Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,538
- High10,643
- Medium6,744
- Low670
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-24344—8.2%
——2——CVE-2025-30255—8.2%
——2——CVE-2019-2011—8.2%
——2——CVE-2024-43169—8.2%
——2——CVE-2025-71178—8.2%
——2——CVE-2025-2871—8.2%
——2——CVE-2025-47677—8.2%
——2——CVE-2026-347622.7 LOW8.2%
——2Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's policy while the audit trail records a fabricated or unrelated subscriber IMSI. This issue has been patched in version 1.8.0.15dCVE-2025-48080—8.2%
——2——CVE-2025-11235—8.2%
——2——CVE-2021-37665—8.2%
——2——CVE-2025-0459—8.2%
——2——CVE-2025-48113—8.2%
——2——CVE-2026-53845—8.2%
——2——CVE-2025-35971—8.2%
——2——CVE-2022-32766—8.2%
——2——CVE-2025-24831—8.2%
——2——CVE-2022-43380—8.2%
——2——CVE-2022-39165—8.2%
——2——CVE-2025-62965—8.2%
——2——CVE-2022-43381—8.2%
——2——CVE-2017-15405—8.2%
——2——CVE-2026-32320—8.2%
——2——CVE-2025-53839—8.2%
——2——CVE-2025-33029—8.2%
——2——CVE-2022-50369—8.2%
——2——CVE-2026-160715.4 MED8.2%
——2A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.2dCVE-2025-13992—8.2%
——2——CVE-2023-33121—8.2%
——2——CVE-2026-64488—8.2%
——2In the Linux kernel, the following vulnerability has been resolved:
ALSA: aoa: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails. In
layout.c, the function does not check the return value before
dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can
lead to a NULL pointer dereference.
Add NULL checks after snd_ctl_new1() calls and return early if any
fails.15dCVE-2022-50689—8.2%
——2——CVE-2019-9449—8.2%
——2——CVE-2024-39465—8.2%
——2——CVE-2025-35030—8.2%
——2——CVE-2026-13025—8.2%
——2——CVE-2025-25769—8.2%
——2——CVE-2024-51141—8.2%
——2——CVE-2026-5501—8.2%
——2——CVE-2020-11267—8.2%
——2——CVE-2023-53349—8.2%
——2——