Vulnerabilities exploitable today
369,332in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,112
- High7,548
- Medium5,585
- Low536
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-44572—20.6%
——6——CVE-2025-12721—20.6%
——6——CVE-2026-54821—20.6%
——6——CVE-2025-55372—20.6%
——6——CVE-2026-187086.4 MED20.6%
——6An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.9dCVE-2022-26707—20.6%
——6——CVE-2026-457908.0 HIG20.6%
——6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite an account with the owner role, while packages/server/src/services/user.ts allows a privileged self-hosted user to create an account with an arbitrary role, enabling permanent organization takeover because owner roles cannot be demoted. This issue is fixed in version 0.29.6.20dCVE-2022-491627.8 HIG20.6%
——6In the Linux kernel, the following vulnerability has been resolved:
video: fbdev: sm712fb: Fix crash in smtcfb_write()
When the sm712fb driver writes three bytes to the framebuffer, the
driver will crash:
BUG: unable to handle page fault for address: ffffc90001ffffff
RIP: 0010:smtcfb_write+0x454/0x5b0
Call Trace:
vfs_write+0x291/0xd60
? do_sys_openat2+0x27d/0x350
? __fget_light+0x54/0x340
ksys_write+0xce/0x190
do_syscall_64+0x43/0x90
entry_SYSCALL_64_after_hwframe+0x44/0xae
Fix it by removing the open-coded endianness fixup-code.33dCVE-2025-21157—20.6%
——6——CVE-2026-55785—20.6%
——6——CVE-2022-26319—20.6%
——6——CVE-2020-8320—20.6%
——6——CVE-2024-55581—20.6%
——6——CVE-2019-25453—20.6%
——6——CVE-2024-42371—20.5%
——6——CVE-2023-46835—20.6%
——6——CVE-2025-61727—20.6%
——6——CVE-2026-656806.7 MED20.6%
——6Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.20dCVE-2022-36774—20.6%
——6——CVE-2024-49822—20.6%
——6——CVE-2026-21686—20.6%
——6——CVE-2021-3636—20.6%
——6——CVE-2026-31867—20.6%
——6——CVE-2024-39510—20.6%
——6——CVE-2024-30525—20.6%
——6——CVE-2025-11881—20.6%
——6——CVE-2025-25188—20.6%
——6——CVE-2023-35990—20.6%
——6——CVE-2026-21691—20.6%
——6——CVE-2024-270347.8 HIG20.6%
——6In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to cover normal cluster write with cp_rwsem
When we overwrite compressed cluster w/ normal cluster, we should
not unlock cp_rwsem during f2fs_write_raw_pages(), otherwise data
will be corrupted if partial blocks were persisted before CP & SPOR,
due to cluster metadata wasn't updated atomically.33dCVE-2026-02817.1 HIG20.6%
——6An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker.
The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not impacted by this vulnerability.26dCVE-2025-10648—20.6%
——6——CVE-2026-42896—20.5%
——6——CVE-2026-458328.8 HIG20.6%
——6All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.54dCVE-2024-43099—20.6%
——6——CVE-2026-2127—20.6%
——6——CVE-2025-43547—20.6%
——6——CVE-2024-10593—20.6%
——6——CVE-2025-26658—20.6%
——6——CVE-2025-26528—20.6%
——6——