Vulnerabilities exploitable today
359,428in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,475
- High11,085
- Medium7,046
- Low645
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-54427—10.9%
——3——CVE-2016-20045—10.9%
——3——CVE-2026-6593—10.9%
——3——CVE-2026-234407.5 HIG10.9%
——3In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix race condition during IPSec ESN update
In IPSec full offload mode, the device reports an ESN (Extended
Sequence Number) wrap event to the driver. The driver validates this
event by querying the IPSec ASO and checking that the esn_event_arm
field is 0x0, which indicates an event has occurred. After handling
the event, the driver must re-arm the context by setting esn_event_arm
back to 0x1.
A race condition exists in this handling path. After validating the
event, the driver calls mlx5_accel_esp_modify_xfrm() to update the
kernel's xfrm state. This function temporarily releases and
re-acquires the xfrm state lock.
So, need to acknowledge the event first by setting esn_event_arm to
0x1. This prevents the driver from reprocessing the same ESN update if
the hardware sends events for other reason. Since the next ESN update
only occurs after nearly 2^31 packets are received, there's no risk of
missing an update, as it will happen long after this handling has
finished.
Processing the event twice causes the ESN high-order bits (esn_msb) to
be incremented incorrectly. The driver then programs the hardware with
this invalid ESN state, which leads to anti-replay failures and a
complete halt of IPSec traffic.
Fix this by re-arming the ESN event immediately after it is validated,
before calling mlx5_accel_esp_modify_xfrm(). This ensures that any
spurious, duplicate events are correctly ignored, closing the race
window.21dCVE-2023-25952—10.9%
——3——CVE-2026-25312—10.9%
——3——CVE-2025-29426—10.9%
——3——CVE-2025-66910—10.9%
——3——CVE-2026-7919—10.9%
——3——CVE-2024-58115—10.9%
——3——CVE-2024-58116—10.9%
——3——CVE-2026-24932—10.9%
——3——CVE-2024-54435—10.9%
——3——CVE-2024-342687.1 HIG10.9%
——3EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.28dCVE-2024-51653—10.9%
——3——CVE-2021-23179—10.9%
——3——CVE-2025-54458—10.9%
——3——CVE-2024-54411—10.9%
——3——CVE-2022-48307—10.9%
——3——CVE-2026-7920—10.9%
——3——CVE-2025-31188—10.9%
——3——CVE-2018-25149—10.9%
——3——CVE-2024-54423—10.9%
——3——CVE-2024-54414—10.9%
——3——CVE-2024-9019—10.9%
——3——CVE-2026-58362.4 LOW10.9%
——3A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument product_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.22dCVE-2022-50815—10.9%
——3——CVE-2023-53978—10.9%
——3——CVE-2026-4595—10.9%
——3——CVE-2022-42879—10.9%
——3——CVE-2024-54436—10.9%
——3——CVE-2019-25689—10.9%
——3——CVE-2023-53977—10.9%
——3——CVE-2026-101714.7 MED10.9%
——3A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.24dCVE-2026-22008—10.9%
——3——CVE-2025-5730—10.9%
——3——CVE-2024-53114—10.9%
——3——CVE-2026-7923—10.9%
——3——CVE-2026-8714—10.9%
——3——CVE-2025-12440—10.9%
——3——