Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-45636—31.9%
——10——CVE-2026-1702—31.9%
——10——CVE-2022-48507—31.9%
——10——CVE-2025-60339—31.9%
——10——CVE-2026-21438—31.9%
——10——CVE-2025-43276—31.9%
——10——CVE-2023-7089—31.9%
——10——CVE-2024-53006—31.9%
——10——CVE-2025-6233—31.9%
——10——CVE-2022-1050—31.9%
——10——CVE-2010-2929—31.9%
——10——CVE-2025-5455—31.9%
——10An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.
If the function was called with malformed data, for example, an URL that
contained a "charset" parameter that lacked a value (such as
"data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).
This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.54dCVE-2026-40246—31.9%
——10——CVE-2026-645317.8 HIG31.9%
——10In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: reject oversized nested action attrs
Open vSwitch stores generated flow actions as nlattrs, whose nla_len
field is u16. Commit a1e64addf3ff ("net: openvswitch: remove
misbehaving actions length check") allowed the total sw_flow_actions
stream to grow beyond 64 KiB, which is valid, but also removed the last
guard preventing a generated nested action attribute from exceeding
U16_MAX.
An oversized generated container can thus be closed with a truncated
nla_len. A later dump or teardown then walks a structurally different
stream than the one that was validated. In particular, an oversized
nested CLONE/CT action may cause subsequent bytes in the generated
stream to be interpreted as independent actions.
Keep the larger total-action-stream behavior, but make nested action
close reject generated containers that do not fit in nla_len, and return
the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and
CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse
construction order before discarding failed wrappers, so resources copied
into the rejected tails are released before the wrappers are removed.
Most failed outer wrappers are discarded by truncating actions_len after
child resources have been released. CHECK_PKT_LEN also trims its parent
after branch resources are gone. SET/TUNNEL close failures unwind their
known tun_dst ownership directly, and SET_TO_MASKED has no external
ownership and truncates on close failure.31dCVE-2026-736475.6 MED31.9%
——10Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ property. The merge could descend into the prototype object and write attacker-controlled properties to Object.prototype in the same JavaScript process. Applications that passed user-controlled or partially user-controlled objects to extend() could experience logic bypass, unsafe default-option injection, denial of service, or other application-specific impact when polluted properties were later consumed. This issue is fixed in version 2.22.0.12dCVE-2017-7261—31.9%
——10——CVE-2026-574989.6 CRI31.9%
——10Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.83dCVE-2026-170576.5 MED31.9%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.13dCVE-2024-8786—31.9%
——10——CVE-2025-3692—31.9%
——10——CVE-2013-5724—31.9%
——10——CVE-2021-4258—31.9%
——10——CVE-2021-46879—31.9%
——10——CVE-2017-9075—31.9%
——10——CVE-2022-1834—31.9%
——10——CVE-2024-21668—31.9%
——10——CVE-2021-39787—31.9%
——10——CVE-2025-60340—31.9%
——10——CVE-2022-41310—31.9%
——10——CVE-2025-53516—31.9%
——10——CVE-2025-53946—31.9%
——10——CVE-2025-53707—31.9%
——10——CVE-2023-23878—31.9%
——10——CVE-2020-14955—31.9%
——10——CVE-2016-9777—31.9%
——10——CVE-2025-27453—31.9%
——10——CVE-2025-59277—31.9%
——10——CVE-2019-10379—31.9%
——10——CVE-2024-9205—31.9%
——10——CVE-2022-0070—31.9%
——10——