Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-422485.4 MED31.5%
——9QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.74dCVE-2014-3089—31.5%
——9——CVE-2024-31253—31.5%
——9——CVE-2023-7240—31.5%
——9——CVE-2013-1050—31.5%
——9——CVE-2025-4223—31.5%
——9——CVE-2025-400758.1 HIG31.5%
——9In the Linux kernel, the following vulnerability has been resolved:
tcp_metrics: use dst_dev_net_rcu()
Replace three dst_dev() with a lockdep enabled helper.53dCVE-2026-567196.5 MED31.5%
——9MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.5dCVE-2025-23041—31.5%
——9——CVE-2024-12132—31.5%
——9——CVE-2026-748869.8 CRI31.5%
——9openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.20dCVE-2021-26273—31.5%
——9——CVE-2024-13134—31.5%
——9——CVE-2007-3532—31.5%
——9——CVE-2023-33356—31.5%
——9——CVE-2024-11008—31.5%
——9——CVE-2026-737518.8 HIG31.5%
——9An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.6dCVE-2014-4509—31.5%
——9——CVE-2026-817308.2 HIG31.5%
——9Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollector.class.php writes to $destdir.'/'.$filename; the name reaches both from the attachment's own getName() or getFilename() value by way of the record-join, create-ticket and create-project operations. A traversal sequence in the filename therefore survives intact, so any sender who can email a mailbox that an EmailCollector monitors, which is the module's ordinary use for a support or ticket inbox, can place attacker-controlled content outside the per-object attachment directory without holding a Dolibarr account. Under the hardened layout Dolibarr's SECURITY.md requires, with htdocs read-only, the write is confined to the documents tree and corrupts or forges other objects' documents; where htdocs is writable the same primitive reaches a web-executable path. Version 24.0.0 applies dol_sanitizePathName() and dol_sanitizeFileName() before the write.21dCVE-2022-45841—31.5%
——9——CVE-2023-2767—31.5%
——9——CVE-2014-3209—31.5%
——9——CVE-2014-9090—31.5%
——9——CVE-2025-23854—31.5%
——9——CVE-2026-6602—31.5%
——9——CVE-2018-1166—31.5%
——9——CVE-2023-5594—31.5%
——9——CVE-2026-47375—31.5%
——9——CVE-2024-34535—31.5%
——9——CVE-2024-11770—31.5%
——9——CVE-2023-38058—31.5%
——9——CVE-2026-340506.5 MED31.5%
——9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page and potentially modify auto-update settings or trigger update checks. This issue is fixed in version 4.0.0-beta.471.76dCVE-2020-36915—31.5%
——9——CVE-2025-64709—31.5%
——9——CVE-2022-497687.5 HIG31.4%
——9In the Linux kernel, the following vulnerability has been resolved:
9p: trans_fd/p9_conn_cancel: drop client lock earlier
syzbot reported a double-lock here and we no longer need this
lock after requests have been moved off to local list:
just drop the lock earlier.48dCVE-2010-0826—31.5%
——9——CVE-2017-12167—31.5%
——9——CVE-2026-8960—31.5%
——9——CVE-2024-583806.5 MED31.5%
——9PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inventory slot greater than 35 to trigger an unhandled exception and crash the server.3dCVE-2020-8691—31.5%
——9——