Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-57062—4.0%
——1——CVE-2022-27836—4.0%
——1——CVE-2025-62876—4.0%
——1——CVE-2026-21365—4.0%
——1——CVE-2026-21443—4.0%
——1——CVE-2026-30904—4.0%
——1——CVE-2026-230865.5 MED4.0%
——1In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: cap TX credit to local buffer size
The virtio transports derives its TX credit directly from peer_buf_alloc,
which is set from the remote endpoint's SO_VM_SOCKETS_BUFFER_SIZE value.
On the host side this means that the amount of data we are willing to
queue for a connection is scaled by a guest-chosen buffer size, rather
than the host's own vsock configuration. A malicious guest can advertise
a large buffer and read slowly, causing the host to allocate a
correspondingly large amount of sk_buff memory.
The same thing would happen in the guest with a malicious host, since
virtio transports share the same code base.
Introduce a small helper, virtio_transport_tx_buf_size(), that
returns min(peer_buf_alloc, buf_alloc), and use it wherever we consume
peer_buf_alloc.
This ensures the effective TX window is bounded by both the peer's
advertised buffer and our own buf_alloc (already clamped to
buffer_max_size via SO_VM_SOCKETS_BUFFER_MAX_SIZE), so a remote peer
cannot force the other to queue more data than allowed by its own
vsock settings.
On an unpatched Ubuntu 22.04 host (~64 GiB RAM), running a PoC with
32 guest vsock connections advertising 2 GiB each and reading slowly
drove Slab/SUnreclaim from ~0.5 GiB to ~57 GiB; the system only
recovered after killing the QEMU process. That said, if QEMU memory is
limited with cgroups, the maximum memory used will be limited.
With this patch applied:
Before:
MemFree: ~61.6 GiB
Slab: ~142 MiB
SUnreclaim: ~117 MiB
After 32 high-credit connections:
MemFree: ~61.5 GiB
Slab: ~178 MiB
SUnreclaim: ~152 MiB
Only ~35 MiB increase in Slab/SUnreclaim, no host OOM, and the guest
remains responsive.
Compatibility with non-virtio transports:
- VMCI uses the AF_VSOCK buffer knobs to size its queue pairs per
socket based on the local vsk->buffer_* values; the remote side
cannot enlarge those queues beyond what the local endpoint
configured.
- Hyper-V's vsock transport uses fixed-size VMBus ring buffers and
an MTU bound; there is no peer-controlled credit field comparable
to peer_buf_alloc, and the remote endpoint cannot drive in-flight
kernel memory above those ring sizes.
- The loopback path reuses virtio_transport_common.c, so it
naturally follows the same semantics as the virtio transport.
This change is limited to virtio_transport_common.c and thus affects
virtio-vsock, vhost-vsock, and loopback, bringing them in line with the
"remote window intersected with local policy" behaviour that VMCI and
Hyper-V already effectively have.
[Stefano: small adjustments after changing the previous patch]
[Stefano: tweak the commit message]13dCVE-2024-41917—4.0%
——1——CVE-2026-57456—3.9%
——1——CVE-2025-39836—3.9%
——1——CVE-2023-73437.8 HIG3.9%
——1Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an administrator opens a maliciously crafted project file. Successful exploitation allows the attacker to execute code in the context of the HiVision process.3dCVE-2023-0192—3.9%
——1——CVE-2020-27044—3.9%
——1——CVE-2025-0252—3.9%
——1——CVE-2024-21923—3.9%
——1——CVE-2023-30730—3.9%
——1——CVE-2024-28169—3.9%
——1——CVE-2020-0208—3.9%
——1——CVE-2026-14899—3.9%
——1The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.5dCVE-2023-30565—3.9%
——1——CVE-2023-45864—3.9%
——1——CVE-2025-20689—3.9%
——1——CVE-2025-49877—3.9%
——1——CVE-2025-20690—3.9%
——1——CVE-2025-20691—3.9%
——1——CVE-2026-84098.8 HIG3.9%
——1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete. The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.4dCVE-2024-36071—3.9%
——1——CVE-2022-20416—3.9%
——1——CVE-2025-20938—3.9%
——1——CVE-2024-45759—3.9%
——1——CVE-2026-31772—3.9%
——1——CVE-2023-2866—3.9%
——1——CVE-2022-39904—3.9%
——1——CVE-2025-4276—3.9%
——1——CVE-2026-4309—3.9%
——1——CVE-2021-26734—3.9%
——1——CVE-2024-44956—3.9%
——1——CVE-2025-26403—3.9%
——1——CVE-2026-4273—3.9%
——1——CVE-2026-27270—3.9%
——1——