Vulnerabilities exploitable today
352,785in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,281
- High7,880
- Medium7,174
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-235816.7 MED0.0%
——0The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.20dCVE-2026-00897.8 HIG0.0%
——0In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2025-54629—0.0%
——0——CVE-2025-27076—0.0%
——0——CVE-2025-596166.6 MED0.0%
——0Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.19dCVE-2022-42775—0.0%
——0——CVE-2025-58313—0.0%
——0——CVE-2026-21444—0.0%
——0——CVE-2025-36921—0.0%
——0——CVE-2024-45565—0.0%
——0——CVE-2025-36889—0.0%
——0——CVE-2022-48451—0.0%
——0——CVE-2023-20620—0.0%
——0——CVE-2026-44509—0.0%
——0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.5dCVE-2025-54651—0.0%
——0——CVE-2022-47331—0.0%
——0——CVE-2026-256006.4 MED0.0%
——0The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable. This secret is used by the application’s
encryption routines, including the function responsible for decrypting
credentials stored in the product’s configuration file. Because the
secret is constant across installations, any attacker with sufficient
local privileges can extract it from the binary. Once obtained, the secret allows the attacker to decrypt the stored
password and authenticate as the user defined in the configuration file.
In the affected version, this user account is configured with
administrative privileges, granting full access to PDBM’s management
interface and its underlying operational functions.4dCVE-2025-41743—0.0%
——0——CVE-2026-50267—0.0%
——0——CVE-2023-20623—0.0%
——0——CVE-2023-21101—0.0%
——0——CVE-2022-20243—0.0%
——0——CVE-2025-54625—0.0%
——0——CVE-2023-44128—0.0%
——0——CVE-2023-20801—0.0%
——0——CVE-2025-48960—0.0%
——0——CVE-2024-45547—0.0%
——0——CVE-2025-21481—0.0%
——0——CVE-2026-440594.5 MED0.0%
——0A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.3dCVE-2025-58303—0.0%
——0——CVE-2025-47404—0.0%
——0——CVE-2023-20835—0.0%
——0——CVE-2023-20686—0.0%
——0——CVE-2023-21399—0.0%
——0——CVE-2026-34862—0.0%
——0——CVE-2025-23364—0.0%
——0——CVE-2026-34861—0.0%
——0——CVE-2023-20687—0.0%
——0——CVE-2026-285777.8 HIG0.0%
——0In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.4dCVE-2025-463713.6 LOW0.0%
——0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.3d