Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,145
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-24151—14.0%
——4——CVE-2025-59571—14.0%
——4——CVE-2023-27899—14.0%
——4——CVE-2025-53427—14.0%
——4——CVE-2026-55724.3 MED14.0%
——4A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.33dCVE-2025-52741—14.0%
——4——CVE-2024-56723—14.0%
——4——CVE-2022-20253—14.0%
——4——CVE-2025-52755—14.0%
——4——CVE-2026-80456.5 MED14.0%
——4CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.37dCVE-2025-58921—14.0%
——4——CVE-2025-49930—14.0%
——4——CVE-2025-52770—14.0%
——4——CVE-2022-22444—14.0%
——4——CVE-2026-6991—14.0%
——4——CVE-2025-52749—14.0%
——4——CVE-2021-36325—14.0%
——4——CVE-2025-21863—14.0%
——4——CVE-2024-39734—14.0%
——4——CVE-2011-4212—14.0%
——4——CVE-2025-30055—13.9%
——4——CVE-2021-473947.8 HIG13.9%
——4In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: unlink table before deleting it
syzbot reports following UAF:
BUG: KASAN: use-after-free in memcmp+0x18f/0x1c0 lib/string.c:955
nla_strcmp+0xf2/0x130 lib/nlattr.c:836
nft_table_lookup.part.0+0x1a2/0x460 net/netfilter/nf_tables_api.c:570
nft_table_lookup net/netfilter/nf_tables_api.c:4064 [inline]
nf_tables_getset+0x1b3/0x860 net/netfilter/nf_tables_api.c:4064
nfnetlink_rcv_msg+0x659/0x13f0 net/netfilter/nfnetlink.c:285
netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2504
Problem is that all get operations are lockless, so the commit_mutex
held by nft_rcv_nl_event() isn't enough to stop a parallel GET request
from doing read-accesses to the table object even after synchronize_rcu().
To avoid this, unlink the table first and store the table objects in
on-stack scratch space.22dCVE-2020-13599—13.9%
——4——CVE-2024-13707—13.9%
——4——CVE-2025-5812—13.9%
——4——CVE-2025-6659—13.9%
——4——CVE-2024-36939—13.9%
——4——CVE-2021-36855—13.9%
——4——CVE-2023-35012—13.9%
——4——CVE-2017-18327—13.9%
——4——CVE-2022-48867—13.9%
——4——CVE-2021-26327—13.9%
——4——CVE-2024-45073—13.9%
——4——CVE-2025-26603—13.9%
——4——CVE-2025-10945—13.9%
——4——CVE-2026-110985.3 MED13.9%
——4Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)34dCVE-2025-12527—13.9%
——4——CVE-2025-6261—13.9%
——4——CVE-2026-33766—13.9%
——4——CVE-2026-583797.3 HIG13.9%
——4A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.44d