Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,428
- Medium6,470
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-571655.3 MED26.7%
——8PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_up_down() in cli_telnet.c). This affects only applications that enable the telnet CLI front-end (same gating as the related CLI issue). The line-redraw sequence for a recalled history entry can accumulate more data than a fixed-size stack buffer holds, which may lead to application termination. Exploitation requires access to the unauthenticated telnet CLI, which already permits arbitrary CLI commands, so the additional impact is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 628b716.4dCVE-2025-24228—26.7%
——8——CVE-2026-163959.8 CRI26.7%
——8Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.55dCVE-2026-854339.8 CRI26.7%
——8MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.2dCVE-2026-12471—26.7%
——8——CVE-2026-6305—26.7%
——8——CVE-2024-35659—26.7%
——8——CVE-2025-53516—26.7%
——8——CVE-2014-0748—26.7%
——8——CVE-2026-554317.7 HIG26.7%
——8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler. Practical exploitation requires the victim to run `coder open app` against a workspace whose external app definition the attacker controls. Only a malicious template author can control external app URLs. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 applies a URL-scheme allowlist in the CLI and limits `$SESSION_TOKEN` substitution to trusted destinations like the web frontend. As a workaround, avoid running `coder open app` for untrusted workspaces.69dCVE-2023-38486—26.7%
——8——CVE-2026-354097.7 HIG26.7%
——8Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block requests to local and private networks could be circumvented using IPv4-Mapped IPv6 address notation. This vulnerability is fixed in 11.16.0.53dCVE-2026-44916—26.7%
——8——CVE-2026-321938.8 HIG26.7%
——8Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.55dCVE-2025-64471—26.7%
——8——CVE-2021-21790—26.7%
——8——CVE-2020-8738—26.7%
——8——CVE-2024-35729—26.7%
——8——CVE-2026-781355.6 MED26.7%
——8libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.12hCVE-2022-32815—26.7%
——8——CVE-2022-35206—26.7%
——8——CVE-2022-38861—26.7%
——8——CVE-2024-7390—26.7%
——8——CVE-2025-44000—26.7%
——8——CVE-2025-32210—26.7%
——8——CVE-2021-34119—26.7%
——8——CVE-2025-14360—26.7%
——8——CVE-2019-14611—26.7%
——8——CVE-2024-23501—26.7%
——8——CVE-2025-29494—26.7%
——8——CVE-2026-24497—26.7%
——8——CVE-2024-31246—26.7%
——8——CVE-2026-2073—26.7%
——8——CVE-2025-29497—26.7%
——8——CVE-2026-2115—26.7%
——8——CVE-2014-9529—26.7%
——8——CVE-2019-3741—26.7%
——8——CVE-2019-0029—26.7%
——8——CVE-2026-2132—26.7%
——8——CVE-2025-22752—26.7%
——8——