Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-28718—27.0%
——8——CVE-2025-32991—27.0%
——8——CVE-2026-52690—27.0%
——8——CVE-2022-34998—27.0%
——8——CVE-2024-12384—27.0%
——8——CVE-2026-22257—27.0%
——8——CVE-2026-728204.9 MED27.0%
——8Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.7dCVE-2024-6493—27.0%
——8——CVE-2022-38228—27.0%
——8——CVE-2024-11723—27.0%
——8——CVE-2025-49876—27.0%
——8——CVE-2024-13466—27.0%
——8——CVE-2023-21884—27.0%
——8——CVE-2024-0437—27.0%
——8——CVE-2023-543907.5 HIG27.0%
——8PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server.7dCVE-2024-3624—27.0%
——8——CVE-2024-7243—27.0%
——8——CVE-2025-14322—27.0%
——8——CVE-2008-5144—27.0%
——8——CVE-2026-551705.4 MED27.0%
——8OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and user:alice as equivalent, causing two distinct check requests to return the same response. This issue is fixed in 1.18.0.64dCVE-2022-38238—27.0%
——8——CVE-2022-36142—27.0%
——8——CVE-2023-4654—27.0%
——8——CVE-2024-53096—27.0%
——8——CVE-2024-34753—27.0%
——8——CVE-2025-70034—27.0%
——8——CVE-2026-26828—27.0%
——8——CVE-2024-6850—27.0%
——8——CVE-2026-855057.5 HIG27.0%
——8ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).7dCVE-2023-44090—27.0%
——8——CVE-2026-33614—27.0%
——8——CVE-2023-24547—27.0%
——8——CVE-2026-33616—27.0%
——8——CVE-2026-848517.5 HIG27.0%
——8An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.13dCVE-2025-219007.5 HIG27.0%
——8In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a deadlock when recovering state on a sillyrenamed file
If the file is sillyrenamed, and slated for delete on close, it is
possible for a server reboot to triggeer an open reclaim, with can again
race with the application call to close(). When that happens, the call
to put_nfs_open_context() can trigger a synchronous delegreturn call
which deadlocks because it is not marked as privileged.
Instead, ensure that the call to nfs4_inode_return_delegation_on_close()
catches the delegreturn, and schedules it asynchronously.48dCVE-2026-558065.9 MED27.0%
——8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.62dCVE-2024-53706—27.0%
——8——CVE-2023-42842—27.0%
——8——CVE-2026-732248.8 HIG27.0%
——8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/components/sftp/file-info-modal.jsx inserts the server-controlled folder name into a du -sh shell command without safely escaping single quotes. This issue is fixed in version 3.15.120.6dCVE-2026-862017.5 HIG27.0%
——8PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.2d