Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,437
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-758427.7 HIG27.3%
——8ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges, exfiltrating sensitive data directly in query responses.8dCVE-2026-694567.8 HIG27.3%
——8Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.5dCVE-2013-5191—27.3%
——8——CVE-2022-37822—27.3%
——8——CVE-2023-35833—27.3%
——8——CVE-2021-25134—27.3%
——8——CVE-2024-32674—27.3%
——8——CVE-2021-25131—27.3%
——8——CVE-2025-30789—27.3%
——8——CVE-2025-30573—27.3%
——8——CVE-2023-23954—27.3%
——8——CVE-2025-65942—27.3%
——8——CVE-2023-22121—27.3%
——8——CVE-2021-25132—27.3%
——8——CVE-2025-66550—27.3%
——8——CVE-2021-25126—27.3%
——8——CVE-2026-67173—27.3%
——8Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able to supply crafted graph data could set an image path to a malicious URI.
When a victim rendered the affected graph, the browser could resolve the attacker-controlled URI and initiate an unintended request or invoke scheme-specific handling in the victim’s context. Depending on the URI, browser behaviour, and installed protocol handlers, exploitation could disclose limited client or network metadata, facilitate rendering-based tracking, or attempt to access local or internal resources.
Exploitation requires a victim to load or render graph data containing the malicious imagePath. The patch normalizes ASCII whitespace and control characters in URI schemes and restricts image paths to relative URLs or the http, https, data, and blob schemes.48dCVE-2024-8186—27.3%
——8——CVE-2021-25135—27.3%
——8——CVE-2023-22128—27.3%
——8——CVE-2026-745928.1 HIG27.3%
——8In the Linux kernel, the following vulnerability has been resolved:
ima: Instantiate file_truncate and path_truncate hooks
Instantiate the file_truncate and path_truncate LSM hooks to reset the
action cache flags (IMA_DONE_MASK) as soon as truncation is requested,
so the file, based on policy, is re-collected, re-measured, re-audited,
and re-appraised on next access.22dCVE-2026-800937.0 HIG27.3%
——8Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.6dCVE-2026-694477.8 HIG27.3%
——8Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.7dCVE-2021-25136—27.3%
——8——CVE-2026-6316—27.3%
——8——CVE-2024-6551—27.3%
——8——CVE-2025-30799—27.3%
——8——CVE-2024-33940—27.3%
——8——CVE-2026-20806—27.3%
——8——CVE-2026-9508—27.3%
——8Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This exposes highly sensitive information that can lead to server impersonation, unauthorized access to databases, and lateral movement.57dCVE-2023-1899—27.3%
——8——CVE-2024-38470—27.3%
——8——CVE-2025-2673—27.3%
——8——CVE-2023-35912—27.3%
——8——CVE-2024-52590—27.3%
——8——CVE-2024-45313—27.3%
——8——CVE-2024-13809—27.3%
——8——CVE-2024-13368—27.3%
——8——CVE-2025-8904—27.3%
——8——CVE-2024-533645.4 MED27.3%
——8A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.73d