Vulnerabilities exploitable today
367,165in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-1453—17.1%
——5——CVE-2026-6874—17.1%
——5——CVE-2026-564445.9 MED17.1%
——5In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable.38dCVE-2026-48969—17.1%
——5——CVE-2022-34892—17.1%
——5——CVE-2025-40801—17.1%
——5——CVE-2025-4894—17.1%
——5——CVE-2020-7515—17.1%
——5——CVE-2022-28638—17.1%
——5——CVE-2024-13207—17.1%
——5——CVE-2025-33138—17.1%
——5——CVE-2026-769996.3 MED17.1%
——5A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.7dCVE-2020-12898—17.1%
——5——CVE-2026-354114.3 MED17.1%
——5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are presented with the legitimate Directus 2FA setup page. After completing the setup process, the application redirects the user to the attacker-controlled URL specified in the redirect parameter without any validation. This vulnerability could be used in phishing attacks targeting Directus administrators, as the initial interaction occurs on a trusted domain. This vulnerability is fixed in 11.16.1.38dCVE-2021-25332—17.1%
——5——CVE-2026-483657.8 HIG17.1%
——5Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2024-45284—17.1%
——5——CVE-2026-748838.8 HIG17.1%
——5openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.14dCVE-2021-25333—17.1%
——5——CVE-2025-1525—17.1%
——5——CVE-2026-483117.8 HIG17.1%
——5Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-483667.8 HIG17.1%
——5Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2025-363206.4 MED17.1%
——5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.56dCVE-2026-22245—17.1%
——5——CVE-2026-24401—17.1%
——5——CVE-2020-12893—17.1%
——5——CVE-2024-10680—17.1%
——5——CVE-2025-47094—17.1%
——5——CVE-2025-1289—17.1%
——5——CVE-2026-483707.8 HIG17.1%
——5Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2025-23023—17.1%
——5——CVE-2024-359587.8 HIG17.1%
——5In the Linux kernel, the following vulnerability has been resolved:
net: ena: Fix incorrect descriptor free behavior
ENA has two types of TX queues:
- queues which only process TX packets arriving from the network stack
- queues which only process TX packets forwarded to it by XDP_REDIRECT
or XDP_TX instructions
The ena_free_tx_bufs() cycles through all descriptors in a TX queue
and unmaps + frees every descriptor that hasn't been acknowledged yet
by the device (uncompleted TX transactions).
The function assumes that the processed TX queue is necessarily from
the first category listed above and ends up using napi_consume_skb()
for descriptors belonging to an XDP specific queue.
This patch solves a bug in which, in case of a VF reset, the
descriptors aren't freed correctly, leading to crashes.27dCVE-2025-5320—17.1%
——5——CVE-2024-45405—17.1%
——5——CVE-2021-1051—17.1%
——5——CVE-2022-32657—17.1%
——5——CVE-2026-483687.8 HIG17.1%
——5Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2021-25331—17.1%
——5——CVE-2006-6275—17.1%
——5——CVE-2022-32658—17.1%
——5——