Vulnerabilities exploitable today
369,271in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,150
- High7,642
- Medium5,616
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-206779.0 CRI20.2%
——6A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.16dCVE-2025-62897—20.2%
——6——CVE-2026-111648.8 HIG20.2%
——6Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2024-33024—20.2%
——6——CVE-2026-559737.5 HIG20.2%
——6In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon.44dCVE-2024-42391—20.2%
——6——CVE-2025-382649.8 CRI20.2%
——6In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: sanitize request list handling
Validate the request in nvme_tcp_handle_r2t() to ensure it's not part of
any list, otherwise a malicious R2T PDU might inject a loop in request
list processing.38dCVE-2024-39385—20.2%
——6——CVE-2026-2003—20.2%
——6——CVE-2026-112628.8 HIG20.2%
——6Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)45dCVE-2026-1541—20.2%
——6——CVE-2025-3861—20.2%
——6——CVE-2026-344295.4 MED20.2%
——6Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media upload and rename permissions to execute arbitrary JavaScript by bypassing MIME type validation and renaming uploaded files to executable extensions. Attackers can prepend a GIF89a header to HTML/JavaScript payloads to bypass upload validation, rename the file to .html extension, and execute malicious scripts in an administrator's browser session to create backdoor accounts and upload malicious plugins for remote code execution.54dCVE-2026-547645.8 MED20.2%
——6Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.60dCVE-2024-33015—20.2%
——6——CVE-2015-7438—20.2%
——6——CVE-2024-23169—20.2%
——6——CVE-2026-8558—20.2%
——6——CVE-2024-7020—20.2%
——6——CVE-2024-28572—20.2%
——6——CVE-2026-110778.8 HIG20.2%
——6Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)45dCVE-2026-28715—20.2%
——6——CVE-2025-3670—20.2%
——6——CVE-2024-33020—20.2%
——6——CVE-2022-49710—20.2%
——6——CVE-2026-4446—20.2%
——6——CVE-2024-36507—20.2%
——6——CVE-2025-5433—20.2%
——6——CVE-2024-33019—20.2%
——6——CVE-2025-30932—20.2%
——6——CVE-2024-42119—20.2%
——6——CVE-2026-770709.8 CRI20.2%
——6n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject operators such as $ne or $where, turning an intended single-document lookup into full-collection disclosure, full-collection deletion, or other operations on the database server.5dCVE-2026-8544—20.2%
——6——CVE-2023-52986—20.2%
——6——CVE-2026-44775—20.2%
——6——CVE-2025-7142—20.2%
——6——CVE-2025-30934—20.2%
——6——CVE-2023-52976—20.2%
——6——CVE-2026-99688.8 HIG20.2%
——6Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)47dCVE-2024-410497.8 HIG20.2%
——6In the Linux kernel, the following vulnerability has been resolved:
filelock: fix potential use-after-free in posix_lock_inode
Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode().
The request pointer had been changed earlier to point to a lock entry
that was added to the inode's list. However, before the tracepoint could
fire, another task raced in and freed that lock.
Fix this by moving the tracepoint inside the spinlock, which should
ensure that this doesn't happen.33d