Vulnerabilities exploitable today
354,953in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,556
- High9,179
- Medium7,436
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-48076—6.4%
——2——CVE-2025-57107—6.4%
——2——CVE-2023-30737—6.4%
——2——CVE-2025-26899—6.4%
——2——CVE-2021-30327—6.4%
——2——CVE-2026-47777—6.4%
——2——CVE-2023-28960—6.4%
——2——CVE-2023-45173—6.4%
——2——CVE-2025-22688—6.4%
——2——CVE-2024-33672—6.4%
——2——CVE-2026-44429—6.4%
——2——CVE-2025-68249—6.4%
——2——CVE-2025-11947—6.4%
——2——CVE-2026-25362—6.4%
——2——CVE-2026-351486.3 MED6.4%
——2HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.13dCVE-2026-48157—6.3%
——2——CVE-2025-68244—6.4%
——2——CVE-2022-41700—6.4%
——2——CVE-2025-38153—6.4%
——2——CVE-2021-37641—6.4%
——2——CVE-2025-9098—6.4%
——2——CVE-2026-27898—6.4%
——2——CVE-2022-20495—6.3%
——2——CVE-2023-54326—6.4%
——2——CVE-2023-34315—6.4%
——2——CVE-2025-380987.8 HIG6.4%
——2In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink
Don't try to operate on a drm_wb_connector as an amdgpu_dm_connector.
While dereferencing aconnector->base will "work" it's wrong and
might lead to unknown bad things. Just... don't.4dCVE-2024-21120—6.4%
——2——CVE-2024-28023—6.4%
——2——CVE-2026-48940—6.4%
——2——CVE-2022-38786—6.4%
——2——CVE-2023-40154—6.4%
——2——CVE-2026-32508—6.4%
——2——CVE-2023-39432—6.4%
——2——CVE-2022-32483—6.4%
——2——CVE-2023-27305—6.4%
——2——CVE-2026-43883—6.4%
——2——CVE-2025-11989—6.4%
——2——CVE-2026-48480—6.3%
——2The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.12dCVE-2020-0051—6.4%
——2——CVE-2024-30124—6.4%
——2——