Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,375
- High10,116
- Medium5,020
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-32801—14.8%
——4——CVE-2023-32701—14.8%
——4——CVE-2024-27265—14.8%
——4——CVE-2024-46773—14.8%
——4——CVE-2026-9129—14.8%
——4A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that use local filesystem storage, a regular authenticated user can supply a URL-encoded absolute path (such as an encoded drive letter) in a Viewer storage API request, causing the configured storage root to be discarded and allowing arbitrary files to be read from the server filesystem.
Because the readable files include the server's master configuration, which stores database credentials, signing key locations, certificate passwords, and OAuth secrets, exploitation can lead to disclosure of all server secrets and full compromise of the server and its data. Cloud deployments are not affected, as they use object storage and do not enable this component.35dCVE-2025-66574—14.8%
——4——CVE-2025-8394—14.8%
——4——CVE-2022-50672—14.8%
——4——CVE-2026-599206.5 MED14.8%
——4Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in CONNECT and CONNECTED frames, so raw newline ( \n ) characters in a header value are written directly to the wire, allowing an attacker who controls a header value to inject additional STOMP headers. This happens because the encoder intentionally skips escaping for CONNECT/CONNECTED frames per the STOMP 1.2 specification but never rejects the raw newlines, and since a broker parses each line as a separate header, an attacker controlling a value such as a user-supplied login or passcode can overwrite connection parameters or add authentication/role headers to bypass authentication or escalate privileges (the actual impact is broker-dependent). The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.21dCVE-2025-9849—14.8%
——4——CVE-2026-399657.7 HIG14.8%
——4TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl() to block private IPs and cloud metadata hostnames. However, the HTTP clients (ky and fetch) follow 302 redirects without re-validating the redirect destination. An authenticated user can point a bot block to an attacker-controlled server that responds with a redirect to an internal IP, causing the Typebot server to reach internal services. An authenticated Typebot user can reach AWS metadata (169.254.169.254), private subnets, and container-internal services. Exploitable to extract cloud IAM credentials or probe internal APIs inaccessible from the internet. This issue has been fixed in version 3.16.0.35dCVE-2023-48368—14.8%
——4——CVE-2025-7732—14.8%
——4——CVE-2026-6404—14.8%
——4——CVE-2025-43795—14.8%
——4——CVE-2023-53898—14.8%
——4——CVE-2026-0408—14.8%
——4——CVE-2025-10181—14.8%
——4——CVE-2025-68118—14.8%
——4——CVE-2023-52507—14.8%
——4——CVE-2025-8073—14.8%
——4——CVE-2026-47241—14.8%
——4——CVE-2020-37237—14.8%
——4——CVE-2024-531358.8 HIG14.8%
——4In the Linux kernel, the following vulnerability has been resolved:
KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
Hide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support
for virtualizing Intel PT via guest/host mode unless BROKEN=y. There are
myriad bugs in the implementation, some of which are fatal to the guest,
and others which put the stability and health of the host at risk.
For guest fatalities, the most glaring issue is that KVM fails to ensure
tracing is disabled, and *stays* disabled prior to VM-Enter, which is
necessary as hardware disallows loading (the guest's) RTIT_CTL if tracing
is enabled (enforced via a VMX consistency check). Per the SDM:
If the logical processor is operating with Intel PT enabled (if
IA32_RTIT_CTL.TraceEn = 1) at the time of VM entry, the "load
IA32_RTIT_CTL" VM-entry control must be 0.
On the host side, KVM doesn't validate the guest CPUID configuration
provided by userspace, and even worse, uses the guest configuration to
decide what MSRs to save/load at VM-Enter and VM-Exit. E.g. configuring
guest CPUID to enumerate more address ranges than are supported in hardware
will result in KVM trying to passthrough, save, and load non-existent MSRs,
which generates a variety of WARNs, ToPA ERRORs in the host, a potential
deadlock, etc.23dCVE-2025-69359—14.8%
——4——CVE-2025-25228—14.8%
——4——CVE-2024-39493—14.8%
——4——CVE-2021-47631—14.8%
——4——CVE-2025-9442—14.8%
——4——CVE-2025-6255—14.8%
——4——CVE-2020-10697—14.8%
——4——CVE-2023-53887—14.8%
——4——CVE-2019-25263—14.8%
——4——CVE-2022-39873—14.8%
——4——CVE-2025-6757—14.8%
——4——CVE-2025-2418—14.8%
——4——CVE-2022-25154—14.8%
——4——CVE-2021-26312—14.8%
——4——CVE-2024-47757—14.8%
——4——CVE-2025-26772—14.8%
——4——