Vulnerabilities exploitable today
376,248in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,387
- High8,793
- Medium6,794
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-745928.1 HIG27.4%
——8In the Linux kernel, the following vulnerability has been resolved:
ima: Instantiate file_truncate and path_truncate hooks
Instantiate the file_truncate and path_truncate LSM hooks to reset the
action cache flags (IMA_DONE_MASK) as soon as truncation is requested,
so the file, based on policy, is re-collected, re-measured, re-audited,
and re-appraised on next access.23dCVE-2026-694477.8 HIG27.4%
——8Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.8dCVE-2021-25132—27.4%
——8——CVE-2024-8186—27.4%
——8——CVE-2026-539047.1 HIG27.4%
——8MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, password resets are not limited in any way. An attacker who provides victim's email and answer to their security question, can successfully initiate the reset process and continuously invalidate credentials, effectively locking the victim out of their account. Answering security questions has a limited number of tries which lowers the risk of this vulnerability.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.73dCVE-2026-694567.8 HIG27.4%
——8Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.6dCVE-2025-66550—27.4%
——8——CVE-2022-37080—27.4%
——8——CVE-2021-25135—27.4%
——8——CVE-2023-7016—27.4%
——8——CVE-2023-29733—27.4%
——8——CVE-2023-22128—27.4%
——8——CVE-2021-25136—27.4%
——8——CVE-2011-4954—27.4%
——8——CVE-2024-5419—27.4%
——8——CVE-2021-25126—27.4%
——8——CVE-2025-65942—27.4%
——8——CVE-2023-26368—27.4%
——8——CVE-2025-30575—27.4%
——8——CVE-2025-30573—27.4%
——8——CVE-2024-1565—27.4%
——8——CVE-2026-696087.8 HIG27.4%
——8Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.7dCVE-2022-37820—27.4%
——8——CVE-2021-25131—27.4%
——8——CVE-2022-37817—27.4%
——8——CVE-2021-26307—27.4%
——8——CVE-2023-35833—27.4%
——8——CVE-2026-611857.4 HIG27.4%
——8Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Product Lifecycle Management for Process executes to compromise Oracle Agile Product Lifecycle Management for Process. While the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).43dCVE-2013-5191—27.4%
——8——CVE-2023-38423—27.4%
——8——CVE-2024-6705—27.4%
——8——CVE-2023-23954—27.4%
——8——CVE-2022-37084—27.4%
——8——CVE-2025-8171—27.4%
——8——CVE-2023-22121—27.4%
——8——CVE-2024-5219—27.4%
——8——CVE-2026-42088—27.4%
——8——CVE-2024-32674—27.4%
——8——CVE-2025-30527—27.4%
——8——CVE-2026-21630—27.4%
——8——