Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,235
- High8,293
- Medium6,321
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32722—22.7%
——7——CVE-2026-22469—22.7%
——7——CVE-2024-6618—22.7%
——7——CVE-2025-64348—22.7%
——7——CVE-2025-9910—22.7%
——7——CVE-2009-3611—22.7%
——7——CVE-2026-853787.3 HIG22.7%
——7A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.6dCVE-2008-4416—22.7%
——7——CVE-2026-39886—22.7%
——7——CVE-2011-2664—22.7%
——7——CVE-2025-32057—22.7%
——7——CVE-2023-524367.8 HIG22.7%
——7In the Linux kernel, the following vulnerability has been resolved:
f2fs: explicitly null-terminate the xattr list
When setting an xattr, explicitly null-terminate the xattr list. This
eliminates the fragile assumption that the unused xattr space is always
zeroed.26dCVE-2024-44252—22.7%
——7——CVE-2003-0875—22.7%
——7——CVE-2026-45728—22.7%
——7——CVE-2006-2539—22.7%
——7——CVE-2026-862777.3 HIG22.7%
——7A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.2dCVE-2024-38493—22.7%
——7——CVE-2026-324687.5 HIG22.7%
——7Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.21dCVE-2026-41461—22.7%
——7——CVE-2026-354127.1 HIG22.7%
——7Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level authorization checks, verifying the user has some permission on directus_files, but never validates item-level access to the specific file being replaced. As a result, row-level permission rules (e.g., "users can only update their own files") are completely bypassed via the TUS path while being correctly enforced on the standard REST upload path. This vulnerability is fixed in 11.16.1.48dCVE-2026-844697.5 HIG22.7%
——7fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later.2dCVE-2026-30224—22.7%
——7——CVE-2023-1491—22.7%
——7——CVE-2026-89647.5 HIG22.7%
——7Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.49dCVE-2025-3739—22.7%
——7——CVE-2025-3738—22.7%
——7——CVE-2023-47578—22.7%
——7——CVE-2026-461258.8 HIG22.7%
——7In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: remove station if connection prep fails
If connection preparation fails for MLO connections, then the
interface is completely reset to non-MLD. In this case, we must
not keep the station since it's related to the link of the vif
being removed. Delete an existing station. Any "new_sta" is
already being removed, so that doesn't need changes.
This fixes a use-after-free/double-free in debugfs if that's
enabled, because a vif going from MLD (and to MLD, but that's
not relevant here) recreates its entire debugfs.58dCVE-2026-28976—22.7%
——7——CVE-2025-54323—22.7%
——7——CVE-2024-20034—22.7%
——7——CVE-2018-20131—22.7%
——7——CVE-2024-13303—22.7%
——7——CVE-2026-20048—22.7%
——7——CVE-2024-7060—22.7%
——7——CVE-2026-34891—22.7%
——7——CVE-2026-160377.5 HIG22.7%
——7Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.2dCVE-2025-3736—22.7%
——7——CVE-2025-12784—22.7%
——7——