%
——10The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.67dCVE-2023-5323—32.7%
——10——CVE-2026-2491—32.7%
——10——CVE-2022-21951—32.7%
——10——CVE-2023-4594—32.7%
——10——CVE-2026-49339—32.7%
——10——CVE-2020-36997—32.7%
——10——CVE-2011-0765—32.7%
——10——CVE-2026-454916.2 MED32.7%
——10Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.61dCVE-2025-31846—32.7%
——10——CVE-1999-0398—32.7%
——10——CVE-2026-33131—32.7%
——10——CVE-2023-37496—32.7%
——10——CVE-2022-40034—32.7%
——10——CVE-2015-3649—32.7%
——10——CVE-2022-47421—32.6%
——10——