Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,389
- High10,124
- Medium5,025
- Low470
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-59189—14.7%
——4——CVE-2020-0533—14.7%
——4——CVE-2020-37213—14.7%
——4——CVE-2025-57396—14.7%
——4——CVE-2026-22789—14.7%
——4——CVE-2024-42086—14.7%
——4——CVE-2026-230957.5 HIG14.7%
——4In the Linux kernel, the following vulnerability has been resolved:
gue: Fix skb memleak with inner IP protocol 0.
syzbot reported skb memleak below. [0]
The repro generated a GUE packet with its inner protocol 0.
gue_udp_recv() returns -guehdr->proto_ctype for "resubmit"
in ip_protocol_deliver_rcu(), but this only works with
non-zero protocol number.
Let's drop such packets.
Note that 0 is a valid number (IPv6 Hop-by-Hop Option).
I think it is not practical to encap HOPOPT in GUE, so once
someone starts to complain, we could pass down a resubmit
flag pointer to distinguish two zeros from the upper layer:
* no error
* resubmit HOPOPT
[0]
BUG: memory leak
unreferenced object 0xffff888109695a00 (size 240):
comm "syz.0.17", pid 6088, jiffies 4294943096
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 40 c2 10 81 88 ff ff 00 00 00 00 00 00 00 00 .@..............
backtrace (crc a84b336f):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4958 [inline]
slab_alloc_node mm/slub.c:5263 [inline]
kmem_cache_alloc_noprof+0x3b4/0x590 mm/slub.c:5270
__build_skb+0x23/0x60 net/core/skbuff.c:474
build_skb+0x20/0x190 net/core/skbuff.c:490
__tun_build_skb drivers/net/tun.c:1541 [inline]
tun_build_skb+0x4a1/0xa40 drivers/net/tun.c:1636
tun_get_user+0xc12/0x2030 drivers/net/tun.c:1770
tun_chr_write_iter+0x71/0x120 drivers/net/tun.c:1999
new_sync_write fs/read_write.c:593 [inline]
vfs_write+0x45d/0x710 fs/read_write.c:686
ksys_write+0xa7/0x170 fs/read_write.c:738
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0xa4/0xf80 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f44dCVE-2022-32967—14.7%
——4——CVE-2025-20751—14.7%
——4——CVE-2026-664617.5 HIG14.7%
——4Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.13dCVE-2026-754806.5 MED14.7%
——4OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.10dCVE-2026-732868.1 HIG14.7%
——4RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1.0.0-beta.12.15dCVE-2026-49070—14.7%
——4——CVE-2019-25349—14.7%
——4——CVE-2026-40774—14.7%
——4——CVE-2026-35462—14.7%
——4——CVE-2024-1460—14.7%
——4——CVE-2025-714037.1 HIG14.7%
——4better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.24dCVE-2023-22314—14.7%
——4——CVE-2024-22028—14.7%
——4——CVE-2021-4023—14.7%
——4——CVE-2026-9199—14.7%
——4——CVE-2025-55626—14.7%
——4——CVE-2024-46702—14.7%
——4——CVE-2021-47305—14.7%
——4——CVE-2024-13724—14.7%
——4——CVE-2022-48641—14.7%
——4——CVE-2021-47177—14.7%
——4——CVE-2026-739318.3 HIG14.7%
——4Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).6dCVE-2022-48704—14.7%
——4——CVE-2026-49111—14.7%
——4——CVE-2023-22317—14.7%
——4——CVE-2024-45157—14.7%
——4——CVE-2023-52851—14.7%
——4——CVE-2026-124977.5 HIG14.7%
——4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to accepting any non-administrator role. Combined with the absence of a nonce on the public registration handler, this allows an unauthenticated visitor to register an account with a higher role, such as Editor or Author, than the form was configured to offer.34dCVE-2025-8208—14.7%
——4——CVE-2026-687535.3 MED14.7%
——4An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.15dCVE-2025-22806—14.7%
——4——CVE-2022-20456—14.7%
——4——CVE-2021-27026—14.7%
——4——