Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-67435—20.8%
——6linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding caller-supplied credential headers other than Authorization and Cookie, allowing a malicious redirect-capable server to receive headers such as X-Auth-Token from authenticated monitoring requests. This issue is fixed in version 6.0.0.39dCVE-2019-19751—20.8%
——6——CVE-2023-46375—20.8%
——6——CVE-2026-16215.3 MED20.8%
——6Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers.
This issue affects E-Municipality: from 20251127 before 20260204.12dCVE-2024-45779—20.8%
——6——CVE-2022-49478—20.8%
——6——CVE-2025-49287—20.8%
——6——CVE-2023-541297.1 HIG20.8%
——6In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Add validation for lmac type
Upon physical link change, firmware reports to the kernel about the
change along with the details like speed, lmac_type_id, etc.
Kernel derives lmac_type based on lmac_type_id received from firmware.
In a few scenarios, firmware returns an invalid lmac_type_id, which
is resulting in below kernel panic. This patch adds the missing
validation of the lmac_type_id field.
Internal error: Oops: 96000005 [#1] PREEMPT SMP
[ 35.321595] Modules linked in:
[ 35.328982] CPU: 0 PID: 31 Comm: kworker/0:1 Not tainted
5.4.210-g2e3169d8e1bc-dirty #17
[ 35.337014] Hardware name: Marvell CN103XX board (DT)
[ 35.344297] Workqueue: events work_for_cpu_fn
[ 35.352730] pstate: 40400089 (nZcv daIf +PAN -UAO)
[ 35.360267] pc : strncpy+0x10/0x30
[ 35.366595] lr : cgx_link_change_handler+0x90/0x18034dCVE-2026-631425.0 MED20.8%
——6Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured security policy.35dCVE-2026-817775.3 MED20.8%
——6Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
This issue affects Essential Addons for Elementor: from n/a through 6.8.0.10dCVE-2024-20057—20.8%
——6——CVE-2026-200147.7 HIG20.8%
——6A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network.
This vulnerability is due to the improper processing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted, authenticated IKEv2 packets to an affected device. A successful exploit could allow the attacker to exhaust memory, causing the device to reload.27dCVE-2026-1896—20.8%
——6——CVE-2026-13508—20.8%
——6——CVE-2026-169039.6 CRI20.8%
——6IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a denial of service due to an out-of-bounds write.17dCVE-2025-32388—20.8%
——6——CVE-2024-0226—20.8%
——6——CVE-2017-18225—20.8%
——6——CVE-2026-169098.8 HIG20.8%
——6IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an off-by-one error in bounds checking.17dCVE-2023-51949—20.8%
——6——CVE-2024-13902—20.8%
——6——CVE-2022-26389—20.8%
——6——CVE-2026-26153—20.8%
——6——CVE-2026-37504—20.8%
——6——CVE-2026-429837.8 HIG20.8%
——6Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.46dCVE-2025-5720—20.8%
——6——CVE-2025-24456—20.8%
——6——CVE-2025-52893—20.8%
——6——CVE-2019-0073—20.8%
——6——CVE-2020-10050—20.8%
——6——CVE-2024-49863—20.8%
——6——CVE-2016-4546—20.8%
——6——CVE-2022-36222—20.8%
——6——CVE-2022-28736—20.8%
——6——CVE-2025-48120—20.8%
——6——CVE-2025-12082—20.8%
——6——CVE-2025-1689—20.8%
——6——CVE-2025-262416.5 MED20.8%
——6A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.59dCVE-2024-22568—20.8%
——6——CVE-2026-308165.7 MED20.8%
——6An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.
Successful
exploitation may allow unauthorized access to arbitrary files on the device,
potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.44d