Vulnerabilities exploitable today
352,317in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,150
- High7,306
- Medium6,373
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-638497.8 HIG2.8%
——1In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring
VCN encoder and decoder rings do not support 64-bit user fence writes,
reject CS submissions with user fences.
(cherry picked from commit e16be95a2c3ee712b142cb27d2dca0b461181359)4dCVE-2026-43201—2.8%
——1——CVE-2024-33054—2.8%
——1——CVE-2026-641817.8 HIG2.8%
——1In the Linux kernel, the following vulnerability has been resolved:
mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()
On x86 32-bit with THP enabled, zap_huge_pmd() is seen to generate a
"WARNING: mm/memory.c:735 at __vm_normal_page+0x6a/0x7d", from the
VM_WARN_ON_ONCE(is_zero_pfn(pfn) || is_huge_zero_pfn(pfn)); followed by
"BUG: Bad rss-counter state"s, then later "BUG: Bad page state"s when
reclaim gets to call shrink_huge_zero_folio_scan().
It's as if the _PAGE_SPECIAL bit never got set in the huge_zero pmd: and
indeed, whereas pte_special() and pte_mkspecial() are subject to a
dedicated CONFIG_ARCH_HAS_PTE_SPECIAL, pmd_special() and pmd_mkspecial()
are subject to CONFIG_ARCH_SUPPORTS_PMD_PFNMAP, which is never enabled on
any 32-bit architecture.
While the problem was exposed through commit d80a9cb1a64a
("mm/huge_memory: add and use normal_or_softleaf_folio_pmd()"), it was an
oversight in commit af38538801c6 ("mm/memory: factor out common code from
vm_normal_page_*()") and would result in other problems:
* huge zero folio accounted in smaps, pagemap (PAGE_IS_FILE) and
numamaps as file-backed THP
* folio_walk_start() returning the folio even without FW_ZEROPAGE set.
Callers seem to tolerate that, though.
... and triggering the VM_WARN_ON_ONE(), although never reported so far.
To fix it, teach vm_normal_page_pmd()/vm_normal_page_pud() to consider
whether pmd_special/pud_special is actually implemented.4dCVE-2023-53266—2.8%
——1——CVE-2022-48310—2.8%
——1——CVE-2019-25293—2.8%
——1——CVE-2021-35526—2.8%
——1——CVE-2022-50424—2.8%
——1——CVE-2025-71286—2.8%
——1——CVE-2026-54431—2.8%
——1In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header.
This issue was fixed in version 2.3.022dCVE-2024-23511—2.8%
——1——CVE-2025-39741—2.8%
——1——CVE-2024-40685—2.8%
——1——CVE-2026-43169—2.8%
——1——CVE-2026-43220—2.8%
——1——CVE-2022-50425—2.8%
——1——CVE-2026-599304.3 MED2.8%
——1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page navigation, CSS selectors, or JavaScript handlers. This issue is fixed in version 3.3.0.15dCVE-2026-57295—2.8%
——1——CVE-2021-47883—2.8%
——1——CVE-2020-36957—2.8%
——1——CVE-2025-39696—2.8%
——1——CVE-2022-50295—2.8%
——1——CVE-2023-53553—2.8%
——1——CVE-2026-21421—2.8%
——1——CVE-2026-22212—2.8%
——1TinyOS versions up to and including 2.1.2 contain a stack-based buffer overflow vulnerability in the mcp2200gpio utility. The vulnerability is caused by unsafe use of strcpy() and strcat() functions when constructing device paths during automatic device discovery. A local attacker can exploit this by creating specially crafted filenames under /dev/usb/, leading to stack memory corruption and application crashes.10dCVE-2025-30075—2.8%
——1——CVE-2026-146105.3 MED2.8%
——1A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.18dCVE-2025-327495.3 MED2.8%
——1Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.1dCVE-2025-11781—2.8%
——1——CVE-2021-40015—2.8%
——1——CVE-2026-43189—2.8%
——1——CVE-2025-71294—2.8%
——1——CVE-2026-23346—2.8%
——1——CVE-2023-53180—2.8%
——1——CVE-2026-46216—2.8%
——1——CVE-2025-38534—2.8%
——1——CVE-2023-21109—2.8%
——1——CVE-2025-39677—2.8%
——1——CVE-2025-20106—2.8%
——1——