Vulnerabilities exploitable today
353,511in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,435
- High8,291
- Medium7,422
- Low691
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-22450—4.1%
——1——CVE-2025-21944—4.1%
——1——CVE-2024-58321—4.1%
——1——CVE-2025-2154—4.1%
——1——CVE-2025-15642—4.1%
——1——CVE-2021-22462—4.1%
——1——CVE-2025-49384—4.1%
——1——CVE-2022-50461—4.1%
——1——CVE-2026-33902—4.1%
——1——CVE-2026-645247.7 HIG4.1%
——1In the Linux kernel, the following vulnerability has been resolved:
drm/hyperv: validate resolution_count and fix WIN8 fallback
A SYNTHVID_RESOLUTION_RESPONSE with resolution_count > 64 walks past
the supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the
parse loop. Bound resolution_count against the array size, folded
into the existing zero-check.
When the WIN10 resolution probe fails, the caller in
hyperv_connect_vsp() left hv->screen_*_max / preferred_* unpopulated,
which sets mode_config.max_width / max_height to 0 and makes
drm_internal_framebuffer_create() reject every userspace framebuffer
with -EINVAL. The pre-WIN10 branch had the same gap for
preferred_width / preferred_height. Use a single post-probe fallback
guarded by screen_width_max == 0 so both paths converge on the WIN8
defaults.2dCVE-2024-51764—4.1%
——1——CVE-2024-51765—4.1%
——1——CVE-2026-42743—4.1%
——1——CVE-2021-22461—4.1%
——1——CVE-2026-348835.3 MED4.1%
——1An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the installer does not properly validate symbolic links or reparse points at the destination path, an attacker can create a malicious link that redirects the write operation to an arbitrary system location, enabling arbitrary file creation or overwrite with elevated privileges.5dCVE-2025-67734—4.1%
——1——CVE-2024-33660—4.1%
——1——CVE-2024-58322—4.1%
——1——CVE-2025-66002—4.1%
——1——CVE-2024-31953—4.1%
——1——CVE-2024-27457—4.1%
——1——CVE-2024-58323—4.1%
——1——CVE-2026-529725.5 MED4.1%
——1In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Cap AEAD AD length to 0x80000000
In order to prevent arithmetic overflows when checking the TX
buffer size, cap the associated data length to 0x80000000.5dCVE-2025-33176—4.1%
——1——CVE-2025-399315.5 MED4.1%
——1In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Set merge to zero early in af_alg_sendmsg
If an error causes af_alg_sendmsg to abort, ctx->merge may contain
a garbage value from the previous loop. This may then trigger a
crash on the next entry into af_alg_sendmsg when it attempts to do
a merge that can't be done.
Fix this by setting ctx->merge to zero near the start of the loop.15dCVE-2021-22457—4.1%
——1——CVE-2025-547704.9 MED4.1%
——1A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availability29dCVE-2020-0054—4.1%
——1——CVE-2024-57974—4.1%
——1——CVE-2023-23438—4.1%
——1——CVE-2023-53467—4.1%
——1——CVE-2022-50383—4.1%
——1——CVE-2026-614337.8 HIG4.1%
——1PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.14dCVE-2022-50685—4.1%
——1——CVE-2025-63717—4.1%
——1——CVE-2022-50683—4.1%
——1——CVE-2025-57977—4.1%
——1——CVE-2025-61648—4.1%
——1——CVE-2023-53455—4.1%
——1——CVE-2022-33878—4.1%
——1——