Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,311
- High9,414
- Medium5,381
- Low529
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-18899—17.9%
——5——CVE-2025-94844.3 MED17.9%
——5GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.38dCVE-2022-26703—17.9%
——5——CVE-2025-1330—17.9%
——5——CVE-2025-10940—17.9%
——5——CVE-2022-43469—17.9%
——5——CVE-2026-502967.0 HIG17.9%
——5Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.41dCVE-2023-51745—17.9%
——5——CVE-2024-13836—17.9%
——5——CVE-2023-23712—17.9%
——5——CVE-2022-46820—17.9%
——5——CVE-2025-43549—17.9%
——5——CVE-2026-5446—17.9%
——5——CVE-2024-13574—17.9%
——5——CVE-2022-41620—17.9%
——5——CVE-2025-44184—17.9%
——5——CVE-2026-661466.1 MED17.9%
——5Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.4dCVE-2025-221088.6 HIG17.9%
——5In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: Mask the bd_cnt field in the TX BD properly
The bd_cnt field in the TX BD specifies the total number of BDs for
the TX packet. The bd_cnt field has 5 bits and the maximum number
supported is 32 with the value 0.
CONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB
fragments can approach or exceed the maximum supported by the chip.
Add a macro to properly mask the bd_cnt field so that the value 32
will be properly masked and set to 0 in the bd_cnd field.
Without this patch, the out-of-range bd_cnt value will corrupt the
TX BD and may cause TX timeout.
The next patch will check for values exceeding 32.34dCVE-2024-12207—17.9%
——5——CVE-2022-45080—17.9%
——5——CVE-2023-24382—17.9%
——5——CVE-2024-4758—17.9%
——5——CVE-2023-23797—17.9%
——5——CVE-2024-48847—17.9%
——5——CVE-2024-51240—17.9%
——5——CVE-2025-14812—17.9%
——5——CVE-2024-26674—17.9%
——5——CVE-2021-37452—17.9%
——5——CVE-2026-0742—17.9%
——5——CVE-2022-46854—17.9%
——5——CVE-2026-8202—17.9%
——5——CVE-2024-8627—17.9%
——5——CVE-2022-36401—17.9%
——5——CVE-2025-58435—17.9%
——5——CVE-2026-139046.5 MED17.9%
——5Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)62dCVE-2025-1331—17.9%
——5——CVE-2026-1943—17.9%
——5——CVE-2025-3878—17.9%
——5——CVE-2026-544937.7 HIG17.9%
——5Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAudioContentType checks used by the regular radio API. app/Http/Requests/Subsonic/CreateInternetRadioStationRequest.php and app/Http/Requests/Subsonic/UpdateInternetRadioStationRequest.php pass the stored URL through app/Services/RadioService.php to app/Services/Radio/RadioStreamProxy.php, where RadioStreamProxy::openStream() calls fopen($url, 'r', false, $context). Streaming /radio/stream/{id} returns the upstream response body, allowing access to loopback, RFC1918, Docker bridge, metadata, or other internal HTTP services reachable from the Koel server. This issue is fixed in version 9.7.0.11dCVE-2025-382938.8 HIG17.9%
——5In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix node corruption in ar->arvifs list
In current WLAN recovery code flow, ath11k_core_halt() only
reinitializes the "arvifs" list head. This will cause the
list node immediately following the list head to become an
invalid list node. Because the prev of that node still points
to the list head "arvifs", but the next of the list head "arvifs"
no longer points to that list node.
When a WLAN recovery occurs during the execution of a vif
removal, and it happens before the spin_lock_bh(&ar->data_lock)
in ath11k_mac_op_remove_interface(), list_del() will detect the
previously mentioned situation, thereby triggering a kernel panic.
The fix is to remove and reinitialize all vif list nodes from the
list head "arvifs" during WLAN halt. The reinitialization is to make
the list nodes valid, ensuring that the list_del() in
ath11k_mac_op_remove_interface() can execute normally.
Call trace:
__list_del_entry_valid_or_report+0xb8/0xd0
ath11k_mac_op_remove_interface+0xb0/0x27c [ath11k]
drv_remove_interface+0x48/0x194 [mac80211]
ieee80211_do_stop+0x6e0/0x844 [mac80211]
ieee80211_stop+0x44/0x17c [mac80211]
__dev_close_many+0xac/0x150
__dev_change_flags+0x194/0x234
dev_change_flags+0x24/0x6c
devinet_ioctl+0x3a0/0x670
inet_ioctl+0x200/0x248
sock_do_ioctl+0x60/0x118
sock_ioctl+0x274/0x35c
__arm64_sys_ioctl+0xac/0xf0
invoke_syscall+0x48/0x114
...
Tested-on: QCA6698AQ hw2.1 PCI WLAN.HSP.1.1-04591-QCAHSPSWPL_V1_V2_SILICONZ_IOE-134d