Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,291
- High9,346
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-7126—16.7%
——5——CVE-2024-53870—16.7%
——5——CVE-2024-35082—16.7%
——5——CVE-2026-650818.1 HIG16.7%
——5NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.1dCVE-2026-7224—16.7%
——5——CVE-2020-1823—16.7%
——5——CVE-2020-1818—16.7%
——5——CVE-2025-0804—16.7%
——5——CVE-2026-57640—16.7%
——5——CVE-2019-19351—16.7%
——5——CVE-2025-31527—16.7%
——5——CVE-2026-197647.3 HIG16.7%
——5A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.15dCVE-2026-188547.3 HIG16.7%
——5A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.17dCVE-2026-6187—16.7%
——5——CVE-2024-500557.8 HIG16.7%
——5In the Linux kernel, the following vulnerability has been resolved:
driver core: bus: Fix double free in driver API bus_register()
For bus_register(), any error which happens after kset_register() will
cause that @priv are freed twice, fixed by setting @priv with NULL after
the first free.26dCVE-2022-49290—16.7%
——5——CVE-2024-26777—16.7%
——5——CVE-2022-40131—16.7%
——5——CVE-2026-27523—16.7%
——5——CVE-2024-50296—16.7%
——5——CVE-2026-273924.3 MED16.7%
——5Contributor Broken Access Control in uListing <= 2.2.0 versions.38dCVE-2025-11962—16.7%
——5——CVE-2026-712117.1 HIG16.7%
——5MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body.3dCVE-2026-8083—16.7%
——5——CVE-2025-712897.1 HIG16.7%
——5In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: handle attr_set_size() errors when truncating files
If attr_set_size() fails while truncating down, the error is silently
ignored and the inode may be left in an inconsistent state.31dCVE-2021-33063—16.7%
——5——CVE-2024-50290—16.7%
——5——CVE-2026-7128—16.7%
——5——CVE-2026-662725.3 MED16.7%
——5Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.12dCVE-2026-6193—16.7%
——5——CVE-2026-3969—16.7%
——5——CVE-2020-7324—16.7%
——5——CVE-2026-476206.5 MED16.7%
——5NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.23dCVE-2020-12891—16.7%
——5——CVE-2024-43935—16.7%
——5——CVE-2026-4504—16.7%
——5——CVE-2022-42263—16.7%
——5——CVE-2026-57430—16.7%
——5——CVE-2024-56587—16.7%
——5——CVE-2024-43839—16.7%
——5——