Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,341
- High10,014
- Medium4,921
- Low461
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-575115.4 MED14.3%
——4SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title field passed to the SMTP DATA command to add Bcc recipients for content exfiltration, forge the From address to bypass SPF and DKIM checks, or inject Content-Type and MIME boundary headers to corrupt message bodies for phishing.28dCVE-2025-65417—14.3%
——4——CVE-2025-43206—14.3%
——4——CVE-2025-22767—14.3%
——4——CVE-2026-457294.3 MED14.3%
——4Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to Picture::load() to crash the process with a 6-byte payload. This issue has been patched in version 1.0.5.36dCVE-2026-40904—14.3%
——4——CVE-2025-59270—14.3%
——4——CVE-2026-667809.9 CRI14.3%
——4A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh.7dCVE-2023-52848—14.3%
——4——CVE-2024-32793—14.3%
——4——CVE-2026-3567—14.3%
——4——CVE-2025-52599—14.3%
——4——CVE-2021-47053—14.3%
——4——CVE-2021-47052—14.3%
——4——CVE-2022-48840—14.3%
——4——CVE-2026-471196.1 MED14.3%
——4Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image_get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers can place a crafted SVG file containing script tags in any path readable by the agent-zero process and lure an authenticated user to the image_get endpoint, causing the browser to execute the malicious script, steal the csrf_token cookie, and perform unauthorized API calls on behalf of the victim.44dCVE-2023-23579—14.3%
——4——CVE-2025-68854—14.3%
——4——CVE-2024-8507—14.3%
——4——CVE-2023-3487—14.3%
——4——CVE-2023-33806—14.3%
——4——CVE-2025-8460—14.3%
——4——CVE-2026-63649—14.3%
——4The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks10dCVE-2025-22356—14.3%
——4——CVE-2024-56575—14.3%
——4——CVE-2025-61306—14.3%
——4——CVE-2026-55849—14.3%
——4@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CLI passes user-supplied --workspace values to a subshell without proper sanitization when npm_execpath is unset or empty, allowing arbitrary OS command execution with the privileges of the invoking user. This issue is fixed in version 5.0.0.48dCVE-2026-1512—14.3%
——4——CVE-2025-4573—14.3%
——4——CVE-2025-48296—14.3%
——4——CVE-2021-47003—14.3%
——4——CVE-2024-565737.0 HIG14.3%
——4In the Linux kernel, the following vulnerability has been resolved:
efi/libstub: Free correct pointer on failure
cmdline_ptr is an out parameter, which is not allocated by the function
itself, and likely points into the caller's stack.
cmdline refers to the pool allocation that should be freed when cleaning
up after a failure, so pass this instead to free_pool().23dCVE-2024-38551—14.3%
——4——CVE-2025-22501—14.3%
——4——CVE-2024-56589—14.3%
——4——CVE-2023-52787—14.3%
——4——CVE-2025-3064—14.3%
——4——CVE-2025-22566—14.3%
——4——CVE-2022-22703—14.3%
——4——CVE-2021-47005—14.3%
——4——