Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-3010—31.8%
——10——CVE-2026-892507.5 HIG31.8%
——10WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video files without authentication or authorization checks.10dCVE-2023-32983—31.8%
——10——CVE-2023-41863—31.8%
——10——CVE-2023-37264—31.8%
——10——CVE-2026-806349.8 CRI31.8%
——10In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps
inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the
decrement still happens and wraps it to 255. The break only leaves
the inner switch -- a later path entry can set info->indev back to
a real device, and we end up returning with num_encaps == 255.
nft_dev_forward_path() then walks info.encap[] (size 2) up to
num_encaps, which means an OOB stack read and a bogus count copied
into the route descriptor.
Should only happen on a malformed bridge path stack, hence the WARN,
but worth handling sanely. Move the decrement out of the WARN.
[ While at this, remove the WARN_ON_ONCE since this can only happen
with a buggy bridge path stack --pablo ].23dCVE-2025-29454—31.8%
——10——CVE-2021-0177—31.8%
——10——CVE-2025-57957—31.8%
——10——CVE-2017-1439—31.8%
——10——CVE-2024-13498—31.8%
——10——CVE-2024-450139.8 CRI31.8%
——10In the Linux kernel, the following vulnerability has been resolved:
nvme: move stopping keep-alive into nvme_uninit_ctrl()
Commit 4733b65d82bd ("nvme: start keep-alive after admin queue setup")
moves starting keep-alive from nvme_start_ctrl() into
nvme_init_ctrl_finish(), but don't move stopping keep-alive into
nvme_uninit_ctrl(), so keep-alive work can be started and keep pending
after failing to start controller, finally use-after-free is triggered if
nvme host driver is unloaded.
This patch fixes kernel panic when running nvme/004 in case that connection
failure is triggered, by moving stopping keep-alive into nvme_uninit_ctrl().
This way is reasonable because keep-alive is now started in
nvme_init_ctrl_finish().48dCVE-2026-33056—31.8%
——10——CVE-2020-24088—31.8%
——10——CVE-2017-1438—31.8%
——10——CVE-2025-15263—31.8%
——10——CVE-2025-15353—31.8%
——10——CVE-2025-711617.5 HIG31.8%
——10In the Linux kernel, the following vulnerability has been resolved:
dm-verity: disable recursive forward error correction
There are two problems with the recursive correction:
1. It may cause denial-of-service. In fec_read_bufs, there is a loop that
has 253 iterations. For each iteration, we may call verity_hash_for_block
recursively. There is a limit of 4 nested recursions - that means that
there may be at most 253^4 (4 billion) iterations. Red Hat QE team
actually created an image that pushes dm-verity to this limit - and this
image just makes the udev-worker process get stuck in the 'D' state.
2. It doesn't work. In fec_read_bufs we store data into the variable
"fio->bufs", but fio bufs is shared between recursive invocations, if
"verity_hash_for_block" invoked correction recursively, it would
overwrite partially filled fio->bufs.53dCVE-2026-835517.2 HIG31.8%
——10Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.18dCVE-2026-1456—31.8%
——10——CVE-2025-15208—31.8%
——10——CVE-2019-5702—31.8%
——10——CVE-2023-32611—31.8%
——10——CVE-2025-46952—31.8%
——10——CVE-2026-0565—31.8%
——10——CVE-2025-31909—31.8%
——10——CVE-2025-29450—31.8%
——10——CVE-2022-40702—31.8%
——10——CVE-2025-15181—31.8%
——10——CVE-2023-270987.5 HIG31.8%
——10TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.75dCVE-2025-48242—31.8%
——10——CVE-2026-919417.5 HIG31.8%
——10Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.2dCVE-2026-71309—31.8%
——10rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic.go WithRemote, which accepts a leading parent path and passes it to GET, HEAD, POST, and DELETE handlers for configured backends including WebDAV, FTP, HTTP, Memory, and SFTP. An attacker who can access the REST endpoint may read, create, overwrite, or delete objects outside the path configured by the operator when the operator publishes a backend subdirectory and the backend credential can access parent or sibling objects. This issue is fixed in 1.75.0.12dCVE-2025-32929—31.8%
——10——CVE-2024-12661—31.8%
——10——CVE-2025-29456—31.8%
——10——CVE-2026-1176—31.8%
——10——CVE-2025-0337—31.8%
——10——CVE-2025-29455—31.8%
——10——CVE-2025-29083—31.8%
——10——