Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-4014—26.3%
——8——CVE-2026-3912—26.3%
——8——CVE-2023-5121—26.3%
——8——CVE-2022-33316—26.3%
——8——CVE-2024-11019—26.3%
——8——CVE-2022-42376—26.2%
——8——CVE-2017-6252—26.2%
——8——CVE-2022-42413—26.2%
——8——CVE-2026-42400—26.2%
——8——CVE-2011-3539—26.2%
——8——CVE-2023-26340—26.2%
——8——CVE-2024-39838—26.2%
——8——CVE-2020-26941—26.2%
——8——CVE-2006-4619—26.2%
——8——CVE-2023-26345—26.2%
——8——CVE-2023-25867—26.2%
——8——CVE-2017-0323—26.2%
——8——CVE-2026-42399—26.2%
——8——CVE-2017-0348—26.2%
——8——CVE-2023-26352—26.2%
——8——CVE-2024-5922—26.2%
——8——CVE-2026-734305.3 MED26.2%
——8Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte all-zero Q_C value. Curve25519Kex::server_dh in russh/src/kex/curve25519.rs accepts the all-zero peer public value and computes an all-zero shared secret, after which compute_exchange_hash calls encode_mpint in russh/src/kex/mod.rs and indexes beyond the end of the input while skipping leading zero bytes. The resulting panic occurs before authentication and terminates the server key-exchange task. This issue is fixed in version 0.62.4.6dCVE-2023-26354—26.2%
——8——CVE-2025-385718.2 HIG26.2%
——8In the Linux kernel, the following vulnerability has been resolved:
sunrpc: fix client side handling of tls alerts
A security exploit was discovered in NFS over TLS in tls_alert_recv
due to its assumption that there is valid data in the msghdr's
iterator's kvec.
Instead, this patch proposes the rework how control messages are
setup and used by sock_recvmsg().
If no control message structure is setup, kTLS layer will read and
process TLS data record types. As soon as it encounters a TLS control
message, it would return an error. At that point, NFS can setup a kvec
backed control buffer and read in the control message such as a TLS
alert. Scott found that a msg iterator can advance the kvec pointer
as a part of the copy process thus we need to revert the iterator
before calling into the tls_alert_recv.48dCVE-2026-490896.5 MED26.2%
——8Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.13dCVE-2023-5553—26.2%
——8——CVE-2026-573776.5 MED26.2%
——8Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.64dCVE-2017-6253—26.2%
——8——CVE-2022-42411—26.2%
——8——CVE-2025-44013—26.2%
——8——CVE-2023-26338—26.2%
——8——CVE-2026-464636.5 MED26.2%
——8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.69dCVE-2022-43039—26.2%
——8——CVE-2025-66911—26.2%
——8——CVE-2017-0341—26.2%
——8——CVE-2023-43037—26.2%
——8——CVE-2026-40766—26.2%
——8——CVE-2017-0347—26.2%
——8——CVE-2026-281688.5 HIG26.2%
——8Subscriber SQL Injection in CubeWP <= 1.1.30 versions.32dCVE-2025-2606—26.2%
——8——