Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,150
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-1985—13.8%
——4——CVE-2026-44466—13.8%
——4——CVE-2024-51406—13.8%
——4——CVE-2026-440997.8 HIG13.8%
——4A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.27dCVE-2021-47780—13.8%
——4——CVE-2020-0137—13.8%
——4——CVE-2022-50738—13.8%
——4——CVE-2022-50768—13.8%
——4——CVE-2009-1215—13.8%
——4——CVE-2024-58034—13.8%
——4——CVE-2022-50674—13.8%
——4——CVE-2023-6409—13.8%
——4——CVE-2025-52883—13.8%
——4——CVE-2026-248698.8 HIG13.8%
——4Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.42dCVE-2024-44128—13.8%
——4——CVE-2026-440967.8 HIG13.8%
——4A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.25dCVE-2024-3175—13.8%
——4——CVE-2026-6501—13.8%
——4——CVE-2022-50748—13.8%
——4——CVE-2022-28196—13.8%
——4——CVE-2024-41043—13.8%
——4——CVE-2025-42929—13.8%
——4——CVE-2024-35139—13.8%
——4——CVE-2026-481076.5 MED13.8%
——4Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.34dCVE-2025-43777—13.8%
——4——CVE-2026-41377—13.8%
——4——CVE-2022-50765—13.8%
——4——CVE-2024-47680—13.8%
——4——CVE-2022-30530—13.8%
——4——CVE-2022-50743—13.8%
——4——CVE-2023-50355—13.8%
——4——CVE-2022-31644—13.8%
——4——CVE-2023-2892—13.8%
——4——CVE-2025-62395—13.8%
——4——CVE-2024-408497.5 HIG13.8%
——4A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.32dCVE-2024-0827—13.8%
——4——CVE-2023-23523—13.8%
——4——CVE-2026-41359—13.8%
——4——CVE-2026-354677.5 HIG13.8%
——4The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.32dCVE-2022-499348.8 HIG13.8%
——4In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: Fix UAF in ieee80211_scan_rx()
ieee80211_scan_rx() tries to access scan_req->flags after a
null check, but a UAF is observed when the scan is completed
and __ieee80211_scan_completed() executes, which then calls
cfg80211_scan_done() leading to the freeing of scan_req.
Since scan_req is rcu_dereference()'d, prevent the racing in
__ieee80211_scan_completed() by ensuring that from mac80211's
POV it is no longer accessed from an RCU read critical section
before we call cfg80211_scan_done().22d