Vulnerabilities exploitable today
372,967in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,231
- High8,251
- Medium6,234
- Low615
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-6732—24.0%
——7——CVE-2022-488308.8 HIG24.0%
——7In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix potential CAN frame reception race in isotp_rcv()
When receiving a CAN frame the current code logic does not consider
concurrently receiving processes which do not show up in real world
usage.
Ziyang Xuan writes:
The following syz problem is one of the scenarios. so->rx.len is
changed by isotp_rcv_ff() during isotp_rcv_cf(), so->rx.len equals
0 before alloc_skb() and equals 4096 after alloc_skb(). That will
trigger skb_over_panic() in skb_put().
=======================================================
CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc8-syzkaller #0
RIP: 0010:skb_panic+0x16c/0x16e net/core/skbuff.c:113
Call Trace:
<TASK>
skb_over_panic net/core/skbuff.c:118 [inline]
skb_put.cold+0x24/0x24 net/core/skbuff.c:1990
isotp_rcv_cf net/can/isotp.c:570 [inline]
isotp_rcv+0xa38/0x1e30 net/can/isotp.c:668
deliver net/can/af_can.c:574 [inline]
can_rcv_filter+0x445/0x8d0 net/can/af_can.c:635
can_receive+0x31d/0x580 net/can/af_can.c:665
can_rcv+0x120/0x1c0 net/can/af_can.c:696
__netif_receive_skb_one_core+0x114/0x180 net/core/dev.c:5465
__netif_receive_skb+0x24/0x1b0 net/core/dev.c:5579
Therefore we make sure the state changes and data structures stay
consistent at CAN frame reception time by adding a spin_lock in
isotp_rcv(). This fixes the issue reported by syzkaller but does not
affect real world operation.39dCVE-2024-11910—24.0%
——7——CVE-2026-822087.5 HIG24.0%
——7With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.12hCVE-2026-865448.1 HIG24.0%
——7knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.3dCVE-2024-47853—24.0%
——7——CVE-2002-2412—24.0%
——7——CVE-2023-27437—24.0%
——7——CVE-2026-12060—24.0%
——7——CVE-2024-39967—24.0%
——7——CVE-2025-27680—23.9%
——7——CVE-2024-36234—24.0%
——7——CVE-2020-0567—24.0%
——7——CVE-2024-37159—24.0%
——7——CVE-2024-32802—24.0%
——7——CVE-2023-38072—24.0%
——7——CVE-2024-57513—24.0%
——7——CVE-2023-6597—24.0%
——7——CVE-2026-874423.1 LOW23.9%
——7Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2026-190627.3 HIG24.0%
——7A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.30dCVE-2024-36229—24.0%
——7——CVE-2008-2794—24.0%
——7——CVE-2024-7939—24.0%
——7——CVE-2020-8335—24.0%
——7——CVE-2020-7544—24.0%
——7——CVE-2025-148137.5 HIG24.0%
——7: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).
This vulnerability is associated with program files G3413CTRBlockCipher.
This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.19hCVE-2024-5868—24.0%
——7——CVE-2024-36232—24.0%
——7——CVE-2023-4383—24.0%
——7——CVE-2022-0402—24.0%
——7——CVE-2020-37156—24.0%
——7——CVE-2024-33641—24.0%
——7——CVE-2023-21592—24.0%
——7——CVE-2024-38834—24.0%
——7——CVE-2023-21577—24.0%
——7——CVE-2026-2556—24.0%
——7——CVE-2020-0511—24.0%
——7——CVE-2026-56257—24.0%
——7——CVE-2026-27652—24.0%
——7——CVE-2023-29196—24.0%
——7——