Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-34333—7.5%
——2——CVE-2024-38597—7.5%
——2——CVE-2026-35902—7.5%
——2——CVE-2021-27487—7.5%
——2——CVE-2025-3099—7.5%
——2——CVE-2024-49980—7.5%
——2——CVE-2026-347077.8 HIG7.5%
——2InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.15dCVE-2025-1353—7.5%
——2——CVE-2025-66162—7.5%
——2——CVE-2024-30946—7.5%
——2——CVE-2025-61670—7.5%
——2——CVE-2020-9939—7.5%
——2——CVE-2023-53793—7.5%
——2——CVE-2025-36730—7.5%
——2——CVE-2025-66163—7.5%
——2——CVE-2023-37243—7.5%
——2——CVE-2025-68198—7.5%
——2——CVE-2025-66166—7.5%
——2——CVE-2023-53777—7.5%
——2——CVE-2025-43486—7.5%
——2——CVE-2025-66164—7.5%
——2——CVE-2025-66165—7.5%
——2——CVE-2025-653966.1 MED7.5%
——2A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data pin of the IC to ground. An attacker can then dump the entire firmware, leading to the disclosure of sensitive information including cryptographic keys and user configurations.33dCVE-2018-11302—7.5%
——2——CVE-2026-45038—7.5%
——2——CVE-2026-41127—7.5%
——2——CVE-2023-22330—7.5%
——2——CVE-2025-68173—7.5%
——2——CVE-2025-66147—7.5%
——2——CVE-2023-53798—7.5%
——2——CVE-2024-37237—7.5%
——2——CVE-2026-225695.4 MED7.5%
——2An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.14dCVE-2025-231315.5 MED7.5%
——2In the Linux kernel, the following vulnerability has been resolved:
dlm: prevent NPD when writing a positive value to event_done
do_uevent returns the value written to event_done. In case it is a
positive value, new_lockspace would undo all the work, and lockspace
would not be set. __dlm_new_lockspace, however, would treat that
positive value as a success due to commit 8511a2728ab8 ("dlm: fix use
count with multiple joins").
Down the line, device_create_lockspace would pass that NULL lockspace to
dlm_find_lockspace_local, leading to a NULL pointer dereference.
Treating such positive values as successes prevents the problem. Given
this has been broken for so long, this is unlikely to break userspace
expectations.34dCVE-2026-272225.5 MED7.5%
——2Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Divide By Zero vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or render it unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.18dCVE-2026-73624.3 MED7.5%
——2IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.4dCVE-2024-57790—7.5%
——2——CVE-2025-59261—7.5%
——2——CVE-2022-20220—7.5%
——2——CVE-2023-21430—7.5%
——2——CVE-2025-15413—7.5%
——2——