Vulnerabilities exploitable today
378,004in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,292
- High8,399
- Medium6,682
- Low748
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28375—31.5%
——9——CVE-2026-527316.5 MED31.5%
——9ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust's byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0.11dCVE-2022-40755—31.5%
——9——CVE-2017-5242—31.5%
——9——CVE-2013-3754—31.5%
——9——CVE-2024-8619—31.5%
——9——CVE-2025-46298—31.5%
——9——CVE-2024-499308.8 HIG31.5%
——9In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix array out-of-bound access in SoC stats
Currently, the ath11k_soc_dp_stats::hal_reo_error array is defined with a
maximum size of DP_REO_DST_RING_MAX. However, the ath11k_dp_process_rx()
function access ath11k_soc_dp_stats::hal_reo_error using the REO
destination SRNG ring ID, which is incorrect. SRNG ring ID differ from
normal ring ID, and this usage leads to out-of-bounds array access. To fix
this issue, modify ath11k_dp_process_rx() to use the normal ring ID
directly instead of the SRNG ring ID to avoid out-of-bounds array access.
Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-148dCVE-2009-2084—31.5%
——9——CVE-2011-1171—31.5%
——9——CVE-2014-7207—31.5%
——9——CVE-2024-49581—31.5%
——9——CVE-2014-8920—31.5%
——9——CVE-2011-1170—31.5%
——9——CVE-2003-0937—31.5%
——9——CVE-2024-45233—31.5%
——9——CVE-2006-2445—31.5%
——9——CVE-2019-13356—31.5%
——9——CVE-2012-0058—31.5%
——9——CVE-2024-0015—31.5%
——9——CVE-2026-34941—31.5%
——9——CVE-2017-3756—31.5%
——9——CVE-2023-52892—31.5%
——9——CVE-2025-23878—31.5%
——9——CVE-2024-11855—31.5%
——9——CVE-2025-2700—31.5%
——9——CVE-2020-0515—31.5%
——9——CVE-2023-543926.5 MED31.5%
——9PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag type, triggering an unhandled UnexpectedTagTypeException that terminates the server process.3dCVE-2026-0729—31.4%
——9——CVE-2024-20904—31.4%
——9——CVE-2005-3001—31.4%
——9——CVE-2025-5590—31.4%
——9——CVE-2023-28727—31.4%
——9——CVE-2000-0364—31.4%
——9——CVE-2024-36359—31.4%
——9——CVE-2023-50928—31.4%
——9——CVE-2021-47831—31.4%
——9——CVE-2022-25732—31.4%
——9——CVE-2026-56351—31.4%
——9——CVE-2008-2931—31.4%
——9——