Vulnerabilities exploitable today
369,308in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,127
- High7,592
- Medium5,602
- Low538
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47467—20.5%
——6——CVE-2026-492588.8 HIG20.5%
——6Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit/mobile-bundle/network-create paths and all CA-management routes were already correctly scoped. A malicious operator could block or delete any other operator's host, or read any operator's hosts and networks. This issue has been fixed in version 0.3.6.38dCVE-2025-47471—20.5%
——6——CVE-2025-1878—20.5%
——6——CVE-2024-13731—20.5%
——6——CVE-2024-41828—20.5%
——6——CVE-2024-8988—20.5%
——6——CVE-2022-3151—20.5%
——6——CVE-2022-495637.8 HIG20.5%
——6In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - add param check for RSA
Reject requests with a source buffer that is bigger than the size of the
key. This is to prevent a possible integer underflow that might happen
when copying the source scatterlist into a linear buffer.33dCVE-2026-30841—20.5%
——6——CVE-2025-14889—20.5%
——6——CVE-2025-47534—20.5%
——6——CVE-2025-46470—20.5%
——6——CVE-2025-1922—20.5%
——6——CVE-2022-22671—20.5%
——6——CVE-2025-657976.5 MED20.5%
——6Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).63dCVE-2010-0923—20.5%
——6——CVE-2022-49078—20.5%
——6——CVE-2025-5183—20.5%
——6——CVE-2025-59031—20.5%
——6——CVE-2026-8116—20.5%
——6——CVE-2024-7491—20.5%
——6——CVE-2025-30315—20.5%
——6——CVE-2026-444014.8 MED20.5%
——6Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting.26dCVE-2023-23735—20.5%
——6——CVE-2025-53847—20.5%
——6——CVE-2025-39511—20.5%
——6——CVE-2017-18845—20.5%
——6——CVE-2024-12623—20.5%
——6——CVE-2012-5628—20.5%
——6——CVE-2017-13679—20.5%
——6——CVE-2024-56277—20.5%
——6——CVE-2024-13391—20.5%
——6——CVE-2025-3100—20.5%
——6——CVE-2020-35538—20.4%
——6——CVE-2025-11747—20.5%
——6——CVE-2026-12348—20.5%
——6——CVE-2020-9912—20.5%
——6——CVE-2024-50561—20.5%
——6——CVE-2024-10665—20.5%
——6——