Vulnerabilities exploitable today
354,538in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,643
- High9,454
- Medium7,665
- Low698
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-47382—4.9%
——1——CVE-2026-28759—4.9%
——1——CVE-2021-40045—4.9%
——1——CVE-2026-20645—4.9%
——1——CVE-2024-36354—4.9%
——1——CVE-2026-23013—4.9%
——1——CVE-2026-0998—4.9%
——1——CVE-2025-58340—4.9%
——1——CVE-2025-20694—4.9%
——1——CVE-2026-98203.8 LOW4.9%
——1Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-0067118dCVE-2025-37986—4.9%
——1——CVE-2025-53548—4.9%
——1——CVE-2024-36316—4.9%
——1——CVE-2026-6689—4.9%
——1——CVE-2024-13961—4.9%
——1——CVE-2025-58344—4.9%
——1——CVE-2025-37971—4.9%
——1——CVE-2025-20901—4.9%
——1——CVE-2026-564585.4 MED4.9%
——1HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.21dCVE-2025-55313—4.9%
——1——CVE-2024-24910—4.9%
——1——CVE-2026-27154—4.9%
——1——CVE-2024-36432—4.9%
——1——CVE-2026-3254—4.9%
——1——CVE-2025-33190—4.9%
——1——CVE-2025-58341—4.9%
——1——CVE-2025-37993—4.9%
——1——CVE-2025-399027.1 HIG4.9%
——1In the Linux kernel, the following vulnerability has been resolved:
mm/slub: avoid accessing metadata when pointer is invalid in object_err()
object_err() reports details of an object for further debugging, such as
the freelist pointer, redzone, etc. However, if the pointer is invalid,
attempting to access object metadata can lead to a crash since it does
not point to a valid object.
One known path to the crash is when alloc_consistency_checks()
determines the pointer to the allocated object is invalid because of a
freelist corruption, and calls object_err() to report it. The debug code
should report and handle the corruption gracefully and not crash in the
process.
In case the pointer is NULL or check_valid_pointer() returns false for
the pointer, only print the pointer value and skip accessing metadata.1dCVE-2025-6494—4.9%
——1——CVE-2025-9625—4.9%
——1——CVE-2025-5932—4.9%
——1——CVE-2022-50406—4.9%
——1——CVE-2025-68160—4.9%
——1——CVE-2026-3856—4.9%
——1——CVE-2026-23099—4.9%
——1——CVE-2026-20661—4.9%
——1——CVE-2025-66519—4.9%
——1——CVE-2024-11220—4.9%
——1——CVE-2024-39811—4.9%
——1——CVE-2026-326036.5 MED4.9%
——1Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDriverApi driver, triggering an immediate kernel crash (BSOD). The vulnerability affects the Standard Sandbox configuration both with and without dropped administrator privileges, but does not affect the Security Hardened Sandbox configuration. This issue has been fixed in version 1.17.3. Users who cannot update can use the Security Hardened Sandbox configuration as a workaround.6d