Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,221
- High8,140
- Medium6,165
- Low607
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9077—22.8%
——7——CVE-2020-8027—22.8%
——7——CVE-2025-43589—22.8%
——7——CVE-2026-476567.9 HIG22.8%
——7Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.50dCVE-2021-30811—22.8%
——7——CVE-2023-49807—22.8%
——7——CVE-2025-39496—22.8%
——7——CVE-2023-49343—22.8%
——7——CVE-2023-49345—22.8%
——7——CVE-2025-21520—22.8%
——7——CVE-2025-5523—22.8%
——7——CVE-2023-49346—22.8%
——7——CVE-2023-49598—22.8%
——7——CVE-2026-42155—22.8%
——7——CVE-2025-10968—22.8%
——7——CVE-2026-332345.0 MED22.8%
——7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution block inputs, then passes them directly to Python's smtplib.SMTP() to open a raw TCP connection with no IP address validation. This completely bypasses the platform's hardened SSRF protections in backend/util/request.py — the validate_url_host() function and BLOCKED_IP_NETWORKS blocklist that every other block uses to block connections to private, loopback, link-local, and cloud metadata addresses. An authenticated user on a shared AutoGPT deployment can use this to perform non-blind internal network port scanning and service fingerprinting: smtplib reads the target's TCP banner on connect and embeds it in the exception message, which is persisted as user-visible block output via the execution framework. This issue has been fixed in version 0.6.52.48dCVE-2024-8961—22.8%
——7——CVE-2026-485687.9 HIG22.8%
——7Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.50dCVE-2026-608015.9 MED22.8%
——7Vulnerability in the Oracle E-Business Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Intelligence. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Intelligence accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Intelligence accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).38dCVE-2024-12167—22.8%
——7——CVE-2020-6021—22.8%
——7——CVE-2024-10189—22.8%
——7——CVE-2024-36257—22.8%
——7——CVE-2026-2986—22.8%
——7——CVE-2023-47731—22.8%
——7——CVE-2023-28351—22.8%
——7——CVE-2026-137748.1 HIG22.8%
——7Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)71dCVE-2026-57164—22.8%
——7PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applications that use the PJLIB-UTIL HTTP client to receive a whole response body at once (a completion callback with no incremental on_data_read callback). When growing the response buffer, an incorrect size calculation based on the server-supplied Content-Length can leave the buffer too small, causing response data to be written past the end of the allocation. A malicious or man-in-the-middle HTTP server can trigger this with a crafted response; impact may range from unexpected application termination to memory corruption. Applications that consume the response incrementally (via on_data_read), or that only connect to trusted servers, are not affected. This issue has been patched via commit 8d5956a.2dCVE-2024-45879—22.8%
——7——CVE-2026-08144.3 MED22.8%
——7The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export form submissions to excel file.47dCVE-2025-24400—22.8%
——7——CVE-2024-409707.8 HIG22.8%
——7In the Linux kernel, the following vulnerability has been resolved:
Avoid hw_desc array overrun in dw-axi-dmac
I have a use case where nr_buffers = 3 and in which each descriptor is composed by 3
segments, resulting in the DMA channel descs_allocated to be 9. Since axi_desc_put()
handles the hw_desc considering the descs_allocated, this scenario would result in a
kernel panic (hw_desc array will be overrun).
To fix this, the proposal is to add a new member to the axi_dma_desc structure,
where we keep the number of allocated hw_descs (axi_desc_alloc()) and use it in
axi_desc_put() to handle the hw_desc array correctly.
Additionally I propose to remove the axi_chan_start_first_queued() call after completing
the transfer, since it was identified that unbalance can occur (started descriptors can
be interrupted and transfer ignored due to DMA channel not being enabled).37dCVE-2016-5340—22.8%
——7——CVE-2023-25862—22.8%
——7——CVE-2020-24451—22.8%
——7——CVE-2026-48943—22.8%
——7——CVE-2022-22253—22.8%
——7——CVE-2024-58301—22.8%
——7——CVE-2026-57338.8 HIG22.8%
——7Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.58dCVE-2024-12566—22.8%
——7——