Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,320
- High8,284
- Medium6,563
- Low705
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-141785.9 MED30.3%
——9openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 seqscan + sort 执行路径下,该字符串原本被分配在 SeqScan 的表达式上下文中;当 SeqScan 完成后,该内存上下文会被 reset,但后续结果输出阶段 timestamp_out() 仍会通过 CheckNlsFormat() 访问 u_sess->parser_cxt.nls_fmt_str,导致访问已释放内存。攻击者在具备数据库 SQL 执行权限的情况下,可构造特定 to_timestamp(..., ..., nlsparam) 查询触发 heap-use-after-free。在 ASan/Memcheck 环境下表现为数据库服务退出;在实际运行环境中可能造成后端进程异常退出,影响数据库服务可用性,形成拒绝服务风险。该问题在openGauss-server-7.0.0-RC1版本和openGauss-server-7.0.0-RC2版本存在,目前已在openGauss-server-7.0.0-RC3版本修复。由于
openGauss-server-7.0.0-RC1版本和openGauss-server-7.0.0-RC2均为创新版本,不会发布针对性补丁包,涉及版本升级至
openGauss-server-7.0.0-RC3或更新版本即可。80dCVE-2026-684269.8 CRI30.3%
——9In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix stale skb->prev after async crypto steals a GSO segment
skb_gso_segment() leaves the segment list head with ->prev pointing at
the last segment, an invariant validate_xmit_skb_list() relies on when
it sets its tail pointer (tail = skb->prev).
When validate_xmit_xfrm() walks a GSO list and some segments are stolen
by async crypto (->xmit() returns -EINPROGRESS), those segments are
unlinked from the list but the head ->prev is never updated. If the
last segment is the one stolen, the returned head still has ->prev
pointing at it, even though it is now owned by the crypto engine and may
be freed. validate_xmit_skb_list() later does tail->next = skb, writing
through that stale pointer -- a use-after-free.
Repoint skb->prev at the last retained segment before returning.33dCVE-2026-28770—30.3%
——9——CVE-2021-3100—30.3%
——9——CVE-2009-1292—30.3%
——9——CVE-2024-12111—30.3%
——9——CVE-2024-43230—30.3%
——9——CVE-2023-272495.5 MED30.3%
——9swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.72dCVE-2024-45659—30.3%
——9——CVE-2026-5737—30.3%
——9——CVE-2025-26416—30.3%
——9——CVE-2025-22639—30.3%
——9——CVE-2023-41655—30.3%
——9——CVE-2026-737217.2 HIG30.3%
——9Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.16dCVE-2024-36773—30.3%
——9——CVE-2025-30975—30.3%
——9——CVE-2001-0063—30.3%
——9——CVE-2004-2265—30.3%
——9——CVE-2026-4352—30.3%
——9——CVE-2015-7946—30.3%
——9——CVE-2025-62721—30.3%
——9——CVE-2025-9437—30.3%
——9——CVE-2026-760468.3 HIG30.3%
——9Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)28dCVE-2025-6387—30.3%
——9——CVE-2017-8254—30.3%
——9——CVE-2020-5252—30.3%
——9——CVE-2025-22505—30.3%
——9——CVE-2026-2785—30.3%
——9——CVE-2026-11344—30.3%
——9——CVE-2023-44437—30.3%
——9——CVE-2022-3097—30.3%
——9——CVE-2020-4799—30.3%
——9——CVE-2023-41948—30.3%
——9——CVE-2026-44560—30.3%
——9——CVE-2023-41859—30.3%
——9——CVE-2019-15429—30.3%
——9——CVE-2019-11486—30.3%
——9——CVE-2026-34164—30.3%
——9——CVE-2022-42406—30.3%
——9——CVE-2021-35067.1 HIG30.3%
——9An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.17d