Vulnerabilities exploitable today
371,173in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,229
- High8,582
- Medium6,298
- Low585
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-9921—22.0%
——7——CVE-2023-48039—22.0%
——7——CVE-2024-33767—22.0%
——7——CVE-2026-41168—22.0%
——7——CVE-2026-737717.5 HIG22.0%
——7An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.5dCVE-2024-7542—22.0%
——7——CVE-2026-4977—22.0%
——7——CVE-2025-25510—22.0%
——7——CVE-2026-731996.5 MED22.0%
——7A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.20dCVE-2026-41335—22.0%
——7——CVE-2025-8528—22.0%
——7——CVE-2026-0844—22.0%
——7——CVE-2010-2945—22.0%
——7——CVE-2016-7959—22.0%
——7——CVE-2010-3380—22.0%
——7——CVE-2008-5380—22.0%
——7——CVE-2010-1794—22.0%
——7——CVE-2017-18416—22.0%
——7——CVE-2026-23656—22.0%
——7——CVE-2026-163718.8 HIG22.0%
——7Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Firefox ESR 140.15, and Thunderbird 140.15.7dCVE-2025-5873—22.0%
——7——CVE-2025-25505—22.0%
——7——CVE-2012-1691—22.0%
——7——CVE-2025-1739—22.0%
——7——CVE-2025-219947.6 HIG22.0%
——7In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix incorrect validation for num_aces field of smb_acl
parse_dcal() validate num_aces to allocate posix_ace_state_array.
if (num_aces > ULONG_MAX / sizeof(struct smb_ace *))
It is an incorrect validation that we can create an array of size ULONG_MAX.
smb_acl has ->size field to calculate actual number of aces in request buffer
size. Use this to check invalid num_aces.41dCVE-2021-0580—22.0%
——7——CVE-2021-1822—22.0%
——7——CVE-2024-34933—22.0%
——7——CVE-2025-20264—22.0%
——7——CVE-2026-7712—22.0%
——7——CVE-2026-614387.3 HIG22.0%
——7PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.55dCVE-2025-59337—22.0%
——7——CVE-2026-261996.5 MED22.0%
——7HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.42dCVE-2013-6122—22.0%
——7——CVE-2025-66549—22.0%
——7——CVE-2026-177153.1 LOW22.0%
——7Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)36dCVE-2026-43935—22.0%
——7——CVE-2026-11848—22.0%
——7——CVE-2026-194268.2 HIG22.0%
——7POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.14dCVE-2025-63499—22.0%
——7——