Vulnerabilities exploitable today
369,220in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,162
- High7,747
- Medium5,656
- Low537
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-51523—19.8%
——6——CVE-2025-1997—19.8%
——6——CVE-2018-12175—19.8%
——6——CVE-2024-37553—19.8%
——6——CVE-2018-0449—19.8%
——6——CVE-2019-25262—19.8%
——6——CVE-2024-53757—19.8%
——6——CVE-2022-490447.8 HIG19.8%
——6In the Linux kernel, the following vulnerability has been resolved:
dm integrity: fix memory corruption when tag_size is less than digest size
It is possible to set up dm-integrity in such a way that the
"tag_size" parameter is less than the actual digest size. In this
situation, a part of the digest beyond tag_size is ignored.
In this case, dm-integrity would write beyond the end of the
ic->recalc_tags array and corrupt memory. The corruption happened in
integrity_recalc->integrity_sector_checksum->crypto_shash_final.
Fix this corruption by increasing the tags array so that it has enough
padding at the end to accomodate the loop in integrity_recalc() being
able to write a full digest size for the last member of the tags
array.24dCVE-2018-18093—19.8%
——6——CVE-2018-3703—19.8%
——6——CVE-2024-549975.4 MED19.8%
——6MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.63dCVE-2026-80347—19.8%
——6——CVE-2026-141678.8 HIG19.8%
——6A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.37dCVE-2022-49339—19.8%
——6——CVE-2026-751057.5 HIG19.8%
——6phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party holding any valid, non-expired temporary share URL can enumerate the subnetId parameter to read every IP address record across all sections and subnets, including hostnames, DNS names, MAC addresses, owner/contact fields, and notes (which may contain credentials and configuration details).16dCVE-2026-822687.5 HIG19.8%
——6Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.8dCVE-2024-37944—19.8%
——6——CVE-2026-141688.8 HIG19.8%
——6A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.37dCVE-2021-1852—19.8%
——6——CVE-2024-57262—19.8%
——6——CVE-2026-4276—19.8%
——6——CVE-2025-634098.8 HIG19.8%
——6Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.63dCVE-2026-3936—19.8%
——6——CVE-2026-32774—19.8%
——6——CVE-2018-12131—19.8%
——6——CVE-2025-37844—19.8%
——6——CVE-2024-37465—19.8%
——6——CVE-2026-0146—19.8%
——6——CVE-2022-48321—19.8%
——6——CVE-2024-37507—19.8%
——6——CVE-2022-491787.8 HIG19.8%
——6In the Linux kernel, the following vulnerability has been resolved:
memstick/mspro_block: fix handling of read-only devices
Use set_disk_ro to propagate the read-only state to the block layer
instead of checking for it in ->open and leaking a reference in case
of a read-only device.32dCVE-2024-37460—19.8%
——6——CVE-2018-18097—19.8%
——6——CVE-2026-42799—19.8%
——6——CVE-2026-791184.3 MED19.8%
——6Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)5dCVE-2024-35755—19.8%
——6——CVE-2026-736248.1 HIG19.8%
——6GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.23dCVE-2026-753636.8 MED19.8%
——6An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.5dCVE-2019-4299—19.8%
——6——CVE-2017-9682—19.8%
——6——