Vulnerabilities exploitable today
366,836in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,360
- High9,604
- Medium5,458
- Low531
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-64814—15.5%
——5——CVE-2025-12058—15.5%
——5——CVE-2025-64607—15.5%
——5——CVE-2025-64626—15.5%
——5——CVE-2024-45465—15.5%
——5——CVE-2024-45466—15.5%
——5——CVE-2025-47886—15.5%
——5——CVE-2025-64597—15.5%
——5——CVE-2025-64564—15.5%
——5——CVE-2026-73492—15.5%
——5Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric character references such as :, 	, 
, or 
. CGI.unescapeHTML leaves these references encoded, so allowed_uri? reports the URL safe even though a browser decodes an encoded colon or strips encoded whitespace and executes the resulting URI scheme. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.14dCVE-2025-64581—15.5%
——5——CVE-2025-64623—15.5%
——5——CVE-2025-64599—15.5%
——5——CVE-2025-64585—15.5%
——5——CVE-2025-64620—15.5%
——5——CVE-2025-64792—15.5%
——5——CVE-2026-164734.3 MED15.5%
——5A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.30dCVE-2025-64554—15.5%
——5——CVE-2025-64614—15.5%
——5——CVE-2025-64801—15.5%
——5——CVE-2025-64555—15.5%
——5——CVE-2025-64803—15.5%
——5——CVE-2024-45470—15.5%
——5——CVE-2025-64580—15.5%
——5——CVE-2023-32376—15.5%
——5——CVE-2025-44110—15.5%
——5——CVE-2026-34336—15.5%
——5——CVE-2024-23299—15.5%
——5——CVE-2026-4572—15.5%
——5——CVE-2025-64594—15.5%
——5——CVE-2024-47355—15.5%
——5——CVE-2025-64578—15.5%
——5——CVE-2025-64804—15.5%
——5——CVE-2025-64603—15.5%
——5——CVE-2025-64627—15.5%
——5——CVE-2025-64543—15.5%
——5——CVE-2025-48753—15.5%
——5——CVE-2025-64802—15.5%
——5——CVE-2025-64821—15.5%
——5——CVE-2026-796715.5 MED15.5%
——5Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to reject hostnames that DNS-resolve to private or internal IPs (e.g., 169.254.169.254.nip.io). An attacker with admin privileges can create a webhook with such a hostname to bypass validation and cause the server to make requests to internal services, cloud metadata endpoints, and private network resources. The issue is fixed in 4.4.3.2d