Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,370
- High10,112
- Medium5,014
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-36605—14.8%
——4——CVE-2025-7791—14.8%
——4——CVE-2024-6379—14.8%
——4——CVE-2025-31130—14.8%
——4——CVE-2024-467257.8 HIG14.8%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix out-of-bounds write warning
Check the ring type value to fix the out-of-bounds
write warning23dCVE-2026-33491—14.8%
——4——CVE-2021-23019—14.8%
——4——CVE-2025-9500—14.8%
——4——CVE-2025-49488—14.8%
——4——CVE-2023-28134—14.8%
——4——CVE-2022-48330—14.8%
——4——CVE-2023-47298—14.8%
——4——CVE-2024-49918—14.8%
——4——CVE-2021-21601—14.8%
——4——CVE-2023-32388—14.8%
——4——CVE-2025-20140—14.8%
——4——CVE-2023-53891—14.8%
——4——CVE-2025-5586—14.8%
——4——CVE-2024-46772—14.8%
——4——CVE-2024-25552—14.8%
——4——CVE-2023-32398—14.8%
——4——CVE-2026-399657.7 HIG14.8%
——4TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow 302 redirects without re-validating the redirect destination. An authenticated user can point a bot block to an attacker-controlled server that responds with a redirect to an internal IP, causing the Typebot server to reach internal services. An authenticated Typebot user can reach AWS metadata (169.254.169.254), private subnets, and container-internal services. Exploitable to extract cloud IAM credentials or probe internal APIs inaccessible from the internet. This issue has been fixed in version 3.16.0.35dCVE-2025-27079—14.8%
——4——CVE-2024-27265—14.8%
——4——CVE-2026-599206.5 MED14.8%
——4Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in CONNECT and CONNECTED frames, so raw newline ( \n ) characters in a header value are written directly to the wire, allowing an attacker who controls a header value to inject additional STOMP headers. This happens because the encoder intentionally skips escaping for CONNECT/CONNECTED frames per the STOMP 1.2 specification but never rejects the raw newlines, and since a broker parses each line as a separate header, an attacker controlling a value such as a user-supplied login or passcode can overwrite connection parameters or add authentication/role headers to bypass authentication or escalate privileges (the actual impact is broker-dependent). The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.21dCVE-2024-7688—14.8%
——4——CVE-2026-9129—14.8%
——4A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a Viewer storage API request, causing the configured storage root to be discarded and allowing arbitrary files to be read from the server filesystem.
Because the readable files include the server's master configuration, which stores database credentials, signing key locations, certificate passwords, and OAuth secrets, exploitation can lead to disclosure of all server secrets and full compromise of the server and its data. Cloud deployments are not affected, as they use object storage and do not enable this component.35dCVE-2025-9849—14.8%
——4——CVE-2024-46773—14.8%
——4——CVE-2021-32801—14.8%
——4——CVE-2025-50902—14.8%
——4——CVE-2022-25154—14.8%
——4——CVE-2021-21546—14.8%
——4——CVE-2023-32701—14.8%
——4——CVE-2025-54962—14.8%
——4——CVE-2024-47757—14.8%
——4——CVE-2024-580107.8 HIG14.8%
——4In the Linux kernel, the following vulnerability has been resolved:
binfmt_flat: Fix integer overflow bug on 32 bit systems
Most of these sizes and counts are capped at 256MB so the math doesn't
result in an integer overflow. The "relocs" count needs to be checked
as well. Otherwise on 32bit systems the calculation of "full_data"
could be wrong.
full_data = data_len + relocs * sizeof(unsigned long);23dCVE-2022-39873—14.8%
——4——CVE-2025-26772—14.8%
——4——CVE-2025-6757—14.8%
——4——