Vulnerabilities exploitable today
369,638in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,638
Distribution · last window
- Critical2,121
- High7,610
- Medium5,709
- Low559
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-62382—21.5%
——6——CVE-2025-61543—21.5%
——6——CVE-2021-0166—21.5%
——6——CVE-2023-50356—21.5%
——6——CVE-2023-40410—21.5%
——6——CVE-2021-2381—21.5%
——6——CVE-2024-53057—21.5%
——6——CVE-2025-25119—21.5%
——6——CVE-2007-0409—21.5%
——6——CVE-2026-1831—21.5%
——6——CVE-2020-26231—21.5%
——6——CVE-2024-6260—21.5%
——6——CVE-2018-25172—21.5%
——6——CVE-2026-25398—21.5%
——6——CVE-2025-82833.7 LOW21.5%
——6A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.7dCVE-2023-30408—21.5%
——6——CVE-2026-554015.3 MED21.5%
——6CVE-2026-55401 is a null dereference vulnerability on the load-balancing
sub-system of Secure Access servers prior to 14.57. Attackers can send
an unauthenticated packet to a Secure Access server with load balancing
enabled, which results in the internal load balancer crashing. After a
successful attack, the Secure Access server is still able to accept
connections and is still able to issue a failover to connected clients. https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L4dCVE-2024-22457—21.5%
——6——CVE-2026-469997.0 HIG21.5%
——6Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L).32dCVE-2024-43977—21.5%
——6——CVE-2026-406917.5 HIG21.5%
——6In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces.46dCVE-2026-24793—21.5%
——6——CVE-2026-622165.0 MED21.5%
——6OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.47dCVE-2025-23194—21.5%
——6——CVE-2024-32949—21.5%
——6——CVE-2025-29556—21.5%
——6——CVE-2025-9867—21.5%
——6——CVE-2025-32504—21.5%
——6——CVE-2025-4101—21.5%
——6——CVE-2025-8975—21.5%
——6——CVE-2025-25158—21.5%
——6——CVE-2023-50974—21.5%
——6——CVE-2025-2290—21.5%
——6——CVE-2025-32582—21.5%
——6——CVE-2025-32562—21.5%
——6——CVE-2023-2303—21.5%
——6——CVE-2026-479245.5 MED21.5%
——6Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.12dCVE-2025-23425—21.5%
——6——CVE-2023-2977—21.5%
——6——CVE-2022-3219—21.5%
——6——