Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-441195.5 MED7.5%
——2Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.15dCVE-2023-22024—7.5%
——2——CVE-2025-384667.8 HIG7.5%
——2In the Linux kernel, the following vulnerability has been resolved:
perf: Revert to requiring CAP_SYS_ADMIN for uprobes
Jann reports that uprobes can be used destructively when used in the
middle of an instruction. The kernel only verifies there is a valid
instruction at the requested offset, but due to variable instruction
length cannot determine if this is an instruction as seen by the
intended execution stream.
Additionally, Mark Rutland notes that on architectures that mix data
in the text segment (like arm64), a similar things can be done if the
data word is 'mistaken' for an instruction.
As such, require CAP_SYS_ADMIN for uprobes.8dCVE-2024-36899—7.5%
——2——CVE-2025-71244—7.5%
——2——CVE-2025-46836—7.5%
——2——CVE-2025-31973—7.5%
——2——CVE-2025-37809—7.5%
——2——CVE-2026-25905—7.5%
——2——CVE-2018-25266—7.5%
——2——CVE-2021-38121—7.5%
——2——CVE-2017-2723—7.5%
——2——CVE-2025-6027—7.5%
——2——CVE-2025-64378—7.5%
——2——CVE-2026-7971—7.5%
——2——CVE-2026-11877—7.5%
——2——CVE-2025-64574—7.5%
——2——CVE-2025-64600—7.5%
——2——CVE-2025-33082—7.5%
——2——CVE-2022-41975—7.5%
——2——CVE-2024-26861—7.5%
——2——CVE-2026-40118—7.5%
——2——CVE-2021-22422—7.5%
——2——CVE-2026-21288—7.5%
——2——CVE-2021-22420—7.5%
——2——CVE-2021-22418—7.5%
——2——CVE-2026-470894.3 MED7.5%
——2An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)21dCVE-2026-477377.5 HIG7.5%
——2Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite REMOTE_ADDR. This issue is fixed in versions 7.2.1 and 8.0.2.23dCVE-2021-22423—7.5%
——2——CVE-2025-64833—7.4%
——2——CVE-2026-145156.1 MED7.5%
——2IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack.2dCVE-2025-48263—7.5%
——2——CVE-2026-346297.8 HIG7.5%
——2InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.13dCVE-2023-21086—7.5%
——2——CVE-2025-33083—7.5%
——2——CVE-2025-14702—7.5%
——2——CVE-2024-57879—7.5%
——2——CVE-2024-3900—7.5%
——2——CVE-2024-3246—7.5%
——2——CVE-2026-6051—7.5%
——2——