Vulnerabilities exploitable today
369,346in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,106
- High7,542
- Medium5,585
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-326657.5 HIG20.7%
——6In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two streams, each sending a declared 65535-byte length prefix and then holding the streams open, a client can already trivially make Unbound roughly allocate double that amount. This is a remote availability issue / memory-accounting bypass in the downstream DoQ implementation that leads to denial of service for new DoQ clients. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.44dCVE-2025-58969—20.7%
——6——CVE-2026-109697.5 HIG20.7%
——6Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)46dCVE-2025-3959—20.6%
——6——CVE-2022-36647—20.7%
——6——CVE-2022-488167.8 HIG20.7%
——6In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: lock against ->sock changing during sysfs read
->sock can be set to NULL asynchronously unless ->recv_mutex is held.
So it is important to hold that mutex. Otherwise a sysfs read can
trigger an oops.
Commit 17f09d3f619a ("SUNRPC: Check if the xprt is connected before
handling sysfs reads") appears to attempt to fix this problem, but it
only narrows the race window.34dCVE-2026-32204—20.7%
——6——CVE-2024-3262—20.7%
——6——CVE-2025-69234—20.6%
——6——CVE-2024-4282—20.6%
——6——CVE-2024-45986—20.6%
——6——CVE-2026-658849.8 CRI20.6%
——6Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.32dCVE-2019-25529—20.6%
——6——CVE-2026-591315.6 MED20.6%
——6No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.12dCVE-2025-10355—20.6%
——6——CVE-2025-2014—20.6%
——6——CVE-2026-748919.8 CRI20.6%
——6openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.5dCVE-2026-555923.9 LOW20.6%
——6Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source without scheme validation. If a logged-in user opens a crafted workspace link containing a javascript: URL, JavaScript runs on the Dashy origin and can read same-origin browser data, interact with the Dashy DOM, and send requests as the victim. This issue is fixed in version 4.3.7.60dCVE-2024-31307—20.6%
——6——CVE-2026-23781—20.6%
——6——CVE-2025-12768—20.6%
——6A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.5dCVE-2026-1932—20.6%
——6——CVE-2025-55383—20.6%
——6——CVE-2024-39623—20.6%
——6——CVE-2021-46771—20.6%
——6——CVE-2022-49350—20.6%
——6——CVE-2023-31669—20.6%
——6——CVE-2025-30464—20.6%
——6——CVE-2022-42309—20.6%
——6——CVE-2026-816987.5 HIG20.6%
——6openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.5dCVE-2021-479447.5 HIG20.6%
——6memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.44dCVE-2024-8487—20.6%
——6——CVE-2026-828569.8 CRI20.6%
——6@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.4dCVE-2024-56240—20.6%
——6——CVE-2022-20239—20.6%
——6——CVE-2021-29038—20.6%
——6——CVE-2026-718456.3 MED20.6%
——6A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.1dCVE-2026-35716.5 MED20.6%
——6The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated attackers to change registration form status.44dCVE-2025-25124—20.6%
——6——CVE-2022-49297—20.6%
——6——