Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,230
- High8,254
- Medium6,232
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1667—23.7%
——7——CVE-2022-35085—23.7%
——7——CVE-2023-42912—23.7%
——7——CVE-2023-42905—23.7%
——7——CVE-2000-0722—23.7%
——7——CVE-2023-28492—23.7%
——7——CVE-2023-42901—23.7%
——7——CVE-2025-11519—23.7%
——7——CVE-2025-49458—23.7%
——7——CVE-2023-52094—23.7%
——7——CVE-2026-558556.5 MED23.7%
——7MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client character sets. PacketOutputStream.writeBufferEscape in lib/io/packet-output-stream.js escaped bytes without the charset-aware getMbRecognizer logic in lib/misc/charset-mb.js. The server SQL lexer runs my_ismbchar before escape processing, so an attacker-controlled lead byte can consume the inserted 0x5C backslash as a multibyte trail byte and leave the following 0x27 quote unescaped, terminating the string literal and allowing arbitrary SQL. The default utf8mb4 character set and parameters sent through the execute binary prepared-statement path are not affected. Successful exploitation can expose or modify data available to the database account. This issue is fixed in versions 3.2.4, 3.3.3, 3.4.6, and 3.5.3.3dCVE-2026-537926.5 MED23.7%
——7rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side.3dCVE-2023-52092—23.7%
——7——CVE-2023-42911—23.7%
——7——CVE-2026-25366—23.7%
——7——CVE-2026-839827.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2026-659766.5 MED23.7%
——7Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in src/lib/server/ClientProxy1_6.cpp or client path in src/lib/client/ServerProxy.cpp to append data beyond the DataStart declared size and configured clipboard limit before DataEnd validation, exhausting receiver memory. This issue is fixed in continuous build 1.26.0.300.2dCVE-2013-5493—23.7%
——7——CVE-2023-4161—23.7%
——7——CVE-2023-42908—23.7%
——7——CVE-2026-185347.4 HIG23.7%
——7ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.8dCVE-2024-41687—23.7%
——7——CVE-2025-42603—23.7%
——7——CVE-2025-21162—23.7%
——7——CVE-2025-52337—23.7%
——7——CVE-2026-537985.3 MED23.7%
——7rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.11dCVE-2026-3921—23.7%
——7——CVE-2026-839757.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2020-25243—23.7%
——7——CVE-2021-22563—23.7%
——7——CVE-2021-22564—23.7%
——7——CVE-2025-11421—23.7%
——7——CVE-2011-1658—23.6%
——7——CVE-2023-52091—23.7%
——7——CVE-2026-39870—23.7%
——7——CVE-2023-42909—23.7%
——7——CVE-2023-43090—23.7%
——7——CVE-2026-839727.8 HIG23.7%
——7Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.2dCVE-2023-42903—23.7%
——7——CVE-2023-52090—23.7%
——7——