Vulnerabilities exploitable today
355,177in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,532
- High9,184
- Medium7,411
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-41629—6.8%
——2——CVE-2026-49406—6.8%
——2——CVE-2026-7511—6.8%
——2——CVE-2025-38138—6.8%
——2——CVE-2025-49358—6.8%
——2——CVE-2024-43299—6.8%
——2——CVE-2024-31870—6.8%
——2——CVE-2023-53736—6.8%
——2——CVE-2023-30722—6.8%
——2——CVE-2025-43341—6.8%
——2——CVE-2025-48021—6.8%
——2——CVE-2026-27977—6.8%
——2——CVE-2025-48022—6.8%
——2——CVE-2026-533667.8 HIG6.8%
——2In the Linux kernel, the following vulnerability has been resolved:
ipv4: account for fraggap on the paged allocation path
In __ip_append_data(), when the paged-allocation branch is taken,
alloclen and pagedlen are computed as
alloclen = fragheaderlen + transhdrlen;
pagedlen = datalen - transhdrlen;
datalen already includes fraggap, but the fraggap bytes carried over
from the previous skb are copied into the new skb's linear area at
offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The
linear area is therefore undersized by fraggap bytes while pagedlen is
overstated by the same amount.
The non-paged branch sets alloclen to fraglen, which already accounts
for fraggap because datalen does. Bring the paged branch in line by
adding fraggap to alloclen and subtracting it from pagedlen.
After this adjustment, copy no longer collapses to -fraggap on the
paged path, so remove the stale comment describing that old arithmetic.10dCVE-2026-273494.3 MED6.8%
——2Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data.
This issue affects Mail Mint: from n/a through 1.19.5.11dCVE-2026-565713.7 LOW6.8%
——2HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.3dCVE-2025-62258—6.8%
——2——CVE-2025-48023—6.8%
——2——CVE-2026-485595.4 MED6.8%
——2Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.13dCVE-2023-20597—6.8%
——2——CVE-2021-36277—6.8%
——2——CVE-2025-2793—6.8%
——2——CVE-2024-22449—6.8%
——2——CVE-2025-39701—6.8%
——2——CVE-2023-38299—6.8%
——2——CVE-2025-38332—6.8%
——2——CVE-2025-67858—6.8%
——2——CVE-2023-21510—6.8%
——2——CVE-2026-387667.8 HIG6.8%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function10dCVE-2024-2502—6.8%
——2——CVE-2024-54455—6.8%
——2——CVE-2023-24502—6.8%
——2——CVE-2023-4129—6.8%
——2——CVE-2025-14412—6.8%
——2——CVE-2025-62752—6.8%
——2——CVE-2025-68257—6.8%
——2——CVE-2025-68258—6.8%
——2——CVE-2023-21500—6.8%
——2——CVE-2025-258185.1 MED6.8%
——2A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.30dCVE-2025-62095—6.8%
——2——