Vulnerabilities exploitable today
358,955in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,690
- High11,550
- Medium7,259
- Low674
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-58858—10.6%
——3——CVE-2021-43772—10.6%
——3——CVE-2025-29314—10.6%
——3——CVE-2017-202335.4 MED10.6%
——3Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can inject or observe multicast and broadcast packets that should have been blocked by the firewall.23dCVE-2023-6804—10.6%
——3——CVE-2023-38524—10.6%
——3——CVE-2025-39561—10.6%
——3——CVE-2026-287647.8 HIG10.5%
——3MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability21dCVE-2026-3492—10.5%
——3——CVE-2019-16206—10.5%
——3——CVE-2025-20967—10.5%
——3——CVE-2025-21713—10.5%
——3——CVE-2023-54279—10.5%
——3——CVE-2025-1413—10.5%
——3——CVE-2024-8244—10.5%
——3——CVE-2024-31433—10.5%
——3——CVE-2024-31376—10.5%
——3——CVE-2026-87226.5 MED10.5%
——3Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections.
The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.22dCVE-2025-11570—10.5%
——3——CVE-2024-358747.8 HIG10.5%
——3In the Linux kernel, the following vulnerability has been resolved:
aio: Fix null ptr deref in aio_complete() wakeup
list_del_init_careful() needs to be the last access to the wait queue
entry - it effectively unlocks access.
Previously, finish_wait() would see the empty list head and skip taking
the lock, and then we'd return - but the completion path would still
attempt to do the wakeup after the task_struct pointer had been
overwritten.9dCVE-2025-62980—10.5%
——3——CVE-2026-1629—10.5%
——3——CVE-2016-20043—10.5%
——3——CVE-2018-5838—10.5%
——3——CVE-2024-44172—10.5%
——3——CVE-2025-33233—10.5%
——3——CVE-2024-37241—10.5%
——3——CVE-2026-25230—10.5%
——3——CVE-2025-65472—10.5%
——3——CVE-2023-54282—10.5%
——3——CVE-2023-24454—10.5%
——3——CVE-2024-0068—10.5%
——3——CVE-2025-575695.6 MED10.5%
——3Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.40dCVE-2025-23330—10.5%
——3——CVE-2025-31170—10.5%
——3——CVE-2025-11413—10.5%
——3——CVE-2022-50884—10.5%
——3——CVE-2026-26182—10.5%
——3——CVE-2024-58124—10.5%
——3——CVE-2025-43270—10.5%
——3——