Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-41002—25.1%
——8——CVE-2026-819477.8 HIG25.1%
——8Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6dCVE-2025-1481—25.1%
——8——CVE-2026-41185—25.1%
——8——CVE-2019-7293—25.1%
——8——CVE-2026-114675.4 MED25.1%
——8A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the argument fileName leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.54dCVE-2024-223475.9 MED25.1%
——8IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.50dCVE-2024-33640—25.1%
——8——CVE-2024-213557.0 HIG25.1%
——8Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability36dCVE-2024-50355—25.1%
——8——CVE-2025-14405—25.1%
——8——CVE-2021-4456—25.1%
——8——CVE-2024-359158.8 HIG25.1%
——8In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: Fix uninit-value in nci_dev_up and nci_ntf_packet
syzbot reported the following uninit-value access issue [1][2]:
nci_rx_work() parses and processes received packet. When the payload
length is zero, each message type handler reads uninitialized payload
and KMSAN detects this issue. The receipt of a packet with a zero-size
payload is considered unexpected, and therefore, such packets should be
silently discarded.
This patch resolved this issue by checking payload size before calling
each message type handler codes.42dCVE-2026-3327—25.1%
——8——CVE-2017-12261—25.1%
——8——CVE-2024-5220—25.1%
——8——CVE-2025-13842—25.1%
——8——CVE-2020-36765—25.1%
——8——CVE-2025-22143—25.1%
——8——CVE-2026-4662—25.1%
——8——CVE-2026-66887.6 HIG25.1%
——8FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname can be up to 255 characters; many callers copy it into short fixed buffers without bounds checks, causing overflow. This maps to CWE-120 (Buffer Copy without Checking Size of Input). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.75dCVE-2022-34757—25.1%
——8——CVE-2016-7759—25.1%
——8——CVE-2023-38472—25.1%
——8——CVE-2023-38470—25.1%
——8——CVE-2024-8964—25.1%
——8——CVE-2024-3298—25.1%
——8——CVE-2025-61911—25.1%
——8——CVE-2022-40979—25.1%
——8——CVE-2024-6346—25.1%
——8——CVE-2025-43344—25.1%
——8——CVE-2024-32163—25.1%
——8——CVE-2025-53512—25.1%
——8——CVE-2024-4045—25.1%
——8——CVE-2024-3557—25.1%
——8——CVE-2025-59241—25.1%
——8——CVE-2024-2455—25.1%
——8——CVE-2023-38473—25.1%
——8——CVE-2026-16286—25.1%
——8——CVE-2026-12360—25.1%
——8——