Vulnerabilities exploitable today
350,257in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,647
New KEV · 24H0
Exploit Today ≥ 701,583
Distribution · last window
- Critical1,426
- High4,742
- Medium3,931
- Low306
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-13037—1.3%
——0——CVE-2026-154755.3 MED1.3%
——0A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 13.9 is sufficient to fix this issue. The affected component should be upgraded. The vendor was contacted early about this disclosure.8dCVE-2026-40604—1.3%
——0——CVE-2023-48406—1.3%
——0——CVE-2025-47384—1.3%
——0——CVE-2026-133164.4 MED1.3%
——0A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.15dCVE-2025-38276—1.3%
——0——CVE-2024-23706—1.3%
——0——CVE-2025-36603—1.3%
——0——CVE-2024-51521—1.3%
——0——CVE-2022-25833—1.3%
——0——CVE-2026-1836—1.3%
——0——CVE-2026-46239—1.3%
——0——CVE-2025-69875—1.3%
——0——CVE-2024-51516—1.3%
——0——CVE-2018-9383—1.3%
——0——CVE-2025-66269—1.3%
——0——CVE-2026-143614.7 MED1.3%
——0The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.12dCVE-2026-21495—1.3%
——0——CVE-2025-34428—1.3%
——0——CVE-2026-21041—1.3%
——0——CVE-2025-27700—1.3%
——0——CVE-2025-6571—1.3%
——0——CVE-2026-56412—1.3%
——0——CVE-2026-27004—1.3%
——0——CVE-2025-66264—1.3%
——0——CVE-2026-28267—1.3%
——0——CVE-2023-21295—1.3%
——0——CVE-2026-532575.5 MED1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: enforce HE/EHT cap/oper consistency
Xiang Mei reports that mac80211 could crash if eht_cap is set
but eht_oper isn't. Rather than fixing that for the individual
user(s), enforce that both HE/EHT have consistent elements.13dCVE-2026-156825.5 MED1.2%
——0AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.7dCVE-2026-40703—1.2%
——0——CVE-2025-39673—1.2%
——0——CVE-2025-13321—1.2%
——0——CVE-2021-0681—1.2%
——0——CVE-2026-25337—1.2%
——0——CVE-2025-27723—1.2%
——0——CVE-2021-39766—1.2%
——0——CVE-2026-314747.8 HIG1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
isotp_sendmsg() uses only cmpxchg() on so->tx.state to serialize access
to so->tx.buf. isotp_release() waits for ISOTP_IDLE via
wait_event_interruptible() and then calls kfree(so->tx.buf).
If a signal interrupts the wait_event_interruptible() inside close()
while tx.state is ISOTP_SENDING, the loop exits early and release
proceeds to force ISOTP_SHUTDOWN and continues to kfree(so->tx.buf)
while sendmsg may still be reading so->tx.buf for the final CAN frame
in isotp_fill_dataframe().
The so->tx.buf can be allocated once when the standard tx.buf length needs
to be extended. Move the kfree() of this potentially extended tx.buf to
sk_destruct time when either isotp_sendmsg() and isotp_release() are done.6dCVE-2026-317617.8 HIG1.2%
——0In the Linux kernel, the following vulnerability has been resolved:
iio: gyro: mpu3050: Move iio_device_register() to correct location
iio_device_register() should be at the end of the probe function to
prevent race conditions.
Place iio_device_register() at the end of the probe function and place
iio_device_unregister() accordingly.7dCVE-2026-157796.1 MED1.2%
——0A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.6d