Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,105
- Medium4,998
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-23315—15.0%
——4——CVE-2026-347635.3 MED15.0%
——4Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates the configured root path directly into a regular expression when deriving the displayed directory path. If root contains regex metacharacters such as +, *, or ., the prefix stripping can fail and the generated directory listing may expose the full filesystem path in the HTML output. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.34dCVE-2025-7554—15.0%
——4——CVE-2023-34431—15.0%
——4——CVE-2024-51931—15.0%
——4——CVE-2024-44648—14.9%
——4——CVE-2023-52520—15.0%
——4——CVE-2025-50986—15.0%
——4——CVE-2026-79269—15.0%
——4——CVE-2024-44651—15.0%
——4——CVE-2021-47117—15.0%
——4——CVE-2024-1598—15.0%
——4——CVE-2025-13828—15.0%
——4——CVE-2025-23314—15.0%
——4——CVE-2026-42878—15.0%
——4——CVE-2026-1885—15.0%
——4——CVE-2024-44641—14.9%
——4——CVE-2021-470617.8 HIG15.0%
——4In the Linux kernel, the following vulnerability has been resolved:
KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU
If allocating a new instance of an I/O bus fails when unregistering a
device, wait to destroy the device until after all readers are guaranteed
to see the new null bus. Destroying devices before the bus is nullified
could lead to use-after-free since readers expect the devices on their
reference of the bus to remain valid.24dCVE-2023-45935—15.0%
——4——CVE-2020-0523—15.0%
——4——CVE-2026-43048—15.0%
——4——CVE-2025-43015—15.0%
——4——CVE-2026-453585.3 MED15.0%
——4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder. This issue has been patched in versions 6.9.13-47 and 7.1.2-22.36dCVE-2025-58866—15.0%
——4——CVE-2023-25445—15.0%
——4——CVE-2023-52826—15.0%
——4——CVE-2024-44660—14.9%
——4——CVE-2025-53822—15.0%
——4——CVE-2026-167385.3 MED15.0%
——4The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.4dCVE-2026-1804—15.0%
——4——CVE-2025-53820—15.0%
——4——CVE-2019-25371—15.0%
——4——CVE-2025-62019—15.0%
——4——CVE-2026-32708—15.0%
——4——CVE-2025-52219—15.0%
——4——CVE-2011-1787—15.0%
——4——CVE-2021-0519—15.0%
——4——CVE-2024-57958—15.0%
——4——CVE-2026-187376.5 MED15.0%
——4Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.22dCVE-2019-2328—15.0%
——4——