Vulnerabilities exploitable today
366,901in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,296
- High9,357
- Medium5,292
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-27854—16.6%
——5——CVE-2024-0789—16.6%
——5——CVE-2025-13639—16.6%
——5——CVE-2022-49369—16.6%
——5——CVE-2022-47139—16.6%
——5——CVE-2023-41921—16.6%
——5——CVE-2025-69169—16.6%
——5——CVE-2024-51786—16.6%
——5——CVE-2022-49680—16.6%
——5——CVE-2023-52835—16.6%
——5——CVE-2018-11921—16.6%
——5——CVE-2026-43573—16.6%
——5——CVE-2024-51627—16.6%
——5——CVE-2022-45846—16.6%
——5——CVE-2023-42947—16.6%
——5——CVE-2024-43294—16.6%
——5——CVE-2003-0438—16.6%
——5——CVE-2024-43305—16.6%
——5——CVE-2021-34373—16.6%
——5——CVE-2024-27872—16.6%
——5——CVE-2022-49387—16.6%
——5——CVE-2024-578507.8 HIG16.6%
——5In the Linux kernel, the following vulnerability has been resolved:
jffs2: Prevent rtime decompress memory corruption
The rtime decompression routine does not fully check bounds during the
entirety of the decompression pass and can corrupt memory outside the
decompression buffer if the compressed data is corrupted. This adds the
required check to prevent this failure mode.26dCVE-2024-43284—16.6%
——5——CVE-2024-410567.3 HIG16.5%
——5In the Linux kernel, the following vulnerability has been resolved:
firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files
Use strnlen() instead of strlen() on the algorithm and coefficient name
string arrays in V1 wmfw files.
In V1 wmfw files the name is a NUL-terminated string in a fixed-size
array. cs_dsp should protect against overrunning the array if the NUL
terminator is missing.26dCVE-2023-40516—16.5%
——5——CVE-2024-27164—16.5%
——5——CVE-2025-9969—16.5%
——5——CVE-2025-13826—16.5%
——5——CVE-2026-7090—16.5%
——5——CVE-2026-56330—16.5%
——5——CVE-2026-735733.1 LOW16.5%
——5In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.2dCVE-2026-410696.5 MED16.5%
——5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.38dCVE-2026-21685—16.5%
——5——CVE-2024-45006—16.5%
——5——CVE-2021-47006—16.5%
——5——CVE-2026-578296.1 MED16.5%
——5Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.37dCVE-2026-99238.8 HIG16.5%
——5Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)40dCVE-2025-34261—16.5%
——5——CVE-2022-47908—16.5%
——5——CVE-2026-81675—16.5%
——5The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt the query structure and cause database errors, exposing the internal logic of the queries. The complexity of the query increases the potential impact, as it could allow for broader manipulation of the content retrieval logic.1d