Vulnerabilities exploitable today
373,010in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,219
- High8,127
- Medium6,187
- Low611
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2001-0887—24.4%
——7——CVE-2026-539057.1 HIG24.4%
——7MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks.
This may expose sensitive permission mappings and internal configuration details.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.68dCVE-2024-3873—24.4%
——7——CVE-2024-8726—24.4%
——7——CVE-2024-12211—24.4%
——7——CVE-2024-22158—24.4%
——7——CVE-2023-1644—24.4%
——7——CVE-2000-0029—24.4%
——7——CVE-2001-0141—24.4%
——7——CVE-2014-8527—24.4%
——7——CVE-2022-40184—24.4%
——7——CVE-2001-1276—24.4%
——7——CVE-2016-5849—24.4%
——7——CVE-2025-10762—24.4%
——7——CVE-2024-49694—24.4%
——7——CVE-2023-1627—24.4%
——7——CVE-2024-24836—24.4%
——7——CVE-2001-1353—24.4%
——7——CVE-2015-0664—24.4%
——7——CVE-2026-45375—24.4%
——7——CVE-2024-38674—24.4%
——7——CVE-2024-43260—24.4%
——7——CVE-2008-5299—24.4%
——7——CVE-2024-25598—24.4%
——7——CVE-2017-2330—24.4%
——7——CVE-2025-3601—24.4%
——7——CVE-2023-1493—24.4%
——7——CVE-2024-6713—24.4%
——7——CVE-2024-3996—24.4%
——7——CVE-2026-639748.8 HIG24.4%
——7In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
Since hci_dev_close_sync() can now be called during the reset path, we
should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts
while the hdev workqueue is being drained.44dCVE-2014-8532—24.4%
——7——CVE-1999-0731—24.4%
——7——CVE-2026-33035—24.4%
——7——CVE-2015-4996—24.4%
——7——CVE-2026-490918.0 HIG24.4%
——7Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.72dCVE-2024-6665—24.4%
——7——CVE-2026-706574.3 MED24.4%
——7Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.24dCVE-2022-2961—24.4%
——7——CVE-2023-50875—24.4%
——7——CVE-2026-581598.2 HIG24.4%
——7Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.40d