Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20220—16.6%
——5——CVE-2026-440566.4 MED16.6%
——5A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause a denial of service, obtain limited information, or modify limited data.37dCVE-2026-57282—16.6%
——5——CVE-2026-53475—16.6%
——5——CVE-2024-51674—16.6%
——5——CVE-2024-38698—16.6%
——5——CVE-2022-49461—16.6%
——5——CVE-2024-35146—16.6%
——5——CVE-2022-47141—16.6%
——5——CVE-2026-40100—16.6%
——5——CVE-2022-26774—16.6%
——5——CVE-2024-51622—16.6%
——5——CVE-2024-43352—16.6%
——5——CVE-2022-49146—16.6%
——5——CVE-2024-38697—16.6%
——5——CVE-2024-51611—16.6%
——5——CVE-2022-49570—16.6%
——5——CVE-2024-37951—16.6%
——5——CVE-2026-12019—16.6%
——5——CVE-2022-49285—16.6%
——5——CVE-2025-13354—16.6%
——5——CVE-2017-18305—16.6%
——5——CVE-2024-43351—16.6%
——5——CVE-2025-64283—16.6%
——5——CVE-2025-12782—16.6%
——5——CVE-2024-51613—16.6%
——5——CVE-2026-580555.4 MED16.6%
——5nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.60dCVE-2026-149247.5 HIG16.6%
——5The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.32dCVE-2020-1669—16.6%
——5——CVE-2022-49677—16.6%
——5——CVE-2022-486327.8 HIG16.6%
——5In the Linux kernel, the following vulnerability has been resolved:
i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction()
memcpy() is called in a loop while 'operation->length' upper bound
is not checked and 'data_idx' also increments.26dCVE-2024-46722—16.6%
——5——CVE-2018-11854—16.6%
——5——CVE-2018-11853—16.6%
——5——CVE-2023-5136—16.6%
——5——CVE-2024-43284—16.6%
——5——CVE-2024-578507.8 HIG16.6%
——5In the Linux kernel, the following vulnerability has been resolved:
jffs2: Prevent rtime decompress memory corruption
The rtime decompression routine does not fully check bounds during the
entirety of the decompression pass and can corrupt memory outside the
decompression buffer if the compressed data is corrupted. This adds the
required check to prevent this failure mode.26dCVE-2023-39917—16.6%
——5——CVE-2022-49387—16.6%
——5——CVE-2024-43267—16.6%
——5——