Vulnerabilities exploitable today
351,929in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical1,913
- High6,189
- Medium5,025
- Low479
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-0461—2.5%
——1——CVE-2026-43302—2.5%
——1——CVE-2021-39652—2.5%
——1——CVE-2026-232727.8 HIG2.5%
——1In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: unconditionally bump set->nelems before insertion
In case that the set is full, a new element gets published then removed
without waiting for the RCU grace period, while RCU reader can be
walking over it already.
To address this issue, add the element transaction even if set is full,
but toggle the set_full flag to report -ENFILE so the abort path safely
unwinds the set to its previous state.
As for element updates, decrement set->nelems to restore it.
A simpler fix is to call synchronize_rcu() in the error path.
However, with a large batch adding elements to already maxed-out set,
this could cause noticeable slowdown of such batches.19dCVE-2026-43312—2.5%
——1——CVE-2026-234227.8 HIG2.5%
——1In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
Commit 31a7a0bbeb00 ("dpaa2-switch: add bounds check for if_id in IRQ
handler") introduces a range check for if_id to avoid an out-of-bounds
access. If an out-of-bounds if_id is detected, the interrupt status is
not cleared. This may result in an interrupt storm.
Clear the interrupt status after detecting an out-of-bounds if_id to avoid
the problem.
Found by an experimental AI code review agent at Google.9dCVE-2026-54531—2.5%
——1——CVE-2025-23105—2.5%
——1——CVE-2023-40727—2.5%
——1——CVE-2026-338025.5 MED2.5%
——1A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).
On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers.
This issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400:
* 23.2R2 versions before 23.2R2-S6,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S3,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S1.9dCVE-2026-68915.0 MED2.5%
——1Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.2dCVE-2026-23082—2.5%
——1——CVE-2026-31512—2.5%
——1——CVE-2026-23312—2.5%
——1——CVE-2025-71118—2.5%
——1——CVE-2026-23309—2.5%
——1——CVE-2026-23339—2.5%
——1——CVE-2026-46009—2.5%
——1——CVE-2022-20057—2.5%
——1——CVE-2026-2646—2.5%
——1——CVE-2022-490427.8 HIG2.5%
——1An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.15hCVE-2026-54530—2.5%
——1——CVE-2026-20436—2.5%
——1——CVE-2025-42992—2.5%
——1——CVE-2022-33277—2.5%
——1——CVE-2026-23367—2.5%
——1——CVE-2026-43080—2.5%
——1——CVE-2026-49461—2.5%
——1——CVE-2026-20977—2.5%
——1——CVE-2026-46044—2.5%
——1——CVE-2026-40025—2.5%
——1——CVE-2022-40531—2.5%
——1——CVE-2026-25605—2.5%
——1——CVE-2026-46003—2.5%
——1——CVE-2026-43436—2.5%
——1——CVE-2026-31519—2.5%
——1——CVE-2025-4952—2.5%
——1——CVE-2026-23093—2.5%
——1——CVE-2022-20035—2.5%
——1——CVE-2022-20033—2.5%
——1——