Vulnerabilities exploitable today
360,835in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,641
- High11,455
- Medium7,085
- Low644
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22283—12.0%
——4——CVE-2024-47038—12.0%
——4——CVE-2024-410867.8 HIG12.0%
——4In the Linux kernel, the following vulnerability has been resolved:
bcachefs: Fix sb_field_downgrade validation
- bch2_sb_downgrade_validate() wasn't checking for a downgrade entry
extending past the end of the superblock section
- for_each_downgrade_entry() is used in to_text() and needs to work on
malformed input; it also was missing a check for a field extending
past the end of the section14dCVE-2025-7502—12.0%
——4——CVE-2024-23238—12.0%
——4——CVE-2026-25532—12.0%
——4——CVE-2026-9241—12.0%
——4——CVE-2025-24087—12.0%
——4——CVE-2026-31943—12.0%
——4——CVE-2022-37025—12.0%
——4——CVE-2025-53121—12.0%
——4——CVE-2025-2134—12.0%
——4——CVE-2023-43537—12.0%
——4——CVE-2026-440634.2 MED12.0%
——4An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.26dCVE-2025-36326—12.0%
——4——CVE-2026-614406.5 MED12.0%
——4PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.31dCVE-2024-53212—12.0%
——4——CVE-2024-39470—12.0%
——4——CVE-2025-21643—12.0%
——4——CVE-2026-28800—12.0%
——4——CVE-2024-42392—12.0%
——4——CVE-2024-32668—12.0%
——4——CVE-2026-689306.5 MED12.0%
——4Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.14dCVE-2026-536344.3 MED12.0%
——4Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the authorization layer and either retrieve the creation form or submit new records for that entity, as long as it had a Quick Creation Command handler configured. This issue has been patched in version 9.22.3.26dCVE-2026-53438—12.0%
——4——CVE-2024-7083—12.0%
——4——CVE-2024-23735—12.0%
——4——CVE-2026-33087.8 HIG12.0%
——4An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution.24dCVE-2022-22303—12.0%
——4——CVE-2024-57896—12.0%
——4——CVE-2024-10539—12.0%
——4——CVE-2025-46714—12.0%
——4——CVE-2023-42834—12.0%
——4——CVE-2024-36479—12.0%
——4——CVE-2024-33850—12.0%
——4——CVE-2024-32449—12.0%
——4——CVE-2026-43568—12.0%
——4——CVE-2021-23179—12.0%
——4——CVE-2024-21458—12.0%
——4——CVE-2024-52586—12.0%
——4——