Vulnerabilities exploitable today
368,008in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,380
- High9,630
- Medium5,583
- Low545
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-51713—18.9%
——6——CVE-2026-25002—18.9%
——6——CVE-2024-51717—18.9%
——6——CVE-2025-13148—18.9%
——6——CVE-2024-49308—18.9%
——6——CVE-2024-51689—18.9%
——6——CVE-2024-51691—18.9%
——6——CVE-2024-43241—18.9%
——6——CVE-2024-51716—18.9%
——6——CVE-2026-4832—18.9%
——6——CVE-2024-51778—18.9%
——6——CVE-2021-30767—18.9%
——6——CVE-2020-36602—18.9%
——6——CVE-2024-49309—18.9%
——6——CVE-2009-0506—18.9%
——6——CVE-2025-27448—18.9%
——6——CVE-2025-22793—18.9%
——6——CVE-2024-51695—18.9%
——6——CVE-2020-4980—18.9%
——6——CVE-2024-51693—18.9%
——6——CVE-2024-37436—18.9%
——6——CVE-2023-46742—18.9%
——6——CVE-2024-51759—18.9%
——6——CVE-2025-22764—18.9%
——6——CVE-2025-22776—18.9%
——6——CVE-2024-43246—18.9%
——6——CVE-2025-47706—18.9%
——6——CVE-2024-51760—18.9%
——6——CVE-2025-31878—18.9%
——6——CVE-2024-51714—18.9%
——6——CVE-2025-53936—18.9%
——6——CVE-2024-51711—18.9%
——6——CVE-2024-51776—18.9%
——6——CVE-2026-23148—18.9%
——6——CVE-2025-687998.1 HIG18.9%
——6In the Linux kernel, the following vulnerability has been resolved:
caif: fix integer underflow in cffrml_receive()
The cffrml_receive() function extracts a length field from the packet
header and, when FCS is disabled, subtracts 2 from this length without
validating that len >= 2.
If an attacker sends a malicious packet with a length field of 0 or 1
to an interface with FCS disabled, the subtraction causes an integer
underflow.
This can lead to memory exhaustion and kernel instability, potential
information disclosure if padding contains uninitialized kernel memory.
Fix this by validating that len >= 2 before performing the subtraction.34dCVE-2026-54215—18.9%
——6Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnerability to
craft a URL within the application that, when visited, redirects the
user’s browser to an arbitrary third-party site. This can be abused for
phishing attacks, where users receive a trusted domain link but are
redirected to a phishing website. This issue affects TeamDavid through Rollout 524.7dCVE-2024-28981—18.9%
——6——CVE-2024-51708—18.9%
——6——CVE-2026-595658.8 HIG18.9%
——6A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.5dCVE-2025-7667—18.9%
——6——