Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,389
- High10,127
- Medium5,026
- Low470
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-47958—14.7%
——4——CVE-2021-0390—14.7%
——4——CVE-2026-715116.5 MED14.7%
——4Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list endpoints to obtain crypted password verifier fields that are not filtered by the base API serializer or the Members API class, potentially enabling offline password cracking attacks.3dCVE-2026-1935—14.7%
——4——CVE-2023-47757—14.7%
——4——CVE-2024-31552—14.7%
——4——CVE-2024-316363.9 LOW14.7%
——4An issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.50dCVE-2025-12891—14.7%
——4——CVE-2026-186918.8 HIG14.7%
——4An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.16dCVE-2026-730585.8 MED14.7%
——4stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve sensitive internal content.10dCVE-2023-32367—14.7%
——4——CVE-2025-53030—14.7%
——4——CVE-2025-54739—14.7%
——4——CVE-2026-563544.1 MED14.7%
——4n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions can inject malicious scripts or redirect parameters to perform stored XSS attacks or phishing redirects against end users.45dCVE-2024-47126—14.7%
——4——CVE-2024-40805—14.7%
——4——CVE-2025-66864—14.7%
——4——CVE-2024-359637.1 HIG14.6%
——4In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sock: Fix not validating setsockopt user input
Check user input length before copying data.23dCVE-2025-52559—14.7%
——4——CVE-2024-6150—14.7%
——4——CVE-2021-25514—14.7%
——4——CVE-2026-597634.3 MED14.7%
——4Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads1dCVE-2023-6998—14.7%
——4——CVE-2024-53228—14.7%
——4——CVE-2023-32453—14.7%
——4——CVE-2024-30516—14.7%
——4——CVE-2020-36928—14.7%
——4——CVE-2024-269908.8 HIG14.7%
——4In the Linux kernel, the following vulnerability has been resolved:
KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing dirty status
Check kvm_mmu_page_ad_need_write_protect() when deciding whether to
write-protect or clear D-bits on TDP MMU SPTEs, so that the TDP MMU
accounts for any role-specific reasons for disabling D-bit dirty logging.
Specifically, TDP MMU SPTEs must be write-protected when the TDP MMU is
being used to run an L2 (i.e. L1 has disabled EPT) and PML is enabled.
KVM always disables PML when running L2, even when L1 and L2 GPAs are in
the some domain, so failing to write-protect TDP MMU SPTEs will cause
writes made by L2 to not be reflected in the dirty log.
[sean: massage shortlog and changelog, tweak ternary op formatting]23dCVE-2023-528527.8 HIG14.7%
——4In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to avoid use-after-free on dic
Call trace:
__memcpy+0x128/0x250
f2fs_read_multi_pages+0x940/0xf7c
f2fs_mpage_readpages+0x5a8/0x624
f2fs_readahead+0x5c/0x110
page_cache_ra_unbounded+0x1b8/0x590
do_sync_mmap_readahead+0x1dc/0x2e4
filemap_fault+0x254/0xa8c
f2fs_filemap_fault+0x2c/0x104
__do_fault+0x7c/0x238
do_handle_mm_fault+0x11bc/0x2d14
do_mem_abort+0x3a8/0x1004
el0_da+0x3c/0xa0
el0t_64_sync_handler+0xc4/0xec
el0t_64_sync+0x1b4/0x1b8
In f2fs_read_multi_pages(), once f2fs_decompress_cluster() was called if
we hit cached page in compress_inode's cache, dic may be released, it needs
break the loop rather than continuing it, in order to avoid accessing
invalid dic pointer.23dCVE-2025-0750—14.7%
——4——CVE-2024-499927.8 HIG14.7%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/stm: Avoid use-after-free issues with crtc and plane
ltdc_load() calls functions drm_crtc_init_with_planes(),
drm_universal_plane_init() and drm_encoder_init(). These functions
should not be called with parameters allocated with devm_kzalloc()
to avoid use-after-free issues [1].
Use allocations managed by the DRM framework.
Found by Linux Verification Center (linuxtesting.org).
[1]
https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/23dCVE-2021-34379—14.7%
——4——CVE-2017-9637—14.7%
——4——CVE-2026-40568—14.6%
——4——CVE-2025-26756—14.7%
——4——CVE-2026-6365—14.7%
——4——CVE-2024-42441—14.6%
——4——CVE-2022-4397—14.7%
——4——CVE-2025-31335—14.7%
——4——CVE-2025-3224—14.7%
——4——