Vulnerabilities exploitable today
354,348in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,603
- High9,354
- Medium7,537
- Low681
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-673994.6 MED4.4%
——1An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access26dCVE-2026-12162—4.4%
——1——CVE-2020-0029—4.4%
——1——CVE-2026-35275—4.4%
——1——CVE-2026-543697.1 HIG4.4%
——1acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.2dCVE-2025-20024—4.4%
——1——CVE-2022-50225—4.4%
——1——CVE-2026-3939—4.4%
——1——CVE-2026-328627.8 HIG4.4%
——1There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.6dCVE-2026-341655.0 MED4.4%
——1go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1.6dCVE-2026-54736—4.4%
——1Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMAC using PHP/Zephir identity comparison, which lowers to a byte-wise comparison that returns early on the first differing byte. This observable timing discrepancy can allow an attacker to recover a valid tag byte-by-byte and attach it to a chosen IV and ciphertext so that decrypt() accepts tampered encrypted content as authentic. This issue is fixed in version 5.14.1.17dCVE-2025-36755—4.4%
——1——CVE-2024-34632—4.4%
——1——CVE-2025-37880—4.4%
——1——CVE-2025-7020—4.4%
——1——CVE-2025-2349—4.4%
——1——CVE-2022-38103—4.4%
——1——CVE-2021-39711—4.4%
——1——CVE-2025-54275—4.4%
——1——CVE-2024-56812—4.4%
——1——CVE-2024-35208—4.4%
——1——CVE-2026-396274.3 MED4.4%
——1Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe: from n/a through <= 2.266.6dCVE-2025-46296—4.4%
——1——CVE-2025-67344—4.4%
——1——CVE-2025-57852—4.4%
——1——CVE-2022-46656—4.4%
——1——CVE-2025-6536—4.4%
——1——CVE-2024-3480—4.4%
——1——CVE-2023-53586—4.4%
——1——CVE-2026-35352—4.4%
——1——CVE-2025-12588—4.4%
——1——CVE-2025-7965—4.4%
——1——CVE-2025-20081—4.4%
——1——CVE-2025-67341—4.4%
——1——CVE-2025-66102—4.4%
——1——CVE-2024-20806—4.4%
——1——CVE-2021-30285—4.4%
——1——CVE-2026-572487.8 HIG4.4%
——1When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.21dCVE-2023-42483—4.4%
——1——CVE-2024-23736—4.4%
——1——