Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-2861—31.5%
——9——CVE-2020-8691—31.5%
——9——CVE-2017-12167—31.5%
——9——CVE-2005-1369—31.5%
——9——CVE-2026-8960—31.5%
——9——CVE-2010-0826—31.5%
——9——CVE-2026-34369—31.5%
——9——CVE-2022-1798—31.5%
——9——CVE-2023-38245—31.5%
——9——CVE-2020-28015—31.5%
——9——CVE-2024-31248—31.5%
——9——CVE-2022-2476—31.5%
——9——CVE-2024-12143—31.5%
——9——CVE-2018-12260—31.5%
——9——CVE-2025-32372—31.5%
——9——CVE-2025-378207.5 HIG31.5%
——9In the Linux kernel, the following vulnerability has been resolved:
xen-netfront: handle NULL returned by xdp_convert_buff_to_frame()
The function xdp_convert_buff_to_frame() may return NULL if it fails
to correctly convert the XDP buffer into an XDP frame due to memory
constraints, internal errors, or invalid data. Failing to check for NULL
may lead to a NULL pointer dereference if the result is used later in
processing, potentially causing crashes, data corruption, or undefined
behavior.
On XDP redirect failure, the associated page must be released explicitly
if it was previously retained via get_page(). Failing to do so may result
in a memory leak, as the pages reference count is not decremented.53dCVE-2025-23854—31.5%
——9——CVE-2019-5641—31.5%
——9——CVE-2026-30230—31.5%
——9——CVE-2023-45226—31.5%
——9——CVE-2024-11739—31.5%
——9——CVE-2024-10537—31.4%
——9——CVE-2021-31844—31.5%
——9——CVE-2025-68017—31.5%
——9——CVE-2023-51543—31.5%
——9——CVE-2026-43569—31.5%
——9——CVE-2026-34275—31.5%
——9——CVE-2026-856186.5 MED31.5%
——9ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbatiminput{path} directives to have the TeX engine read arbitrary files accessible to the server process and include them in downloadable PDF output.11dCVE-2024-55909—31.5%
——9——CVE-2026-26717—31.5%
——9——CVE-2026-28375—31.5%
——9——CVE-2024-49581—31.5%
——9——CVE-2026-527316.5 MED31.5%
——9ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust's byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0.11dCVE-2017-1654—31.5%
——9——CVE-2017-3746—31.5%
——9——CVE-2017-18202—31.5%
——9——CVE-2026-694496.7 MED31.5%
——9Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.12dCVE-2017-5242—31.5%
——9——CVE-2013-3754—31.5%
——9——CVE-2025-46298—31.5%
——9——