Vulnerabilities exploitable today
352,317in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical2,150
- High7,306
- Medium6,373
- Low617
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-8597—2.8%
——1——CVE-2026-31782—2.8%
——1——CVE-2022-34910—2.8%
——1——CVE-2024-33042—2.8%
——1——CVE-2026-23437—2.8%
——1——CVE-2026-44274—2.8%
——1——CVE-2026-603316.4 MED2.8%
——1Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).1dCVE-2025-20983—2.8%
——1——CVE-2026-20971—2.8%
——1——CVE-2020-37030—2.8%
——1——CVE-2026-46131—2.8%
——1——CVE-2026-48155—2.8%
——1——CVE-2026-547996.7 MED2.8%
——1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.15dCVE-2024-38401—2.8%
——1——CVE-2021-39693—2.8%
——1——CVE-2020-36903—2.8%
——1——CVE-2025-1927—2.8%
——1——CVE-2021-47859—2.8%
——1——CVE-2021-47863—2.8%
——1——CVE-2025-13205—2.8%
——1——CVE-2024-13972—2.8%
——1——CVE-2025-71326—2.8%
——1——CVE-2025-8700—2.8%
——1——CVE-2021-47868—2.8%
——1——CVE-2021-47861—2.8%
——1——CVE-2021-47867—2.8%
——1——CVE-2026-42193—2.8%
——1——CVE-2026-28281—2.8%
——1——CVE-2021-47862—2.8%
——1——CVE-2026-640767.8 HIG2.8%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: bridge: eb_tables: close module init race
sashiko reports for unrelated patch:
Does the core ebtables initialization in ebtables.c suffer from a similar race?
Once nf_register_sockopt() completes, the sockopts are exposed globally.
sockopt has to be registered last, just like in ip/ip6/arptables.4dCVE-2021-0921—2.8%
——1——CVE-2026-31493—2.8%
——1——CVE-2026-31541—2.8%
——1——CVE-2026-532515.5 MED2.8%
——1In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
hci_get_route() returns a reference-counted hci_dev pointer via
hci_dev_hold(). The function exits normally or with an error without ever
releasing it.16dCVE-2026-31442—2.8%
——1——CVE-2021-0398—2.8%
——1——CVE-2025-38519—2.8%
——1——CVE-2025-21014—2.8%
——1——CVE-2026-21049—2.8%
——1Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.14dCVE-2026-31471—2.8%
——1——