Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,379
- High8,748
- Medium6,795
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-8842—29.7%
——9——CVE-2024-9658—29.7%
——9——CVE-2006-0561—29.7%
——9——CVE-2006-0948—29.7%
——9——CVE-2026-27203—29.7%
——9——CVE-2026-626887.8 HIG29.7%
——9Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.36dCVE-2023-47352—29.7%
——9——CVE-2025-60268—29.7%
——9——CVE-1999-0422—29.7%
——9——CVE-2011-4355—29.7%
——9——CVE-2010-3517—29.7%
——9——CVE-2006-1092—29.7%
——9——CVE-2020-24394—29.7%
——9——CVE-2006-1695—29.7%
——9——CVE-2006-2036—29.7%
——9——CVE-2024-13558—29.7%
——9——CVE-2019-5690—29.7%
——9——CVE-2026-97084.9 MED29.7%
——9Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming webhook configuration and payloads.. Mattermost Advisory ID: MMSA-2026-0068367dCVE-2021-28070—29.7%
——9——CVE-2023-33054—29.7%
——9——CVE-2022-45091—29.7%
——9——CVE-2026-637556.5 MED29.7%
——9SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses in UPDATE, UPSERT, INSERT ON DUPLICATE KEY UPDATE, and RELATE update-variant statements) against full record data before enforcing PERMISSIONS FOR SELECT WHERE restrictions. An authenticated user — including Record and Scope users — can exploit this ordering flaw to read the full contents of any table in the database they are authenticated against, bypassing table-level permission checks. Exfiltration is most direct when scripting functions are enabled (--allow-scripting), but is also possible via SurrealQL's THROW statement and timing-based side channels without scripting. The vulnerability is confined to the attacker's current database and does not cross namespace or database isolation boundaries.58dCVE-2020-0113—29.7%
——9——CVE-2025-68061—29.7%
——9——CVE-2019-19247—29.7%
——9——CVE-2024-0970—29.7%
——9——CVE-2017-0492—29.7%
——9——CVE-2025-687459.8 CRI29.7%
——9In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Clear cmds after chip reset
Commit aefed3e5548f ("scsi: qla2xxx: target: Fix offline port handling
and host reset handling") caused two problems:
1. Commands sent to FW, after chip reset got stuck and never freed as FW
is not going to respond to them anymore.
2. BUG_ON(cmd->sg_mapped) in qlt_free_cmd(). Commit 26f9ce53817a
("scsi: qla2xxx: Fix missed DMA unmap for aborted commands")
attempted to fix this, but introduced another bug under different
circumstances when two different CPUs were racing to call
qlt_unmap_sg() at the same time: BUG_ON(!valid_dma_direction(dir)) in
dma_unmap_sg_attrs().
So revert "scsi: qla2xxx: Fix missed DMA unmap for aborted commands" and
partially revert "scsi: qla2xxx: target: Fix offline port handling and
host reset handling" at __qla2x00_abort_all_cmds.50dCVE-2026-31962—29.7%
——9——CVE-2013-2798—29.7%
——9——CVE-2026-109588.8 HIG29.7%
——9Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)58dCVE-2024-32692—29.7%
——9——CVE-2025-47635—29.7%
——9——CVE-2026-571197.5 HIG29.7%
——9PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.2dCVE-2026-109658.8 HIG29.7%
——9Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2025-68062—29.7%
——9——CVE-2026-631876.3 MED29.7%
——9Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title to npx commitlint. A pull request title containing a single quote could terminate the echo string and append arbitrary shell commands on the GitHub Actions runner. The pull_request trigger used a read-only GITHUB_TOKEN and did not expose repository secrets, but injected commands could alter or disrupt the ephemeral workflow execution. This issue is fixed in version 1.41.0.9dCVE-2026-109598.8 HIG29.7%
——9Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58dCVE-2026-624317.5 HIG29.7%
——9The logic to handle periodic Viridian STIMERs performs a division with an
unchecked user-controlled divisor value, that can be set to zero to cause a #DE
fault.52dCVE-2026-109578.8 HIG29.7%
——9Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)58d