Vulnerabilities exploitable today
355,262in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,657
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,741
- High11,060
- Medium7,345
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-37667—7.0%
——2——CVE-2021-37666—7.0%
——2——CVE-2022-49911—7.0%
——2——CVE-2022-29508—7.0%
——2——CVE-2024-28809—7.0%
——2——CVE-2026-40896—7.0%
——2——CVE-2026-42150—7.0%
——2——CVE-2025-218827.8 HIG7.0%
——2In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix vport QoS cleanup on error
When enabling vport QoS fails, the scheduling node was never freed,
causing a leak.
Add the missing free and reset the vport scheduling node pointer to
NULL.5dCVE-2025-6773—7.0%
——2——CVE-2025-2555—7.0%
——2——CVE-2026-32105—7.0%
——2——CVE-2025-8325—7.0%
——2——CVE-2021-37652—7.0%
——2——CVE-2023-528257.8 HIG7.0%
——2In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix a race condition of vram buffer unref in svm code
prange->svm_bo unref can happen in both mmu callback and a callback after
migrate to system ram. Both are async call in different tasks. Sync svm_bo
unref operation to avoid random "use-after-free".2hCVE-2026-542443.5 LOW7.0%
——2Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. This issue is fixed in versions 5.74.0 and 6.20.3.12dCVE-2025-40091—7.0%
——2——CVE-2025-23135—7.0%
——2——CVE-2025-40073—7.0%
——2——CVE-2022-30262—7.0%
——2——CVE-2021-37663—7.0%
——2——CVE-2025-36139—7.0%
——2——CVE-2026-163819.1 CRI7.0%
——2Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.11dCVE-2025-38104—7.0%
——2——CVE-2025-40066—7.0%
——2——CVE-2024-34612—7.0%
——2——CVE-2025-53754—7.0%
——2——CVE-2021-37639—7.0%
——2——CVE-2025-14721—7.0%
——2——CVE-2024-3511—7.0%
——2——CVE-2026-50021—7.0%
——2——CVE-2026-02826.5 MED7.0%
——2A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory.
The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not impacted by this vulnerability.22dCVE-2025-4760—7.0%
——2——CVE-2023-46669—7.0%
——2——CVE-2026-663385.4 MED7.0%
——2A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.8dCVE-2024-26962—7.0%
——2——CVE-2026-8274—7.0%
——2——CVE-2026-201324.8 MED7.0%
——2Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.
These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.33dCVE-2025-37806—7.0%
——2——CVE-2025-40089—7.0%
——2——CVE-2026-36933—7.0%
——2——