Vulnerabilities exploitable today
351,837in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,651
New KEV · 24H0
Exploit Today ≥ 701,587
Distribution · last window
- Critical1,811
- High5,855
- Medium4,717
- Low452
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-20018—1.9%
——1——CVE-2026-48066—1.9%
——1——CVE-2025-0135—1.8%
——1——CVE-2026-463087.8 HIG1.8%
——1In the Linux kernel, the following vulnerability has been resolved:
pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy()
In scpsys_get_bus_protection_legacy(), of_find_node_with_property()
returns a device node with its reference count incremented. The function
then calls of_node_put(node) before checking whether
syscon_regmap_lookup_by_phandle() returns an error. If an error occurs,
dev_err_probe() dereferences the node pointer to print diagnostic
information, but the node memory may have already been freed due to the
earlier of_node_put(), leading to a use-after-free vulnerability.
Fix this by moving the of_node_put() call after the error check, ensuring
the node is still valid when accessed in the error path.14dCVE-2025-29991—1.8%
——1——CVE-2025-48311—1.8%
——1——CVE-2026-43272—1.8%
——1——CVE-2021-47985—1.8%
——1——CVE-2026-0714—1.8%
——1——CVE-2025-43468—1.8%
——1——CVE-2024-54101—1.8%
——1——CVE-2025-48580—1.8%
——1——CVE-2026-572398.2 HIG1.8%
——1The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.13dCVE-2025-22453—1.8%
——1——CVE-2026-101973.3 LOW1.8%
——1A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.15hCVE-2026-22985—1.8%
——1——CVE-2021-0895—1.8%
——1——CVE-2021-0689—1.8%
——1——CVE-2021-0894—1.8%
——1——CVE-2025-48930—1.8%
——1——CVE-2024-23458—1.8%
——1——CVE-2026-48147—1.8%
——1——CVE-2024-0037—1.8%
——1——CVE-2025-33237—1.8%
——1——CVE-2025-38448—1.8%
——1——CVE-2025-46297—1.8%
——1——CVE-2025-27389—1.8%
——1——CVE-2024-45559—1.8%
——1——CVE-2026-35266—1.8%
——1——CVE-2022-25666—1.8%
——1——CVE-2026-598834.7 MED1.8%
——1Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.9dCVE-2026-31652—1.8%
——1——CVE-2025-48309—1.8%
——1——CVE-2025-71099—1.8%
——1——CVE-2025-48306—1.8%
——1——CVE-2026-9567—1.8%
——1——CVE-2025-69418—1.8%
——1——CVE-2021-0537—1.8%
——1——CVE-2025-48308—1.8%
——1——CVE-2026-40928—1.8%
——1——