Vulnerabilities exploitable today
371,767in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,239
- High8,303
- Medium6,328
- Low606
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-0507—22.7%
——7——CVE-2026-26025—22.7%
——7——CVE-2026-622894.3 MED22.7%
——7libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.18hCVE-2023-21619—22.7%
——7——CVE-2026-45494—22.7%
——7——CVE-2021-34337—22.7%
——7——CVE-2026-0942—22.7%
——7——CVE-2024-47327—22.7%
——7——CVE-2023-29285—22.7%
——7——CVE-2020-28421—22.7%
——7——CVE-2019-12660—22.7%
——7——CVE-2025-6202—22.7%
——7——CVE-2023-22229—22.7%
——7——CVE-2023-1870—22.7%
——7——CVE-2026-213105.3 MED22.7%
——7Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction.14dCVE-2022-28185—22.7%
——7——CVE-2026-7535—22.7%
——7——CVE-2013-0943—22.7%
——7——CVE-2023-26372—22.7%
——7——CVE-2026-558398.7 HIG22.7%
——7Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel in the Flow list. This issue is fixed in version 1.3.24.23dCVE-2024-47349—22.7%
——7——CVE-2010-3277—22.7%
——7——CVE-2024-47301—22.7%
——7——CVE-2025-59788—22.7%
——7——CVE-2023-22227—22.7%
——7——CVE-2026-555886.5 MED22.7%
——7ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.14dCVE-2023-29282—22.7%
——7——CVE-2021-23217—22.7%
——7——CVE-2026-828609.8 CRI22.7%
——7@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.10dCVE-2021-34403—22.7%
——7——CVE-2005-0142—22.7%
——7——CVE-2024-4353—22.7%
——7——CVE-2026-45492—22.7%
——7——CVE-2012-4113—22.7%
——7——CVE-2025-26868—22.7%
——7——CVE-2026-828599.8 CRI22.7%
——7hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.10dCVE-2024-37180—22.7%
——7——CVE-2024-467137.8 HIG22.7%
——7In the Linux kernel, the following vulnerability has been resolved:
perf/aux: Fix AUX buffer serialization
Ole reported that event->mmap_mutex is strictly insufficient to
serialize the AUX buffer, add a per RB mutex to fully serialize it.
Note that in the lock order comment the perf_event::mmap_mutex order
was already wrong, that is, it nesting under mmap_lock is not new with
this patch.37dCVE-2025-26993—22.7%
——7——CVE-2024-28804—22.7%
——7——