Vulnerabilities exploitable today
372,253in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,277
- High8,394
- Medium6,440
- Low634
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18249—23.1%
——7——CVE-2026-562984.3 MED23.1%
——7Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location information and other embedded metadata from uploaded files.65dCVE-2008-1692—23.1%
——7——CVE-2024-56298—23.1%
——7——CVE-2017-12709—23.1%
——7——CVE-2024-36992—23.1%
——7——CVE-2025-24532—23.1%
——7——CVE-2025-48446—23.1%
——7——CVE-2024-35144—23.1%
——7——CVE-2023-4681—23.1%
——7——CVE-2024-20089—23.1%
——7——CVE-2024-25359—23.1%
——7——CVE-2026-145259.4 CRI23.1%
——7IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.25dCVE-2025-32240—23.1%
——7——CVE-2025-40681—23.1%
——7——CVE-2024-57337—23.1%
——7——CVE-2025-26482—23.1%
——7——CVE-2025-63384—23.1%
——7——CVE-2026-44556—23.1%
——7——CVE-2025-3661—23.1%
——7——CVE-2026-655547.1 HIG23.1%
——7Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.30dCVE-2020-7945—23.1%
——7——CVE-2023-30959—23.1%
——7——CVE-2026-56319—23.1%
——7——CVE-2020-16097—23.1%
——7——CVE-2024-54049—23.1%
——7——CVE-2024-343356.1 MED23.1%
——7ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.68dCVE-2025-49590—23.1%
——7——CVE-2024-22387—23.1%
——7——CVE-2025-13090—23.1%
——7——CVE-2024-9149—23.1%
——7——CVE-2024-9866—23.1%
——7——CVE-2025-218097.5 HIG23.1%
——7In the Linux kernel, the following vulnerability has been resolved:
rxrpc, afs: Fix peer hash locking vs RCU callback
In its address list, afs now retains pointers to and refs on one or more
rxrpc_peer objects. The address list is freed under RCU and at this time,
it puts the refs on those peers.
Now, when an rxrpc_peer object runs out of refs, it gets removed from the
peer hash table and, for that, rxrpc has to take a spinlock. However, it
is now being called from afs's RCU cleanup, which takes place in BH
context - but it is just taking an ordinary spinlock.
The put may also be called from non-BH context, and so there exists the
possibility of deadlock if the BH-based RCU cleanup happens whilst the hash
spinlock is held. This led to the attached lockdep complaint.
Fix this by changing spinlocks of rxnet->peer_hash_lock back to
BH-disabling locks.
================================
WARNING: inconsistent lock state
6.13.0-rc5-build2+ #1223 Tainted: G E
--------------------------------
inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.
swapper/1/0 [HC0[0]:SC1[1]:HE1:SE0] takes:
ffff88810babe228 (&rxnet->peer_hash_lock){+.?.}-{3:3}, at: rxrpc_put_peer+0xcb/0x180
{SOFTIRQ-ON-W} state was registered at:
mark_usage+0x164/0x180
__lock_acquire+0x544/0x990
lock_acquire.part.0+0x103/0x280
_raw_spin_lock+0x2f/0x40
rxrpc_peer_keepalive_worker+0x144/0x440
process_one_work+0x486/0x7c0
process_scheduled_works+0x73/0x90
worker_thread+0x1c8/0x2a0
kthread+0x19b/0x1b0
ret_from_fork+0x24/0x40
ret_from_fork_asm+0x1a/0x30
irq event stamp: 972402
hardirqs last enabled at (972402): [<ffffffff8244360e>] _raw_spin_unlock_irqrestore+0x2e/0x50
hardirqs last disabled at (972401): [<ffffffff82443328>] _raw_spin_lock_irqsave+0x18/0x60
softirqs last enabled at (972300): [<ffffffff810ffbbe>] handle_softirqs+0x3ee/0x430
softirqs last disabled at (972313): [<ffffffff810ffc54>] __irq_exit_rcu+0x44/0x110
other info that might help us debug this:
Possible unsafe locking scenario:
CPU0
----
lock(&rxnet->peer_hash_lock);
<Interrupt>
lock(&rxnet->peer_hash_lock);
*** DEADLOCK ***
1 lock held by swapper/1/0:
#0: ffffffff83576be0 (rcu_callback){....}-{0:0}, at: rcu_lock_acquire+0x7/0x30
stack backtrace:
CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Tainted: G E 6.13.0-rc5-build2+ #1223
Tainted: [E]=UNSIGNED_MODULE
Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014
Call Trace:
<IRQ>
dump_stack_lvl+0x57/0x80
print_usage_bug.part.0+0x227/0x240
valid_state+0x53/0x70
mark_lock_irq+0xa5/0x2f0
mark_lock+0xf7/0x170
mark_usage+0xe1/0x180
__lock_acquire+0x544/0x990
lock_acquire.part.0+0x103/0x280
_raw_spin_lock+0x2f/0x40
rxrpc_put_peer+0xcb/0x180
afs_free_addrlist+0x46/0x90 [kafs]
rcu_do_batch+0x2d2/0x640
rcu_core+0x2f7/0x350
handle_softirqs+0x1ee/0x430
__irq_exit_rcu+0x44/0x110
irq_exit_rcu+0xa/0x30
sysvec_apic_timer_interrupt+0x7f/0xa0
</IRQ>43dCVE-2004-0404—23.1%
——7——CVE-2026-281918.8 HIG23.1%
——7Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation.
This issue affects The Grid: from n/a through 2.8.0.10dCVE-2024-56297—23.1%
——7——CVE-2025-6786—23.1%
——7——CVE-2023-48285—23.1%
——7——CVE-2026-26022—23.1%
——7——CVE-2026-7638—23.1%
——7——