Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-13493—25.1%
——8——CVE-2026-187338.8 HIG25.1%
——8A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate.
To remediate this issue, users should upgrade to version 0.8.0.42dCVE-2024-579958.8 HIG25.1%
——8In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev()
In ath12k_mac_assign_vif_to_vdev(), if arvif is created on a different
radio, it gets deleted from that radio through a call to
ath12k_mac_unassign_link_vif(). This action frees the arvif pointer.
Subsequently, there is a check involving arvif, which will result in a
read-after-free scenario.
Fix this by moving this check after arvif is again assigned via call to
ath12k_mac_assign_link_vif().
Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-142dCVE-2018-11448—25.1%
——8——CVE-2025-51458—25.1%
——8——CVE-2025-136017.7 HIG25.1%
——8A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.15dCVE-2026-781227.4 HIG25.1%
——8docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.20dCVE-2023-49223—25.1%
——8——CVE-2026-11357—25.1%
——8——CVE-2023-30517—25.1%
——8——CVE-2023-3509—25.1%
——8——CVE-2024-9724—25.1%
——8——CVE-2025-13842—25.1%
——8——CVE-2024-7611—25.1%
——8——CVE-2016-4980—25.1%
——8——CVE-2018-18398—25.1%
——8——CVE-2020-37209—25.1%
——8——CVE-2026-22560—25.1%
——8——CVE-2025-43758—25.1%
——8——CVE-2009-3706—25.1%
——8——CVE-2026-66827.6 HIG25.1%
——8In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). Remote delivery is also possible in OTA/update pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.75dCVE-2024-30481—25.1%
——8——CVE-2009-4193—25.1%
——8——CVE-2020-8575—25.1%
——8——CVE-2016-9356—25.1%
——8——CVE-2014-0378—25.1%
——8——CVE-2026-78446.3 MED25.1%
——8A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File Service. The manipulation results in missing authentication. The attacker must have access to the local network to execute the attack. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.53dCVE-2017-0311—25.1%
——8——CVE-2024-5041—25.1%
——8——CVE-2024-29095—25.1%
——8——CVE-2024-4375—25.1%
——8——CVE-2023-22119—25.1%
——8——CVE-2026-4662—25.1%
——8——CVE-2016-7759—25.1%
——8——CVE-2026-66887.6 HIG25.1%
——8FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname can be up to 255 characters; many callers copy it into short fixed buffers without bounds checks, causing overflow. This maps to CWE-120 (Buffer Copy without Checking Size of Input). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.75dCVE-2024-4470—25.1%
——8——CVE-2022-1789—25.1%
——8——CVE-2024-2618—25.1%
——8——CVE-2026-32055—25.1%
——8——CVE-2025-66371—25.1%
——8——