Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,949
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-38369—27.4%
——8——CVE-2022-1892—27.4%
——8——CVE-2026-77693—27.4%
——8——CVE-2024-4043—27.4%
——8——CVE-2022-46311—27.4%
——8——CVE-2024-28589—27.4%
——8——CVE-2025-54008—27.4%
——8——CVE-2024-41595—27.4%
——8——CVE-2026-51271—27.4%
——8Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.47dCVE-2025-32486—27.4%
——8——CVE-2024-4458—27.4%
——8——CVE-2024-8046—27.4%
——8——CVE-2019-25269—27.4%
——8——CVE-2025-5724—27.4%
——8——CVE-2025-71282—27.4%
——8——CVE-2019-14396—27.4%
——8——CVE-2024-4980—27.4%
——8——CVE-2017-1714—27.4%
——8——CVE-2024-4459—27.4%
——8——CVE-2024-54156—27.4%
——8——CVE-2026-749599.1 CRI27.4%
——8Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.23dCVE-2016-5242—27.3%
——8——CVE-2017-18790—27.3%
——8——CVE-2024-54253—27.3%
——8——CVE-2026-156309.9 CRI27.3%
——8A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).5dCVE-2021-25656—27.3%
——8——CVE-2023-35783—27.3%
——8——CVE-2026-4358—27.3%
——8——CVE-2019-25501—27.3%
——8——CVE-2024-358878.8 HIG27.3%
——8In the Linux kernel, the following vulnerability has been resolved:
ax25: fix use-after-free bugs caused by ax25_ds_del_timer
When the ax25 device is detaching, the ax25_dev_device_down()
calls ax25_ds_del_timer() to cleanup the slave_timer. When
the timer handler is running, the ax25_ds_del_timer() that
calls del_timer() in it will return directly. As a result,
the use-after-free bugs could happen, one of the scenarios
is shown below:
(Thread 1) | (Thread 2)
| ax25_ds_timeout()
ax25_dev_device_down() |
ax25_ds_del_timer() |
del_timer() |
ax25_dev_put() //FREE |
| ax25_dev-> //USE
In order to mitigate bugs, when the device is detaching, use
timer_shutdown_sync() to stop the timer.2dCVE-2023-31437—27.3%
——8——CVE-2018-8754—27.3%
——8——CVE-2022-39394—27.3%
——8——CVE-2023-5377—27.3%
——8——CVE-2024-30178—27.3%
——8——CVE-2023-23427—27.3%
——8——CVE-2025-59045—27.3%
——8——CVE-2025-8344—27.3%
——8——CVE-2016-4960—27.3%
——8——CVE-2016-4634—27.3%
——8——