Vulnerabilities exploitable today
357,495in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,609
- High11,033
- Medium6,955
- Low675
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-35006——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-23765——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-23692——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-35026——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-728659.9 CRI—
———Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate into docker compose -f, docker stack deploy -c, and touch shell commands executed through /bin/sh -c. An authenticated member with compose write and deploy permission can supply a crafted composePath, trigger compose.deploy or startCompose, and execute arbitrary operating-system commands in the Docker-privileged Dokploy host context. This issue is fixed in version 0.29.13.6hCVE-2026-35027——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-35028——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-68268——
———In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Return error on non-migratable faults requiring devmem
Non-migratable faults that require devmem incorrectly jump to the 'out'
label, which squashes the error code intended to be returned to the
upper layers. Fix this by returning -EACCES instead.
(cherry picked from commit c4508edb2c723de93717272488ea65b165637eac)12hCVE-2026-23691——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-40512——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-566195.4 MED—
———HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.8hCVE-2026-715768.5 HIG—
———A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the self-asserted source identity. This allows the attacker to falsify or delete critical data, such as compliance, inventory, and cluster health information, belonging to other hubs in the database.8hCVE-2026-23690——
———Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.8hCVE-2026-715776.3 MED—
———A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.8hCVE-2026-68154——
———In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on
that invariant and uses type 0 to identify leaf devices.
If crush_decode() accepts a bucket with type 0, a malformed CRUSH map
can make the mapper treat a negative bucket ID as a device and pass it
to is_out(), which then indexes the OSD weight array with a negative
value.
Reject zero bucket types while decoding the CRUSH map so the invalid
state never reaches the mapper.12h