Vulnerabilities exploitable today
356,426in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603
Distribution · last window
- Critical2,802
- High11,190
- Medium7,403
- Low703
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-32617—7.5%
——2——CVE-2022-31221—7.5%
——2——CVE-2026-119252.7 LOW7.5%
——2Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.15dCVE-2026-346277.8 HIG7.5%
——2InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.13dCVE-2026-39316—7.5%
——2——CVE-2023-34314—7.5%
——2——CVE-2026-27267—7.5%
——2——CVE-2022-28757—7.5%
——2——CVE-2024-2971—7.5%
——2——CVE-2024-49790—7.5%
——2——CVE-2025-64548—7.5%
——2——CVE-2023-39284—7.5%
——2——CVE-2026-54040—7.5%
——2——CVE-2026-13281—7.5%
——2——CVE-2025-12624—7.5%
——2——CVE-2025-36042—7.5%
——2——CVE-2025-64869—7.4%
——2——CVE-2026-557984.5 MED7.5%
——2Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(..., shell=True), allowing shell metacharacters in the file path to inject arbitrary cmd.exe commands. This issue is fixed in version 12.3.0.30dCVE-2026-112473.1 LOW7.5%
——2Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)15dCVE-2026-657107.1 HIG7.5%
——2sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the public link creation flow. Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountService::getDataForLink to load arbitrary target accounts without AccountFilterUser restrictions, decrypt credentials using the session master key, and serialize cleartext passwords into Vault storage on the PublicLink database row, enabling subsequent unauthenticated retrieval if the generated link hash is recovered.10dCVE-2026-32932—7.5%
——2——CVE-2025-4233—7.5%
——2——CVE-2024-33611—7.5%
——2——CVE-2025-64602—7.5%
——2——CVE-2026-118874.3 MED7.5%
——2The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.36dCVE-2025-11777—7.5%
——2——CVE-2026-346287.8 HIG7.5%
——2InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.13dCVE-2019-25550—7.5%
——2——CVE-2023-32831—7.4%
——2——CVE-2025-64853—7.4%
——2——CVE-2025-64622—7.4%
——2——CVE-2025-64559—7.4%
——2——CVE-2025-59026—7.4%
——2——CVE-2026-7422—7.4%
——2——CVE-2026-570196.5 MED7.4%
——2An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).
When a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered.
Affected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE).
When this issue happens the following logs can be observed:
fpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default
fpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default
This issue affects Junos OS on MX Series:
* all versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S7,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2.24dCVE-2025-64829—7.4%
——2——CVE-2025-30190—7.4%
——2——CVE-2024-32667—7.4%
——2——CVE-2025-64800—7.4%
——2——CVE-2024-11014—7.4%
——2——