Vulnerabilities exploitable today
354,883in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,556
- High9,177
- Medium7,435
- Low692
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-10553—6.3%
——2——CVE-2025-59115—6.3%
——2——CVE-2026-2002—6.3%
——2——CVE-2023-28075—6.3%
——2——CVE-2025-36145—6.3%
——2——CVE-2025-50036—6.3%
——2——CVE-2026-335536.1 MED6.3%
——2Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.11dCVE-2025-37912—6.3%
——2——CVE-2023-53763—6.3%
——2——CVE-2025-62626—6.3%
——2——CVE-2025-10551—6.3%
——2——CVE-2023-28191—6.3%
——2——CVE-2026-74527.8 HIG6.3%
——2A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.11dCVE-2024-39296—6.3%
——2——CVE-2024-50260—6.3%
——2——CVE-2024-56694—6.3%
——2——CVE-2026-602656.0 MED6.3%
——2Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).7dCVE-2025-44612—6.3%
——2——CVE-2026-3177—6.3%
——2——CVE-2024-4403—6.3%
——2——CVE-2026-96736.8 MED6.3%
——2Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.30dCVE-2025-53249—6.3%
——2——CVE-2024-53934—6.3%
——2——CVE-2026-64038—6.3%
——2In the Linux kernel, the following vulnerability has been resolved:
hwmon: (lm90) Stop work before releasing hwmon device
Sashiko reports:
In lm90_probe(), the devm action to cancel the alert_work and report_work
(lm90_restore_conf) is registered in lm90_init_client() before
devm_hwmon_device_register_with_info() is called.
Because devm executes cleanup actions in reverse order during module
unbind or probe failure, the hwmon device is unregistered and freed first.
If lm90_alert_work() or lm90_report_alarms() runs in the window between
the hwmon device being freed and the delayed works being cancelled,
lm90_update_alarms() will dereference the freed data->hwmon_dev here.
Fix the problem by canceling the workers separately after registering
the hwmon device and before registering the interrupt handler. This ensures
that the workers are canceled after interrupts are disabled and before
the hwmon device is released. Add "shutdown" flag to indicate that device
shutdown is in progress to prevent workers from being re-armed.4dCVE-2024-6751—6.3%
——2——CVE-2023-53814—6.3%
——2——CVE-2024-45245—6.3%
——2——CVE-2026-57234—6.3%
——2——CVE-2023-53752—6.3%
——2——CVE-2025-26902—6.3%
——2——CVE-2026-40606—6.3%
——2——CVE-2021-0348—6.3%
——2——CVE-2023-28396—6.3%
——2——CVE-2018-9545—6.3%
——2——CVE-2025-49237—6.3%
——2——CVE-2021-27701—6.3%
——2——CVE-2026-32527—6.3%
——2——CVE-2024-26837—6.3%
——2——CVE-2026-20165—6.3%
——2——CVE-2026-40505—6.3%
——2——