Vulnerabilities exploitable today
351,920in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590
Distribution · last window
- Critical1,901
- High6,163
- Medium4,997
- Low479
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-43297—2.4%
——1——CVE-2026-0960—2.4%
——1——CVE-2026-43419—2.4%
——1——CVE-2026-31559—2.4%
——1——CVE-2022-42522—2.4%
——1——CVE-2026-43293—2.4%
——1——CVE-2026-31561—2.4%
——1——CVE-2026-31575—2.4%
——1——CVE-2026-45921—2.4%
——1——CVE-2026-6522—2.4%
——1——CVE-2026-31482—2.4%
——1——CVE-2026-443625.5 MED2.4%
——1OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` parses subkey headers but does not assign the `subkey_version` to the runtime `shdr_pub_key` structure. As a result, the `key->version` field remains at zero regardless of the version specified in the header. When `ree_fs_ta_open()` in `core/kernel/ree_fs_ta.c` calls `check_update_version()`, it passes this zeroed version to the rollback database. Because the database never receives a non-zero version to record, it never advances, effectively bypassing the rollback check and allowing TAs signed with downgraded subkey chains to load successfully. This impacts OP-TEE mainline configurations that utilize subkey-based signing chains for Trusted Application (TA) authentication. Version 4.11.0 contains a patch. No known workarounds are available.15dCVE-2026-23142—2.4%
——1——CVE-2026-8797—2.4%
——1——CVE-2026-31722—2.4%
——1——CVE-2026-23330—2.4%
——1——CVE-2026-31725—2.4%
——1——CVE-2026-31724—2.4%
——1——CVE-2026-46012—2.4%
——1——CVE-2026-23138—2.4%
——1——CVE-2026-31593—2.4%
——1——CVE-2022-50045—2.4%
——1——CVE-2026-31579—2.4%
——1——CVE-2026-462865.5 MED2.4%
——1In the Linux kernel, the following vulnerability has been resolved:
leds: qcom-lpg: Check for array overflow when selecting the high resolution
When selecting the high resolution values from the array, FIELD_GET() is
used to pull from a 3 bit register, yet the array being indexed has only
5 values in it. Odds are the hardware is sane, but just to be safe,
properly check before just overflowing and reading random data and then
setting up chip values based on that.14dCVE-2025-12690—2.4%
——1——CVE-2026-453595.7 MED2.4%
——1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in a heap buffer over-read when performing the connected components operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-22.8dCVE-2026-43395—2.4%
——1——CVE-2025-71273—2.4%
——1——CVE-2026-43012—2.4%
——1——CVE-2026-43170—2.4%
——1——CVE-2026-43323—2.4%
——1——CVE-2026-43244—2.4%
——1——CVE-2026-43320—2.4%
——1——CVE-2026-31646—2.4%
——1——CVE-2025-22242—2.4%
——1——CVE-2022-20201—2.4%
——1——CVE-2026-31736—2.4%
——1——CVE-2026-45976—2.4%
——1——CVE-2026-31741—2.4%
——1——CVE-2026-31740—2.4%
——1——