Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,538
- High10,642
- Medium6,744
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-22543—8.3%
——2——CVE-2026-69248—8.3%
——2cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.4dCVE-2025-53579—8.3%
——2——CVE-2026-24985—8.3%
——2——CVE-2022-50030—8.3%
——2——CVE-2023-3363—8.3%
——2——CVE-2023-29113—8.3%
——2——CVE-2025-47578—8.3%
——2——CVE-2026-429797.8 HIG8.3%
——2Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.17dCVE-2019-2122—8.3%
——2——CVE-2025-43381—8.3%
——2——CVE-2026-606438.0 HIG8.3%
——2Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).10dCVE-2026-22450—8.3%
——2——CVE-2025-70048—8.3%
——2——CVE-2026-25329—8.3%
——2——CVE-2020-9713—8.3%
——2——CVE-2025-56463—8.3%
——2——CVE-2025-65104—8.3%
——2——CVE-2020-9711—8.3%
——2——CVE-2024-35295—8.3%
——2——CVE-2026-29773—8.3%
——2——CVE-2026-273924.3 MED8.3%
——2Contributor Broken Access Control in uListing <= 2.2.0 versions.16dCVE-2026-24579—8.3%
——2——CVE-2025-43837—8.3%
——2——CVE-2025-54055—8.3%
——2——CVE-2026-24522—8.3%
——2——CVE-2023-22883—8.3%
——2——CVE-2023-24523—8.3%
——2——CVE-2021-1940—8.3%
——2——CVE-2025-43839—8.3%
——2——CVE-2026-64484—8.3%
——2In the Linux kernel, the following vulnerability has been resolved:
ALSA: es1938: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_es1938_mixer() does not check the return value before dereferencing
the pointer, which can lead to a NULL pointer dereference.
Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.15dCVE-2025-6232—8.3%
——2——CVE-2023-53346—8.3%
——2——CVE-2022-35120—8.3%
——2——CVE-2026-35349—8.3%
——2——CVE-2025-43472—8.3%
——2——CVE-2025-6231—8.3%
——2——CVE-2026-113488.1 HIG8.3%
——2Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data.
This issue affects Liman MYS: before release.Master.1107.32dCVE-2026-24580—8.3%
——2——CVE-2019-25621—8.3%
——2——