Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22195—25.3%
——8——CVE-2026-27740—25.3%
——8——CVE-2025-6168—25.3%
——8——CVE-2010-2022—25.3%
——8——CVE-2026-40618—25.3%
——8——CVE-2025-562006.1 MED25.3%
——8A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use ':' as the delimiter. This parsing difference allows attackers to bypass protocol and domain validation by crafting URLs leading to XSS and Open Redirect attacks.72dCVE-2026-454768.2 HIG25.3%
——8Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.54dCVE-2025-50465—25.3%
——8——CVE-2025-55036—25.3%
——8——CVE-2023-43523—25.3%
——8——CVE-2023-33057—25.3%
——8——CVE-2026-40256—25.3%
——8——CVE-2025-15069—25.3%
——8——CVE-2021-476208.1 HIG25.3%
——8In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: refactor malicious adv data check
Check for out-of-bound read was being performed at the end of while
num_reports loop, and would fill journal with false positives. Added
check to beginning of loop processing so that it doesn't get checked
after ptr has been advanced.42dCVE-2025-46334—25.3%
——8——CVE-2025-29992—25.3%
——8——CVE-2023-49746—25.3%
——8——CVE-2026-22196—25.3%
——8——CVE-2026-44378—25.3%
——8——CVE-2023-24843—25.3%
——8——CVE-2023-33099—25.3%
——8——CVE-2024-45292—25.3%
——8——CVE-2026-20001—25.3%
——8——CVE-2023-34363—25.3%
——8——CVE-2025-59781—25.3%
——8——CVE-2026-34559—25.3%
——8——CVE-2022-40228—25.3%
——8——CVE-2021-0105—25.3%
——8——CVE-2025-5384—25.3%
——8——CVE-2024-21600—25.3%
——8——CVE-2014-2488—25.3%
——8——CVE-2022-500988.8 HIG25.3%
——8In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts
Ensure SRB is returned during I/O timeout error escalation. If that is not
possible fail the escalation path.
Following crash stack was seen:
BUG: unable to handle kernel paging request at 0000002f56aa90f8
IP: qla_chk_edif_rx_sa_delete_pending+0x14/0x30 [qla2xxx]
Call Trace:
? qla2x00_status_entry+0x19f/0x1c50 [qla2xxx]
? qla2x00_start_sp+0x116/0x1170 [qla2xxx]
? dma_pool_alloc+0x1d6/0x210
? mempool_alloc+0x54/0x130
? qla24xx_process_response_queue+0x548/0x12b0 [qla2xxx]
? qla_do_work+0x2d/0x40 [qla2xxx]
? process_one_work+0x14c/0x39042dCVE-2026-8076—25.3%
——8——CVE-2025-58120—25.3%
——8——CVE-2025-58096—25.3%
——8——CVE-2025-53474—25.3%
——8——CVE-2025-61990—25.3%
——8——CVE-2020-5363—25.3%
——8——CVE-2025-5386—25.3%
——8——CVE-2025-61960—25.3%
——8——