Vulnerabilities exploitable today
352,772in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,281
- High7,876
- Medium7,167
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-29864—3.2%
——1——CVE-2025-31457—3.2%
——1——CVE-2026-257818.4 HIG3.2%
——1in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.1dCVE-2025-62186—3.2%
——1——CVE-2025-54702—3.2%
——1——CVE-2025-1479—3.2%
——1——CVE-2025-53268—3.2%
——1——CVE-2026-133566.3 MED3.2%
——1A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.17dCVE-2024-38806—3.2%
——1——CVE-2026-461177.8 HIG3.2%
——1In the Linux kernel, the following vulnerability has been resolved:
RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
Sashiko points out that the user can specify WQs sharing the same CQ as a
part of the uAPI and this will trigger the WARN_ON() then go on to corrupt
the kernel.
Just reject it outright and fail the QP creation.4dCVE-2026-31630—3.2%
——1——CVE-2026-23717—3.2%
——1——CVE-2025-49968—3.2%
——1——CVE-2025-53269—3.2%
——1——CVE-2025-53272—3.2%
——1——CVE-2025-53273—3.2%
——1——CVE-2026-42795—3.2%
——1Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.
The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package.
An attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact.
This issue affects Gleam from 0.10.0-rc1 until 1.17.0.3dCVE-2025-12889—3.2%
——1——CVE-2026-599487.0 HIG3.2%
——1Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org or Private Packagist can cause Composer to write attacker-controlled files outside the vendor directory and outside the project during install or update by using an invalid package name that is not correctly validated before dependency-resolution results are written or installed. This issue is fixed in versions 2.2.29 and 2.10.2.15dCVE-2025-20047—3.2%
——1——CVE-2025-53197—3.2%
——1——CVE-2024-38825—3.2%
——1——CVE-2026-54326—3.2%
——1——CVE-2025-49966—3.2%
——1——CVE-2025-9612—3.1%
——1——CVE-2024-37181—3.2%
——1——CVE-2026-35351—3.2%
——1——CVE-2017-15856—3.2%
——1——CVE-2026-229267.8 HIG3.2%
——1Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.2dCVE-2025-38102—3.2%
——1——CVE-2019-256824.3 MED3.2%
——1CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.15hCVE-2026-23017—3.2%
——1——CVE-2026-20621—3.2%
——1——CVE-2026-42290—3.2%
——1——CVE-2023-40080—3.2%
——1——CVE-2026-35591—3.2%
——1libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.2dCVE-2026-43450—3.2%
——1——CVE-2025-31915—3.2%
——1——CVE-2022-20454—3.2%
——1——CVE-2022-30773—3.2%
——1——