Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32127—25.6%
——8——CVE-2024-39126—25.6%
——8——CVE-2026-35167—25.6%
——8——CVE-2025-633976.5 MED25.6%
——8Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.73dCVE-2019-1734—25.6%
——8——CVE-2025-10867—25.6%
——8——CVE-2021-0642—25.6%
——8——CVE-2026-28119—25.6%
——8——CVE-2025-41418—25.6%
——8——CVE-2017-2665—25.6%
——8——CVE-2026-28121—25.6%
——8——CVE-2021-47909—25.6%
——8——CVE-2021-320849.8 CRI25.6%
——8An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.43dCVE-2018-4388—25.6%
——8——CVE-2026-28129—25.6%
——8——CVE-2024-11601—25.6%
——8——CVE-2023-5586—25.6%
——8——CVE-2026-11832—25.6%
——8——CVE-2025-1920—25.6%
——8——CVE-2024-12267—25.6%
——8——CVE-2024-39550—25.6%
——8——CVE-2025-48958—25.6%
——8——CVE-2026-22377—25.6%
——8——CVE-2019-19335—25.6%
——8——CVE-2026-54816—25.6%
——8——CVE-2010-2224—25.6%
——8——CVE-2026-49865—25.6%
——8Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side PDF renderer will fetch remote image URLs embedded in Markdown image syntax. This allows the application server to issue outbound requests to attacker-controlled or internal targets during PDF rendering. The behavior can be used for internal network probing, server-side reachability checks, and potentially follow-on exploitation depending on deployment environment and accessible internal services. Version 2.58.0 patches the issue.20hCVE-2025-66370—25.6%
——8——CVE-2024-566518.8 HIG25.6%
——8In the Linux kernel, the following vulnerability has been resolved:
can: hi311x: hi3110_can_ist(): fix potential use-after-free
The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr
during bus-off") removed the reporting of rxerr and txerr even in case
of correct operation (i. e. not bus-off).
The error count information added to the CAN frame after netif_rx() is
a potential use after free, since there is no guarantee that the skb
is in the same state. It might be freed or reused.
Fix the issue by postponing the netif_rx() call in case of txerr and
rxerr reporting.42dCVE-2026-22381—25.6%
——8——CVE-2026-28124—25.6%
——8——CVE-2026-53698—25.6%
——8——CVE-2022-23449—25.6%
——8——CVE-2024-33018—25.6%
——8——CVE-2019-257406.5 MED25.6%
——8Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbitrary files accessible to the web server.55dCVE-2025-50466—25.6%
——8——CVE-2026-843656.5 MED25.6%
——8Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments. Static site generation builds each output path from the route path and values supplied through ssgParams, then verifies that the result stays inside the output directory using the same normalization routine that built the path. That routine does not fully collapse runs of consecutive parent-directory segments, allowing a path that the check accepts to resolve outside the output directory, and the check also treats output directories that differ in how they are rooted as equivalent. This arises when an application generates a static site from route parameter values it does not fully control, such as slugs from a CMS, API, or user submission. An untrusted ssgParams value can create or overwrite files elsewhere in the build environment and alter generated artifacts or deployment output. The vulnerability affects build-time static site generation only; request-time routing and applications with entirely developer-controlled ssgParams values are not affected. This issue is fixed in version 4.13.5.12dCVE-2024-30952—25.6%
——8——CVE-2026-889386.5 MED25.6%
——8knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.4dCVE-2026-28125—25.6%
——8——