Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,273
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-26930—17.2%
——5——CVE-2022-4095—17.2%
——5——CVE-2026-8199—17.2%
——5——CVE-2025-217807.8 HIG17.2%
——5In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: avoid buffer overflow attach in smu_sys_set_pp_table()
It malicious user provides a small pptable through sysfs and then
a bigger pptable, it may cause buffer overflow attack in function
smu_sys_set_pp_table().48dCVE-2025-37870—17.2%
——5——CVE-2025-10730—17.2%
——5——CVE-2024-7077—17.2%
——5——CVE-2024-3405—17.2%
——5——CVE-2025-58477—17.2%
——5——CVE-2025-26740—17.2%
——5——CVE-2024-58055—17.2%
——5——CVE-2024-56536—17.2%
——5——CVE-2025-29427—17.2%
——5——CVE-2025-10201—17.2%
——5——CVE-2025-14865—17.2%
——5——CVE-2025-15258—17.2%
——5——CVE-2026-817245.3 MED17.2%
——5NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.3dCVE-2020-7320—17.2%
——5——CVE-2025-22673—17.2%
——5——CVE-2025-46453—17.2%
——5——CVE-2026-55538—17.2%
——5——CVE-2025-3760—17.2%
——5——CVE-2025-10649—17.2%
——5——CVE-2026-27118—17.2%
——5——CVE-2026-423397.1 HIG17.2%
——5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user holding any valid API token can send a multimodal request to /v1/chat/completions, /v1/responses, or /v1/messages with 0.0.0.0 as the image/file URL host, bypassing the private-IP filter and causing the server to issue HTTP requests to localhost. This constitutes at minimum a blind SSRF; when the request is routed through an AWS/Bedrock Claude adaptor, the fetched content is inlined into the model response, upgrading it to a full-read SSRF. At time of publication, there are no publicly available patches.38dCVE-2022-33748—17.2%
——5——CVE-2025-26749—17.2%
——5——CVE-2026-828729.1 CRI17.2%
——5ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.6hCVE-2025-46472—17.2%
——5——CVE-2024-54207—17.2%
——5——CVE-2024-43097—17.2%
——5——CVE-2024-54206—17.2%
——5——CVE-2013-1673—17.2%
——5——CVE-2026-705885.0 MED17.2%
——5Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.26dCVE-2026-398837.0 HIG17.2%
——5OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.17dCVE-2026-32078—17.2%
——5——CVE-2025-26880—17.2%
——5——CVE-2023-53928—17.2%
——5——CVE-2025-13497—17.2%
——5——CVE-2026-32076—17.2%
——5——