Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,371
- High8,689
- Medium6,707
- Low718
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-3453—30.1%
——9——CVE-2021-3988—30.1%
——9——CVE-2013-4452—30.1%
——9——CVE-2016-5410—30.1%
——9——CVE-2024-47344—30.1%
——9——CVE-2026-844787.3 HIG30.1%
——9WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server, with the vulnerability enabling both file deletion and information disclosure about the filesystem.10dCVE-2003-0641—30.1%
——9——CVE-2025-14899—30.1%
——9——CVE-2025-6014—30.1%
——9——CVE-2025-20329—30.1%
——9——CVE-2023-21347—30.1%
——9——CVE-2023-33920—30.1%
——9——CVE-2023-38652—30.1%
——9——CVE-2024-38756—30.1%
——9——CVE-2022-42430—30.1%
——9——CVE-2017-17046—30.1%
——9——CVE-2026-51303—30.1%
——9Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.49dCVE-2011-0260—30.1%
——9——CVE-2023-48058—30.1%
——9——CVE-2026-724407.1 HIG30.1%
——9In the Linux kernel, the following vulnerability has been resolved:
md/raid1: fix writes_pending and barrier reference leaks on write failures
raid1_make_request() acquires a writes_pending reference with
md_write_start() before calling raid1_write_request(). Several failure
paths in raid1_write_request() complete the bio and return without
reaching the normal write completion path, causing the corresponding
md_write_end() to be skipped.
Make raid1_write_request() return a status indicating whether the write
request was successfully queued. This allows raid1_make_request() to
call md_write_end() when raid1_write_request() fails.
Additionally, if wait_blocked_rdev() fails after wait_barrier()
succeeds, the associated barrier reference is not released.
Call allow_barrier() before returning from that path to keep the barrier
accounting balanced.32dCVE-2024-38742—30.1%
——9——CVE-2026-704638.1 HIG30.1%
——9rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.18dCVE-2021-3753—30.1%
——9——CVE-2025-27098—30.1%
——9——CVE-2022-42954—30.0%
——9——CVE-2026-769457.5 HIG30.1%
——9The affected Ebyte device relies on client-managed authentication tokens
without sufficient server-side validation. An attacker may replay or
manipulate authentication tokens to gain unauthorized access to
administrative functionality.18dCVE-2025-11671—30.1%
——9——CVE-2023-39376—30.1%
——9——CVE-2025-22728—30.1%
——9——CVE-2026-45060—30.1%
——9——CVE-2026-446689.8 CRI30.1%
——9FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.60dCVE-2023-5125—30.1%
——9——CVE-2024-38760—30.1%
——9——CVE-2023-46171—30.1%
——9——CVE-2026-56311—30.1%
——9——CVE-2024-26293—30.1%
——9——CVE-2026-788936.5 MED30.1%
——9Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)22dCVE-2017-1692—30.1%
——9——CVE-2026-706198.8 HIG30.1%
——9Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint configuration file and process environment, causing all subsequent embedding operations including chat messages, RAG queries, memory entries, and vault text to be transmitted in plaintext to the attacker-controlled destination, or delete the endpoint configuration to deny embedding service to all users.9dCVE-2025-14897—30.1%
——9——