Vulnerabilities exploitable today
366,545in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,403
- High10,329
- Medium5,269
- Low512
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-55053—14.9%
——4——CVE-2025-57935—14.9%
——4——CVE-2021-0169—14.9%
——4——CVE-2025-14689—14.9%
——4——CVE-2024-410227.0 HIG14.9%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
The "instance" variable needs to be signed for the error handling to work.24dCVE-2025-60158—14.9%
——4——CVE-2024-11499—14.9%
——4——CVE-2024-51583—14.9%
——4——CVE-2024-23441—14.9%
——4——CVE-2024-51584—14.9%
——4——CVE-2021-25483—14.9%
——4——CVE-2024-51592—14.9%
——4——CVE-2026-763367.1 HIG14.9%
——4In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.7dCVE-2024-51580—14.9%
——4——CVE-2025-5841—14.9%
——4——CVE-2026-624278.8 HIG14.9%
——4[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
To manage the system, sysctl and platform operations are used by the
control domain or a possible Xenstore domain. Some of these operations
may not be executed in parallel, so a system-wide lock each is used.
The way those locks are acquired is, however, not providing any fairness.
Furthermore, with XSM/Flask in use, the lock acquire will, for some
operations, occur ahead of any permission checking.
The sysctl issue is CVE-2026-62426.
The platform-op issue is CVE-2026-62427.31dCVE-2026-28833—14.9%
——4——CVE-2026-703457.8 HIG14.9%
——4Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.12dCVE-2025-68053—14.9%
——4——CVE-2026-25420—14.9%
——4——CVE-2025-32003—14.9%
——4——CVE-2026-628777.8 HIG14.9%
——4Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.12dCVE-2026-62659—14.9%
——4A
security flaw was discovered in the NETGEAR WAX333 Access Point that could
allow someone already logged in and connected to the local network to make
unauthorized changes to the device's settings44dCVE-2021-0167—14.9%
——4——CVE-2026-628807.8 HIG14.9%
——4Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.12dCVE-2021-29613—14.9%
——4——CVE-2025-33124—14.9%
——4——CVE-2023-40335—14.9%
——4——CVE-2025-45878—14.9%
——4——CVE-2025-0272—14.9%
——4——CVE-2021-27456—14.9%
——4——CVE-2024-44158—14.9%
——4——CVE-2024-26636—14.9%
——4——CVE-2025-123175.0 MED14.9%
——4When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user.
This vulnerability could allow users to retain their previous access privileges even after their roles have been revoked. As a result, a user can continue to perform unauthorized actions or access restricted resources until the expired tokens naturally expire.21dCVE-2026-25375—14.9%
——4——CVE-2022-50775—14.9%
——4——CVE-2025-11628—14.9%
——4——CVE-2025-45879—14.9%
——4——CVE-2025-59398—14.9%
——4——CVE-2020-12961—14.9%
——4——