Vulnerabilities exploitable today
354,470in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,643
- High9,463
- Medium7,694
- Low694
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-22889—4.6%
——1——CVE-2017-3772—4.6%
——1——CVE-2025-9884—4.6%
——1——CVE-2025-38606—4.6%
——1——CVE-2026-443875.2 MED4.6%
——1ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.3dCVE-2025-23376—4.6%
——1——CVE-2024-42425—4.6%
——1——CVE-2026-21381—4.6%
——1——CVE-2025-39847—4.6%
——1——CVE-2019-25275—4.6%
——1——CVE-2023-28074—4.6%
——1——CVE-2024-11719—4.6%
——1——CVE-2022-41602—4.6%
——1——CVE-2022-41603—4.6%
——1——CVE-2022-41601—4.6%
——1——CVE-2025-55116—4.6%
——1——CVE-2022-41598—4.6%
——1——CVE-2026-436987.8 HIG4.6%
——1An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.2dCVE-2025-36418—4.6%
——1——CVE-2022-49829—4.6%
——1——CVE-2025-39846—4.6%
——1——CVE-2021-47803—4.6%
——1——CVE-2025-46328—4.6%
——1——CVE-2022-49938—4.6%
——1——CVE-2025-398488.8 HIG4.6%
——1In the Linux kernel, the following vulnerability has been resolved:
ax25: properly unshare skbs in ax25_kiss_rcv()
Bernard Pidoux reported a regression apparently caused by commit
c353e8983e0d ("net: introduce per netns packet chains").
skb->dev becomes NULL and we crash in __netif_receive_skb_core().
Before above commit, different kind of bugs or corruptions could happen
without a major crash.
But the root cause is that ax25_kiss_rcv() can queue/mangle input skb
without checking if this skb is shared or not.
Many thanks to Bernard Pidoux for his help, diagnosis and tests.
We had a similar issue years ago fixed with commit 7aaed57c5c28
("phonet: properly unshare skbs in phonet_rcv()").1dCVE-2024-45353—4.6%
——1——CVE-2024-36558—4.6%
——1——CVE-2022-41595—4.6%
——1——CVE-2025-399027.1 HIG4.6%
——1In the Linux kernel, the following vulnerability has been resolved:
mm/slub: avoid accessing metadata when pointer is invalid in object_err()
object_err() reports details of an object for further debugging, such as
the freelist pointer, redzone, etc. However, if the pointer is invalid,
attempting to access object metadata can lead to a crash since it does
not point to a valid object.
One known path to the crash is when alloc_consistency_checks()
determines the pointer to the allocated object is invalid because of a
freelist corruption, and calls object_err() to report it. The debug code
should report and handle the corruption gracefully and not crash in the
process.
In case the pointer is NULL or check_valid_pointer() returns false for
the pointer, only print the pointer value and skip accessing metadata.1dCVE-2026-49358—4.6%
——1——CVE-2022-41593—4.6%
——1——CVE-2026-546567.8 HIG4.6%
——1datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until 0.60.2, datamodel-code-generator interpolates validators from --extra-template-data in src/datamodel_code_generator/model/pydantic_v2/base_model.py through _process_validators into @field_validator decorators without safe validation, allowing Python code execution when the generated Pydantic v2 model is imported. This issue is fixed in version 0.60.2.12hCVE-2024-20413—4.6%
——1——CVE-2023-0207—4.6%
——1——CVE-2026-48903—4.6%
——1——CVE-2025-3770—4.6%
——1——CVE-2020-11293—4.6%
——1——CVE-2024-34615—4.6%
——1——CVE-2025-65842—4.6%
——1——CVE-2024-47149—4.6%
——1——