Vulnerabilities exploitable today
367,922in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,397
- High9,645
- Medium5,598
- Low550
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3744—18.7%
——6——CVE-2024-55927—18.7%
——6——CVE-2026-51235—18.7%
——6Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.33dCVE-2025-8529—18.7%
——6——CVE-2021-36276—18.7%
——6——CVE-2026-40150—18.7%
——6——CVE-2026-34563—18.7%
——6——CVE-2025-30366—18.7%
——6——CVE-2023-38575—18.7%
——6——CVE-2025-1757—18.7%
——6——CVE-2025-68697—18.7%
——6——CVE-2026-139895.3 MED18.7%
——6Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)63dCVE-2026-34566—18.7%
——6——CVE-2025-64011—18.7%
——6——CVE-2026-8786—18.7%
——6——CVE-2025-28878—18.7%
——6——CVE-2026-54015—18.7%
——6——CVE-2023-526677.8 HIG18.7%
——6In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: fix a potential double-free in fs_any_create_groups
When kcalloc() for ft->g succeeds but kvzalloc() for in fails,
fs_any_create_groups() will free ft->g. However, its caller
fs_any_create_table() will free ft->g again through calling
mlx5e_destroy_flow_table(), which will lead to a double-free.
Fix this by setting ft->g to NULL in fs_any_create_groups().29dCVE-2024-51574—18.7%
——6——CVE-2023-4611—18.7%
——6——CVE-2024-499667.8 HIG18.7%
——6In the Linux kernel, the following vulnerability has been resolved:
ocfs2: cancel dqi_sync_work before freeing oinfo
ocfs2_global_read_info() will initialize and schedule dqi_sync_work at the
end, if error occurs after successfully reading global quota, it will
trigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled:
ODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c
This reports that there is an active delayed work when freeing oinfo in
error handling, so cancel dqi_sync_work first. BTW, return status instead
of -1 when .read_file_info fails.29dCVE-2024-36367—18.7%
——6——CVE-2024-28063—18.7%
——6——CVE-2026-4857—18.7%
——6——CVE-2025-40710—18.7%
——6——CVE-2024-49838—18.7%
——6——CVE-2021-36797—18.7%
——6——CVE-2025-54228—18.7%
——6——CVE-2026-561145.3 MED18.7%
——6dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory.49dCVE-2025-0813—18.7%
——6——CVE-2025-62977—18.7%
——6——CVE-2026-7014—18.7%
——6——CVE-2025-14040—18.7%
——6——CVE-2026-409563.7 LOW18.7%
——6CVE-2026-40956
is a memory disclosure vulnerability in Secure Access client versions prior to 14.55.
Attackers with intimate knowledge of and total control over the tunnel protocol
can cause a small amount of random memory to leak.48dCVE-2013-4738—18.7%
——6——CVE-2026-762078.1 HIG18.7%
——6phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.18hCVE-2025-64301—18.7%
——6——CVE-2026-3572—18.7%
——6——CVE-2024-3941—18.7%
——6——CVE-2025-36087—18.7%
——6——