Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,473
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-26450—0.2%
——0——CVE-2024-20119—0.2%
——0——CVE-2023-38456—0.2%
——0——CVE-2026-41967—0.2%
——0——CVE-2023-21234—0.2%
——0——CVE-2023-38455—0.2%
——0——CVE-2023-38444—0.2%
——0——CVE-2025-20767—0.2%
——0——CVE-2024-40657—0.2%
——0——CVE-2022-26452—0.2%
——0——CVE-2024-32917—0.2%
——0——CVE-2023-33119—0.2%
——0——CVE-2024-20109—0.2%
——0——CVE-2022-39887—0.2%
——0——CVE-2022-39886—0.2%
——0——CVE-2025-47362—0.2%
——0——CVE-2025-20769—0.2%
——0——CVE-2025-58307—0.2%
——0——CVE-2024-42186—0.2%
——0——CVE-2025-26434—0.2%
——0——CVE-2026-8804—0.2%
——0Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.46dCVE-2026-419766.6 MED0.2%
——0Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.29dCVE-2026-40224—0.2%
——0——CVE-2024-43077—0.2%
——0——CVE-2026-22077—0.2%
——0——CVE-2025-20763—0.2%
——0——CVE-2026-42489—0.2%
——0——CVE-2022-39879—0.2%
——0——CVE-2024-20117—0.2%
——0——CVE-2026-150604.7 MED0.2%
——0When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.
- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file
- versions older than v258 are not affected
- unrelated to the systemd service manager (pid 1 or user session managers)
- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)
- terminal-only or remote sessions (e.g.: ssh) are not affected11dCVE-2024-20113—0.2%
——0——CVE-2026-24921—0.2%
——0——CVE-2023-33110—0.1%
——0——CVE-2026-438207.7 HIG0.2%
——0NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.28dCVE-2025-22414—0.2%
——0——CVE-2025-48558—0.2%
——0——CVE-2025-596146.7 MED0.2%
——0Memory Corruption when sending random number generator command with insufficient output buffer size.30dCVE-2022-20091—0.2%
——0——CVE-2023-40634—0.2%
——0——CVE-2025-596136.7 MED0.2%
——0Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.30d