Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-13863—17.9%
——5——CVE-2026-41389—17.9%
——5——CVE-2020-3350—17.9%
——5——CVE-2026-544937.7 HIG17.9%
——5Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAudioContentType checks used by the regular radio API. app/Http/Requests/Subsonic/CreateInternetRadioStationRequest.php and app/Http/Requests/Subsonic/UpdateInternetRadioStationRequest.php pass the stored URL through app/Services/RadioService.php to app/Services/Radio/RadioStreamProxy.php, where RadioStreamProxy::openStream() calls fopen($url, 'r', false, $context). Streaming /radio/stream/{id} returns the upstream response body, allowing access to loopback, RFC1918, Docker bridge, metadata, or other internal HTTP services reachable from the Koel server. This issue is fixed in version 9.7.0.11dCVE-2023-23797—17.9%
——5——CVE-2022-45080—17.9%
——5——CVE-2025-221088.6 HIG17.9%
——5In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Mask the bd_cnt field in the TX BD properly
The bd_cnt field in the TX BD specifies the total number of BDs for
the TX packet. The bd_cnt field has 5 bits and the maximum number
supported is 32 with the value 0.
CONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB
fragments can approach or exceed the maximum supported by the chip.
Add a macro to properly mask the bd_cnt field so that the value 32
will be properly masked and set to 0 in the bd_cnd field.
Without this patch, the out-of-range bd_cnt value will corrupt the
TX BD and may cause TX timeout.
The next patch will check for values exceeding 32.34dCVE-2024-12207—17.9%
——5——CVE-2024-4758—17.9%
——5——CVE-2023-24382—17.9%
——5——CVE-2024-48847—17.9%
——5——CVE-2025-43568—17.9%
——5——CVE-2023-23795—17.9%
——5——CVE-2026-28352—17.9%
——5——CVE-2025-30516—17.9%
——5——CVE-2023-26289—17.9%
——5——CVE-2026-49082—17.9%
——5——CVE-2022-47183—17.9%
——5——CVE-2025-94844.3 MED17.9%
——5GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.38dCVE-2025-1330—17.9%
——5——CVE-2022-49524—17.9%
——5——CVE-2019-18899—17.9%
——5——CVE-2026-502967.0 HIG17.9%
——5Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.41dCVE-2022-43469—17.9%
——5——CVE-2025-43570—17.9%
——5——CVE-2023-22686—17.9%
——5——CVE-2026-503727.0 HIG17.9%
——5Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.41dCVE-2022-26703—17.9%
——5——CVE-2022-46815—17.9%
——5——CVE-2026-139176.5 MED17.9%
——5Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)62dCVE-2023-33315—17.9%
——5——CVE-2023-23680—17.9%
——5——CVE-2025-21532—17.9%
——5——CVE-2007-6216—17.9%
——5——CVE-2023-51746—17.9%
——5——CVE-2022-38356—17.9%
——5——CVE-2022-46857—17.9%
——5——CVE-2019-25391—17.9%
——5——CVE-2021-0076—17.9%
——5——CVE-2024-13891—17.9%
——5——