Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,105
- Medium4,998
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-52898—14.9%
——4——CVE-2026-1395—14.9%
——4——CVE-2024-51587—14.9%
——4——CVE-2024-51576—14.9%
——4——CVE-2025-25269—14.9%
——4——CVE-2024-9875—14.9%
——4——CVE-2026-627367.8 HIG14.9%
——4Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.14dCVE-2026-657867.8 HIG14.9%
——4Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.11dCVE-2025-5336—14.9%
——4——CVE-2020-37018—14.9%
——4——CVE-2026-627337.8 HIG14.9%
——4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11dCVE-2026-628767.8 HIG14.9%
——4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11dCVE-2025-43410—14.9%
——4——CVE-2025-57935—14.9%
——4——CVE-2024-410227.0 HIG14.9%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
The "instance" variable needs to be signed for the error handling to work.23dCVE-2024-51583—14.9%
——4——CVE-2024-50472—14.9%
——4——CVE-2025-14142—14.9%
——4——CVE-2024-51580—14.9%
——4——CVE-2026-763367.1 HIG14.9%
——4In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.6dCVE-2026-28833—14.9%
——4——CVE-2025-68053—14.9%
——4——CVE-2026-627707.8 HIG14.9%
——4Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.11dCVE-2026-624278.8 HIG14.9%
——4[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To manage the system, sysctl and platform operations are used by the
control domain or a possible Xenstore domain. Some of these operations
may not be executed in parallel, so a system-wide lock each is used.
The way those locks are acquired is, however, not providing any fairness.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking.
The sysctl issue is CVE-2026-62426.
The platform-op issue is CVE-2026-62427.30dCVE-2026-442295.4 MED14.9%
——4RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.9dCVE-2026-43915—14.9%
——4——CVE-2026-25613—14.9%
——4——CVE-2026-2325—14.9%
——4——CVE-2024-51586—14.9%
——4——CVE-2026-29085—14.9%
——4——CVE-2026-627797.8 HIG14.9%
——4Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.14dCVE-2024-6841—14.9%
——4——CVE-2026-108196.5 MED14.9%
——4Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-0069524dCVE-2018-13811—14.9%
——4——CVE-2025-33124—14.9%
——4——CVE-2026-627557.8 HIG14.9%
——4Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.11dCVE-2025-59398—14.9%
——4——CVE-2021-29571—14.9%
——4——CVE-2026-25399—14.9%
——4——CVE-2024-27437—14.9%
——4——