Vulnerabilities exploitable today
364,588in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,675
New KEV · 24H0
Exploit Today ≥ 701,620
Distribution · last window
- Critical2,405
- High10,150
- Medium5,058
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-3175—13.8%
——4——CVE-2022-50748—13.8%
——4——CVE-2022-28196—13.8%
——4——CVE-2026-6501—13.8%
——4——CVE-2024-41043—13.8%
——4——CVE-2026-1674—13.8%
——4——CVE-2023-2863—13.8%
——4——CVE-2024-12923—13.8%
——4——CVE-2025-30109—13.8%
——4——CVE-2024-31942—13.8%
——4——CVE-2026-440937.8 HIG13.8%
——4A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.27dCVE-2025-12437—13.8%
——4——CVE-2026-44463—13.8%
——4——CVE-2024-48426—13.8%
——4——CVE-2025-24904—13.8%
——4——CVE-2026-36097.8 HIG13.8%
——4Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.20dCVE-2025-4220—13.8%
——4——CVE-2021-36284—13.8%
——4——CVE-2025-8737—13.8%
——4——CVE-2022-28195—13.8%
——4——CVE-2025-43781—13.8%
——4——CVE-2024-29660—13.8%
——4——CVE-2022-45415—13.8%
——4——CVE-2022-31646—13.8%
——4——CVE-2026-483747.8 HIG13.8%
——4Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.23dCVE-2025-22788—13.8%
——4——CVE-2026-538298.0 HIG13.8%
——4OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.34dCVE-2025-8582—13.8%
——4——CVE-2025-46721—13.8%
——4——CVE-2025-4171—13.8%
——4——CVE-2026-196807.1 HIG13.8%
——4A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.6dCVE-2025-402777.8 HIG13.8%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
This data originates from userspace and is used in buffer offset
calculations which could potentially overflow causing an out-of-bounds
access.27dCVE-2026-21294—13.8%
——4——CVE-2026-441067.8 HIG13.8%
——4A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.25dCVE-2025-5315—13.8%
——4——CVE-2023-37605—13.8%
——4——CVE-2023-38579—13.8%
——4——CVE-2026-555936.5 MED13.8%
——4Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a valid session before routing state-changing requests. The editapikey action in Ajax::editApiKey updates allowed_from and valid_until without validating a CSRF token, while templates/Froxlor/assets/js/jquery/apikeys.js sends no token because the endpoint does not require one. An unauthenticated attacker can induce an authenticated administrator's browser to submit a forged request that adds an attacker-controlled address to an API key's allowed_from list or removes its expiration, weakening the key's security restrictions. This issue is fixed in version 2.3.8.6dCVE-2025-6857—13.8%
——4——CVE-2024-53543—13.8%
——4——