Vulnerabilities exploitable today
354,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,622
- High9,423
- Medium7,591
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-64236—5.2%
——2In the Linux kernel, the following vulnerability has been resolved:
i2c: davinci: fix division by zero on missing clock-frequency
When the 'clock-frequency' property is missing from the device tree,
the driver falls back to DAVINCI_I2C_DEFAULT_BUS_FREQ. However, this
macro was defined in kHz (100), whereas the device tree property is
expected in Hz.
The probe function divided the fallback value by 1000, causing
integer truncation that resulted in dev->bus_freq = 0. This triggered
a deterministic division-by-zero kernel panic when calculating clock
dividers later in the probe sequence.
Fix this by redefining DAVINCI_I2C_DEFAULT_BUS_FREQ in Hz (100000)
to match the expected device tree property unit, allowing the existing
division logic to work correctly for both cases.1dCVE-2021-0347—5.2%
——2——CVE-2026-7108—5.2%
——2——CVE-2022-20422—5.2%
——2——CVE-2025-38642—5.2%
——2——CVE-2026-21496—5.2%
——2——CVE-2026-45900—5.2%
——2——CVE-2021-1050—5.2%
——2——CVE-2024-35207—5.2%
——2——CVE-2026-45880—5.2%
——2——CVE-2025-68760—5.2%
——2——CVE-2025-38417—5.2%
——2——CVE-2026-5026—5.2%
——2——CVE-2018-25200—5.2%
——2——CVE-2026-606358.8 HIG5.1%
——2Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).2dCVE-2024-36266—5.2%
——2——CVE-2017-9689—5.2%
——2——CVE-2026-20662—5.2%
——2——CVE-2026-45973—5.2%
——2——CVE-2026-565873.7 LOW5.2%
——2HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.2dCVE-2026-21502—5.2%
——2——CVE-2026-21503—5.2%
——2——CVE-2026-28377—5.2%
——2——CVE-2026-40514—5.2%
——2——CVE-2026-21499—5.2%
——2——CVE-2024-11679—5.2%
——2——CVE-2020-4944—5.2%
——2——CVE-2025-69646—5.2%
——2——CVE-2025-59163.9 LOW5.2%
——2A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0.32dCVE-2024-8527—5.2%
——2——CVE-2024-53160—5.2%
——2——CVE-2026-45874—5.2%
——2——CVE-2026-0063—5.2%
——2——CVE-2026-63873—5.2%
——2In the Linux kernel, the following vulnerability has been resolved:
accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
aie2_populate_range() jumps back to the again label without calling
mmput(mm), leaking a reference to the mm_struct.
Add the missing mmput() before jumping to again.4dCVE-2025-38654—5.2%
——2——CVE-2026-41125—5.2%
——2——CVE-2024-43781—5.2%
——2——CVE-2026-21498—5.2%
——2——CVE-2025-2501—5.2%
——2——CVE-2026-8576—5.2%
——2——