Vulnerabilities exploitable today
354,538in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,647
- High9,476
- Medium7,699
- Low698
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-6030—4.9%
——1——CVE-2020-37221—4.9%
——1——CVE-2025-0120—4.9%
——1——CVE-2026-411234.3 MED4.9%
——1Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.23dCVE-2025-48374—4.9%
——1——CVE-2023-32609—4.9%
——1——CVE-2026-632424.3 MED4.9%
——1A business logic vulnerability in Koollab LMS
allowed an
authenticated learner to set their lesson completion status to completed via
the SCORM commit endpoint without viewing the lesson material, compromising
training and completion records.19hCVE-2026-22019—4.9%
——1——CVE-2025-27408—4.9%
——1——CVE-2026-664004.8 MED4.9%
——1Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout period, as the expiry check compares an array to a scalar value which always evaluates incorrectly in PHP.20hCVE-2024-30120—4.9%
——1——CVE-2022-50503—4.9%
——1——CVE-2026-02477.8 HIG4.9%
——1Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.17dCVE-2026-25020—4.9%
——1——CVE-2026-295187.0 HIG4.9%
——1Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.16dCVE-2025-69346—4.9%
——1——CVE-2023-43043—4.9%
——1——CVE-2025-36353—4.9%
——1——CVE-2026-24358—4.9%
——1——CVE-2025-711457.8 HIG4.9%
——1In the Linux kernel, the following vulnerability has been resolved:
usb: phy: isp1301: fix non-OF device reference imbalance
A recent change fixing a device reference leak in a UDC driver
introduced a potential use-after-free in the non-OF case as the
isp1301_get_client() helper only increases the reference count for the
returned I2C device in the OF case.
Increment the reference count also for non-OF so that the caller can
decrement it unconditionally.
Note that this is inherently racy just as using the returned I2C device
is since nothing is preventing the PHY driver from being unbound while
in use.1dCVE-2025-10285—4.9%
——1——CVE-2022-509566.2 MED4.9%
——1WordPress Plugin amministrazione-aperta 3.7.3 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in the open parameter. Attackers can supply file paths through the open GET parameter in dispatcher.php to include and read sensitive files accessible to the web server.7dCVE-2026-535168.3 HIG4.9%
——1Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to bind the victim's OAuth identity to the attacker's account. The same primitive affects one-tap, and emailAndPassword.requireEmailVerification: true does not mitigate the link-time verification change. This issue is fixed in version 1.6.11.10dCVE-2026-24996—4.9%
——1——CVE-2026-26973—4.9%
——1——CVE-2024-8398—4.9%
——1——CVE-2024-22338—4.9%
——1——CVE-2021-26280—4.9%
——1——CVE-2024-45674—4.9%
——1——CVE-2026-24194—4.9%
——1——CVE-2026-641188.4 HIG4.9%
——1In the Linux kernel, the following vulnerability has been resolved:
qed: fix double free in qed_cxt_tables_alloc()
If one of the later PF or VF CID bitmap allocations fails,
qed_cid_map_alloc() jumps to cid_map_fail and frees the previously
allocated CID bitmaps before returning an error. qed_cxt_tables_alloc()
then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free()
again.
Fix this by setting each CID bitmap pointer to NULL after bitmap_free()
to avoid double free.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc3.
Runtime reproduction was not attempted because exercising the failing
allocation path requires device-specific setup.21hCVE-2025-64292—4.9%
——1——CVE-2025-69348—4.9%
——1——CVE-2026-167995.0 MED4.9%
——1Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.2dCVE-2021-37645—4.9%
——1——CVE-2025-32454—4.9%
——1——CVE-2021-37680—4.9%
——1——CVE-2026-65414.3 MED4.9%
——1Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID. Mattermost Advisory ID: MMSA-2026-0065318dCVE-2026-40554.3 MED4.9%
——1Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via specifying a different team ID in the run creation API request. Mattermost Advisory ID: MMSA-2026-006298dCVE-2025-59354—4.9%
——1——