Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-60108—17.6%
——5——CVE-2025-69063—17.6%
——5——CVE-2024-47396—17.6%
——5——CVE-2026-28070—17.6%
——5——CVE-2024-36284—17.6%
——5——CVE-2024-23639—17.6%
——5——CVE-2022-44515—17.6%
——5——CVE-2024-40939—17.6%
——5——CVE-2024-43710—17.6%
——5——CVE-2024-50451—17.6%
——5——CVE-2024-50443—17.6%
——5——CVE-2024-49630—17.6%
——5——CVE-2025-27437—17.6%
——5——CVE-2023-47169—17.6%
——5——CVE-2025-49033—17.6%
——5——CVE-2025-58881—17.6%
——5——CVE-2026-94456.3 MED17.6%
——5A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.43dCVE-2023-531868.1 HIG17.6%
——5In the Linux kernel, the following vulnerability has been resolved:
skbuff: Fix a race between coalescing and releasing SKBs
Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment
recycling") allowed coalescing to proceed with non page pool page and page
pool page when @from is cloned, i.e.
to->pp_recycle --> false
from->pp_recycle --> true
skb_cloned(from) --> true
However, it actually requires skb_cloned(@from) to hold true until
coalescing finishes in this situation. If the other cloned SKB is
released while the merging is in process, from_shinfo->nr_frags will be
set to 0 toward the end of the function, causing the increment of frag
page _refcount to be unexpectedly skipped resulting in inconsistent
reference counts. Later when SKB(@to) is released, it frees the page
directly even though the page pool page is still in use, leading to
use-after-free or double-free errors. So it should be prohibited.
The double-free error message below prompted us to investigate:
BUG: Bad page state in process swapper/1 pfn:0e0d1
page:00000000c6548b28 refcount:-1 mapcount:0 mapping:0000000000000000
index:0x2 pfn:0xe0d1
flags: 0xfffffc0000000(node=0|zone=1|lastcpupid=0x1fffff)
raw: 000fffffc0000000 0000000000000000 ffffffff00000101 0000000000000000
raw: 0000000000000002 0000000000000000 ffffffffffffffff 0000000000000000
page dumped because: nonzero _refcount
CPU: 1 PID: 0 Comm: swapper/1 Tainted: G E 6.2.0+
Call Trace:
<IRQ>
dump_stack_lvl+0x32/0x50
bad_page+0x69/0xf0
free_pcp_prepare+0x260/0x2f0
free_unref_page+0x20/0x1c0
skb_release_data+0x10b/0x1a0
napi_consume_skb+0x56/0x150
net_rx_action+0xf0/0x350
? __napi_schedule+0x79/0x90
__do_softirq+0xc8/0x2b1
__irq_exit_rcu+0xb9/0xf0
common_interrupt+0x82/0xa0
</IRQ>
<TASK>
asm_common_interrupt+0x22/0x40
RIP: 0010:default_idle+0xb/0x2028dCVE-2026-30346—17.6%
——5——CVE-2025-70614—17.6%
——5——CVE-2026-25485—17.6%
——5——CVE-2024-3666—17.6%
——5——CVE-2024-50236—17.6%
——5——CVE-2026-55583—17.6%
——5——CVE-2026-748778.8 HIG17.6%
——5openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.1dCVE-2022-40633—17.6%
——5——CVE-2020-7267—17.6%
——5——CVE-2022-49728—17.6%
——5——CVE-2026-30128.0 HIG17.6%
——5A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.22hCVE-2024-47377—17.6%
——5——CVE-2025-65118—17.6%
——5——CVE-2024-7571—17.6%
——5——CVE-2025-67492—17.6%
——5——CVE-2026-2752—17.6%
——5——CVE-2022-44516—17.6%
——5——CVE-2026-24904—17.6%
——5——CVE-2020-7265—17.6%
——5——CVE-2025-50740—17.6%
——5——CVE-2024-40828—17.6%
——5——CVE-2026-47120—17.6%
——5——