Vulnerabilities exploitable today
366,910in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,352
- Medium5,308
- Low510
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-4326—16.8%
——5——CVE-2025-5285—16.8%
——5——CVE-2025-44206—16.8%
——5——CVE-2023-22674—16.8%
——5——CVE-2026-627575.3 MED16.8%
——5Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.14dCVE-2023-50572—16.8%
——5——CVE-2023-52836—16.8%
——5——CVE-2025-63001—16.8%
——5——CVE-2022-49095—16.8%
——5——CVE-2023-41660—16.8%
——5——CVE-2023-40443—16.8%
——5——CVE-2026-41495—16.8%
——5——CVE-2023-52764—16.8%
——5——CVE-2025-66136—16.8%
——5——CVE-2025-66056—16.8%
——5——CVE-2025-60165—16.8%
——5——CVE-2025-61618—16.8%
——5——CVE-2025-68511—16.8%
——5——CVE-2023-527997.8 HIG16.8%
——5In the Linux kernel, the following vulnerability has been resolved:
jfs: fix array-index-out-of-bounds in dbFindLeaf
Currently while searching for dmtree_t for sufficient free blocks there
is an array out of bounds while getting element in tp->dm_stree. To add
the required check for out of bound we first need to determine the type
of dmtree. Thus added an extra parameter to dbFindLeaf so that the type
of tree can be determined and the required check can be applied.26dCVE-2026-212854.3 MED16.8%
——5Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.2dCVE-2025-61607—16.8%
——5——CVE-2025-11133—16.8%
——5——CVE-2024-49903—16.8%
——5——CVE-2024-50110—16.8%
——5——CVE-2022-43512—16.8%
——5——CVE-2025-12098—16.8%
——5——CVE-2026-55536.3 MED16.8%
——5A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.37dCVE-2021-47652—16.8%
——5——CVE-2026-661408.4 HIG16.8%
——5Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.13dCVE-2024-468137.8 HIG16.8%
——5In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check link_index before accessing dc->links[]
[WHY & HOW]
dc->links[] has max size of MAX_LINKS and NULL is return when trying to
access with out-of-bound index.
This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.26dCVE-2024-34438—16.8%
——5——CVE-2025-59391—16.8%
——5——CVE-2026-55586.3 MED16.8%
——5A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.37dCVE-2023-39562—16.8%
——5——CVE-2022-27575—16.8%
——5——CVE-2025-11895—16.8%
——5——CVE-2022-49100—16.8%
——5——CVE-2024-40931—16.8%
——5——CVE-2024-43408—16.8%
——5——CVE-2026-99347.5 HIG16.8%
——5Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)40d