Vulnerabilities exploitable today
358,987in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,465
- High10,986
- Medium6,932
- Low650
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-12553—10.7%
——3——CVE-2022-50575—10.7%
——3——CVE-2026-5163—10.7%
——3——CVE-2026-454105.3 MED10.7%
——3TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, the backend performed a bcrypt password comparison before returning a 401 Unauthorized, adding ~370 ms of latency. When the email did not exist, the backend returned immediately (~10 ms). This ~14× timing difference could be detected without any difference in HTTP status codes or response bodies. This vulnerability is fixed in 3.0.18.24dCVE-2025-57714—10.7%
——3——CVE-2024-32268—10.7%
——3——CVE-2023-52706—10.7%
——3——CVE-2025-7225—10.7%
——3——CVE-2021-46995—10.7%
——3——CVE-2025-67556—10.7%
——3——CVE-2026-624235.5 MED10.7%
——3[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:
* The directory loop itself assumes a good record length. This is
CVE-2026-42494.
* The calculation of the System Use area may underflow. This is
CVE-2026-42495.
* The Rock Ridge extension loop assumes a good (inner) record length.
This is CVE-2026-62423.
* The Rock Ridge NM record processing assumes a good entry length.
This is CVE-2026-62424.
* The Rock Ridge CE record processing assumes a good size and offset.
This is CVE-2026-62425.17dCVE-2026-57653—10.7%
——3——CVE-2022-3698—10.7%
——3——CVE-2026-23671—10.7%
——3——CVE-2025-7244—10.7%
——3——CVE-2026-24296—10.7%
——3——CVE-2021-47042—10.7%
——3——CVE-2025-26737—10.7%
——3——CVE-2026-624245.5 MED10.7%
——3[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:
* The directory loop itself assumes a good record length. This is
CVE-2026-42494.
* The calculation of the System Use area may underflow. This is
CVE-2026-42495.
* The Rock Ridge extension loop assumes a good (inner) record length.
This is CVE-2026-62423.
* The Rock Ridge NM record processing assumes a good entry length.
This is CVE-2026-62424.
* The Rock Ridge CE record processing assumes a good size and offset.
This is CVE-2026-62425.17dCVE-2025-12064—10.7%
——3——CVE-2026-559985.3 MED10.7%
——3The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle.9dCVE-2023-28000—10.7%
——3——CVE-2023-32426—10.7%
——3——CVE-2024-28948—10.7%
——3——CVE-2024-53288—10.7%
——3——CVE-2026-330207.1 HIG10.7%
——3libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel count exceeds INT_MAX / 4, the overflow produces an undersized heap allocation for the conversion buffer and a negative pointer offset for the normalization sub-buffer, after which sixel_helper_normalize_pixelformat() writes the full image data starting from the invalid pointer, causing massive heap corruption confirmed by ASAN. An attacker providing a specially crafted large palettised PNG can corrupt the heap of the victim process, resulting in a reliable crash and potential arbitrary code execution.
This issue has been fixed in version 1.8.7-r1.20dCVE-2024-38797—10.7%
——3——CVE-2026-424955.5 MED10.7%
——3[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:
* The directory loop itself assumes a good record length. This is
CVE-2026-42494.
* The calculation of the System Use area may underflow. This is
CVE-2026-42495.
* The Rock Ridge extension loop assumes a good (inner) record length.
This is CVE-2026-62423.
* The Rock Ridge NM record processing assumes a good entry length.
This is CVE-2026-62424.
* The Rock Ridge CE record processing assumes a good size and offset.
This is CVE-2026-62425.17dCVE-2025-7226—10.7%
——3——CVE-2023-38531—10.7%
——3——CVE-2023-3359—10.7%
——3——CVE-2026-37535—10.7%
——3——CVE-2023-32199—10.7%
——3——CVE-2025-12193—10.7%
——3——CVE-2025-63033—10.7%
——3——CVE-2026-30876—10.7%
——3——CVE-2023-52914—10.7%
——3——CVE-2026-24295—10.7%
——3——CVE-2022-48886—10.7%
——3——CVE-2026-0503—10.7%
——3——