Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,690
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-11604—4.5%
——1An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).8dCVE-2020-27037—4.5%
——1——CVE-2025-47473—4.5%
——1——CVE-2025-11547—4.5%
——1——CVE-2025-57784—4.5%
——1——CVE-2025-47466—4.5%
——1——CVE-2026-22167—4.5%
——1——CVE-2025-384467.3 HIG4.5%
——1In the Linux kernel, the following vulnerability has been resolved:
clk: imx: Fix an out-of-bounds access in dispmix_csr_clk_dev_data
When num_parents is 4, __clk_register() occurs an out-of-bounds
when accessing parent_names member. Use ARRAY_SIZE() instead of
hardcode number here.
BUG: KASAN: global-out-of-bounds in __clk_register+0x1844/0x20d8
Read of size 8 at addr ffff800086988e78 by task kworker/u24:3/59
Hardware name: NXP i.MX95 19X19 board (DT)
Workqueue: events_unbound deferred_probe_work_func
Call trace:
dump_backtrace+0x94/0xec
show_stack+0x18/0x24
dump_stack_lvl+0x8c/0xcc
print_report+0x398/0x5fc
kasan_report+0xd4/0x114
__asan_report_load8_noabort+0x20/0x2c
__clk_register+0x1844/0x20d8
clk_hw_register+0x44/0x110
__clk_hw_register_mux+0x284/0x3a8
imx95_bc_probe+0x4f4/0xa7020hCVE-2025-1865—4.5%
——1——CVE-2025-46752—4.5%
——1——CVE-2026-21785—4.5%
——1——CVE-2025-13353—4.5%
——1——CVE-2023-27887—4.5%
——1——CVE-2023-30717—4.5%
——1——CVE-2021-1942—4.5%
——1——CVE-2022-50490—4.5%
——1——CVE-2022-49774—4.5%
——1——CVE-2024-26806—4.5%
——1——CVE-2022-49773—4.5%
——1——CVE-2022-49791—4.5%
——1——CVE-2022-22367—4.5%
——1——CVE-2023-38267—4.5%
——1——CVE-2022-50442—4.5%
——1——CVE-2022-50507—4.5%
——1——CVE-2023-22592—4.5%
——1——CVE-2026-34682—4.5%
——1——CVE-2025-14979—4.5%
——1——CVE-2025-58411—4.5%
——1——CVE-2022-49810—4.5%
——1——CVE-2022-50328—4.5%
——1——CVE-2024-47045—4.5%
——1——CVE-2026-112435.4 MED4.5%
——1Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)8dCVE-2026-451846.5 MED4.5%
——1Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.10dCVE-2026-56392—4.5%
——1GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.
When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.
When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.
This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d10hCVE-2025-25230—4.5%
——1——CVE-2025-33045—4.5%
——1——CVE-2020-27040—4.5%
——1——CVE-2025-32887—4.5%
——1——CVE-2022-49876—4.5%
——1——CVE-2022-49766—4.5%
——1——