Vulnerabilities exploitable today
360,749in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,492
- High11,026
- Medium7,021
- Low631
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-32485—11.9%
——4——CVE-2026-27706—11.9%
——4——CVE-2023-43574—11.9%
——4——CVE-2026-423457.7 HIG11.9%
——4FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a fullUrl.startsWith() check against a hardcoded list. This check can be bypassed using at least 7 different URL encoding techniques, all of which resolve to the same cloud metadata service but do not match the blocklist patterns. Additionally, the broader private IP check (isInternalIPv4/isInternalIPv6) is disabled by default because CHECK_INTERNAL_IP defaults to false (not 'true'), so these bypasses reach the metadata endpoint without any further validation. At time of publication, there are no publicly available patches.23dCVE-2025-13311—11.9%
——4——CVE-2025-62031—11.9%
——4——CVE-2025-40264—11.9%
——4——CVE-2024-7867—11.9%
——4——CVE-2025-10282—11.9%
——4——CVE-2024-56652—11.9%
——4——CVE-2024-9352—11.9%
——4——CVE-2024-36589—11.9%
——4——CVE-2024-9649—11.9%
——4——CVE-2024-42603—11.9%
——4——CVE-2023-28202—11.9%
——4——CVE-2026-2201—11.9%
——4——CVE-2024-45737—11.9%
——4——CVE-2026-41259—11.9%
——4——CVE-2025-4338—11.9%
——4——CVE-2025-53631—11.9%
——4——CVE-2024-477487.8 HIG11.9%
——4In the Linux kernel, the following vulnerability has been resolved:
vhost_vdpa: assign irq bypass producer token correctly
We used to call irq_bypass_unregister_producer() in
vhost_vdpa_setup_vq_irq() which is problematic as we don't know if the
token pointer is still valid or not.
Actually, we use the eventfd_ctx as the token so the life cycle of the
token should be bound to the VHOST_SET_VRING_CALL instead of
vhost_vdpa_setup_vq_irq() which could be called by set_status().
Fixing this by setting up irq bypass producer's token when handling
VHOST_SET_VRING_CALL and un-registering the producer before calling
vhost_vring_ioctl() to prevent a possible use after free as eventfd
could have been released in vhost_vring_ioctl(). And such registering
and unregistering will only be done if DRIVER_OK is set.13dCVE-2025-6271—11.9%
——4——CVE-2021-47495—11.9%
——4——CVE-2026-29043—11.9%
——4——CVE-2025-11497—11.9%
——4——CVE-2025-378917.8 HIG11.9%
——4In the Linux kernel, the following vulnerability has been resolved:
ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
The conversion function from MIDI 1.0 to UMP packet contains an
internal buffer to keep the incoming MIDI bytes, and its size is 4, as
it was supposed to be the max size for a MIDI1 UMP packet data.
However, the implementation overlooked that SysEx is handled in a
different format, and it can be up to 6 bytes, as found in
do_convert_to_ump(). It leads eventually to a buffer overflow, and
may corrupt the memory when a longer SysEx message is received.
The fix is simply to extend the buffer size to 6 to fit with the SysEx
UMP message.18dCVE-2020-0444—11.9%
——4——CVE-2024-53199—11.9%
——4——CVE-2026-5516—11.9%
——4——CVE-2021-429237.3 HIG11.9%
——4ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-ShowMyPC3606\wodVPN.dll, it will run any malicious code contained in that file. The code will run with normal user privileges unless the user specifically runs ShowMyPC as administrator.39dCVE-2026-27444—11.9%
——4——CVE-2026-92244.3 MED11.9%
——4Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier24dCVE-2021-47389—11.9%
——4——CVE-2026-92464.3 MED11.9%
——4Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier24dCVE-2026-24070—11.9%
——4——CVE-2025-43260—11.9%
——4——CVE-2024-12706—11.9%
——4——CVE-2023-43572—11.9%
——4——CVE-2025-10281—11.9%
——4——CVE-2024-42606—11.9%
——4——