Vulnerabilities exploitable today
354,953in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,556
- High9,179
- Medium7,436
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-47777—6.4%
——2——CVE-2023-28960—6.4%
——2——CVE-2021-0298—6.4%
——2——CVE-2022-34401—6.4%
——2——CVE-2023-44190—6.4%
——2——CVE-2025-8354—6.4%
——2——CVE-2026-41004—6.4%
——2——CVE-2023-23434—6.4%
——2——CVE-2026-396075.4 MED6.4%
——2Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17.9dCVE-2023-44194—6.4%
——2——CVE-2022-50929—6.4%
——2——CVE-2022-42974—6.4%
——2——CVE-2023-33867—6.4%
——2——CVE-2023-53123—6.4%
——2——CVE-2022-50693—6.4%
——2——CVE-2024-50220—6.4%
——2——CVE-2025-68371—6.4%
——2In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Fix device resources accessed after device removal
Correct possible race conditions during device removal.
Previously, a scheduled work item to reset a LUN could still execute
after the device was removed, leading to use-after-free and other
resource access issues.
This race condition occurs because the abort handler may schedule a LUN
reset concurrently with device removal via sdev_destroy(), leading to
use-after-free and improper access to freed resources.
- Check in the device reset handler if the device is still present in
the controller's SCSI device list before running; if not, the reset
is skipped.
- Cancel any pending TMF work that has not started in sdev_destroy().
- Ensure device freeing in sdev_destroy() is done while holding the
LUN reset mutex to avoid races with ongoing resets.20dCVE-2025-31601—6.4%
——2——CVE-2021-37657—6.4%
——2——CVE-2025-20326—6.4%
——2——CVE-2023-53143—6.4%
——2——CVE-2025-61761—6.4%
——2——CVE-2026-22717—6.4%
——2——CVE-2025-6034—6.4%
——2——CVE-2025-382838.8 HIG6.4%
——2In the Linux kernel, the following vulnerability has been resolved:
hisi_acc_vfio_pci: bugfix live migration function without VF device driver
If the VF device driver is not loaded in the Guest OS and we attempt to
perform device data migration, the address of the migrated data will
be NULL.
The live migration recovery operation on the destination side will
access a null address value, which will cause access errors.
Therefore, live migration of VMs without added VF device drivers
does not require device data migration.
In addition, when the queue address data obtained by the destination
is empty, device queue recovery processing will not be performed.4dCVE-2020-0060—6.4%
——2——CVE-2020-9147—6.4%
——2——CVE-2024-38778—6.4%
——2——CVE-2023-53632—6.4%
——2——CVE-2020-0016—6.4%
——2——CVE-2026-28864—6.4%
——2——CVE-2026-25651—6.4%
——2——CVE-2026-78749.1 CRI6.4%
——2IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.32dCVE-2026-21971—6.4%
——2——CVE-2026-502149.8 CRI6.4%
——2The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.12dCVE-2023-30696—6.4%
——2——CVE-2026-138637.8 HIG6.4%
——2Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)28dCVE-2022-50090—6.4%
——2——CVE-2024-43930—6.4%
——2——CVE-2026-28036—6.4%
——2——