Vulnerabilities exploitable today
368,208in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,694
New KEV · 24H0
Exploit Today ≥ 701,631
Distribution · last window
- Critical2,147
- High7,679
- Medium5,506
- Low542
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-68666—19.3%
——6——CVE-2023-51795—19.3%
——6——CVE-2026-815258.1 HIG19.3%
——6The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a different storage location than the one the application intended.6dCVE-2025-5517—19.3%
——6——CVE-2024-40850—19.3%
——6——CVE-2024-8010—19.3%
——6——CVE-2022-49432—19.3%
——6——CVE-2026-130978.7 HIG19.3%
——6A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.7dCVE-2022-43152—19.3%
——6——CVE-2025-2120—19.3%
——6——CVE-2019-15876—19.3%
——6——CVE-2020-0226—19.3%
——6——CVE-2025-60130—19.3%
——6——CVE-2025-53348—19.3%
——6——CVE-2025-52949—19.3%
——6——CVE-2025-55678—19.3%
——6——CVE-2024-50218—19.3%
——6——CVE-2025-1692—19.3%
——6——CVE-2023-52652—19.3%
——6——CVE-2024-502377.8 HIG19.3%
——6In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
Avoid potentially crashing in the driver because of uninitialized private data31dCVE-2025-53757—19.3%
——6——CVE-2024-42169—19.3%
——6——CVE-2026-310188.8 HIG19.3%
——6In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.61dCVE-2026-42241—19.3%
——6——CVE-2026-35660—19.3%
——6——CVE-2024-6121—19.3%
——6——CVE-2024-20999—19.3%
——6——CVE-2025-14006—19.3%
——6——CVE-2022-44081—19.3%
——6——CVE-2024-4083—19.3%
——6——CVE-2025-68436—19.3%
——6——CVE-2025-57778—19.3%
——6——CVE-2026-656976.1 MED19.3%
——6Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname to the unauthenticated /collect endpoint. The parseHostname and parsePathname functions perform no URI scheme validation, allowing a javascript: hostname combined with a newline-prefixed pathname to be stored and later rendered as an anchor href in the authenticated dashboard without sanitization, enabling session hijacking and full account takeover when an operator clicks the poisoned entry.42dCVE-2025-91897.8 HIG19.3%
——6There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.10hCVE-2007-6705—19.3%
——6——CVE-2025-30110—19.3%
——6——CVE-2024-44239—19.3%
——6——CVE-2025-10467—19.3%
——6——CVE-2026-31935—19.3%
——6——CVE-2025-12655—19.3%
——6——