Vulnerabilities exploitable today
355,017in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,558
- High9,190
- Medium7,448
- Low695
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-53863—6.6%
——2——CVE-2025-67623—6.6%
——2——CVE-2026-57654—6.6%
——2——CVE-2026-563641.9 LOW6.6%
——2ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.32dCVE-2025-43478—6.6%
——2——CVE-2026-22006—6.6%
——2——CVE-2024-20824—6.6%
——2——CVE-2024-20823—6.6%
——2——CVE-2026-466285.4 MED6.6%
——2Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.19dCVE-2023-53554—6.6%
——2——CVE-2026-28713—6.6%
——2——CVE-2025-48113—6.6%
——2——CVE-2025-49919—6.6%
——2——CVE-2023-28089—6.6%
——2——CVE-2025-61994—6.6%
——2——CVE-2026-563663.3 LOW6.6%
——2ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.21dCVE-2026-26345—6.6%
——2——CVE-2026-596898.0 HIG6.6%
——2An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.6dCVE-2025-156536.8 MED6.6%
——2Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy functions, manipulate device-processed data, or leverage the device as a pivot point for broader network-based attacks when connected to a network or Dräger Service Connect.12dCVE-2025-1696—6.6%
——2——CVE-2022-27599—6.6%
——2——CVE-2025-400688.4 HIG6.6%
——2In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: Fix integer overflow in run_unpack()
The MFT record relative to the file being opened contains its runlist,
an array containing information about the file's location on the physical
disk. Analysis of all Call Stack paths showed that the values of the
runlist array, from which LCNs are calculated, are not validated before
run_unpack function.
The run_unpack function decodes the compressed runlist data format
from MFT attributes (for example, $DATA), converting them into a runs_tree
structure, which describes the mapping of virtual clusters (VCN) to
logical clusters (LCN). The NTFS3 subsystem also has a shortcut for
deleting files from MFT records - in this case, the RUN_DEALLOCATE
command is sent to the run_unpack input, and the function logic
provides that all data transferred to the runlist about file or
directory is deleted without creating a runs_tree structure.
Substituting the runlist in the $DATA attribute of the MFT record for an
arbitrary file can lead either to access to arbitrary data on the disk
bypassing access checks to them (since the inode access check
occurs above) or to destruction of arbitrary data on the disk.
Add overflow check for addition operation.
Found by Linux Verification Center (linuxtesting.org) with SVACE.4dCVE-2025-46263—6.6%
——2——CVE-2025-46262—6.6%
——2——CVE-2018-5861—6.6%
——2——CVE-2024-37144—6.6%
——2——CVE-2025-26168—6.6%
——2——CVE-2017-11078—6.6%
——2——CVE-2024-41776—6.6%
——2——CVE-2023-42772—6.6%
——2——CVE-2023-23441—6.6%
——2——CVE-2021-47671—6.6%
——2——CVE-2025-526064.3 MED6.6%
——2HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.12dCVE-2025-49074—6.6%
——2——CVE-2024-8477—6.6%
——2——CVE-2025-43473—6.6%
——2——CVE-2025-2163—6.6%
——2——CVE-2024-20822—6.6%
——2——CVE-2025-46543—6.6%
——2——CVE-2026-393666.5 MED6.6%
——2WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate their wallet balance and renew subscriptions. The newer ipnV2.php and webhook.php handlers correctly deduplicate via PayPalYPT_log entries, but the v1 handler was never updated and remains actively referenced as the notify_url for billing plans.10d