Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,474
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20795—0.1%
——0——CVE-2025-682437.0 HIG0.1%
——0In the Linux kernel, the following vulnerability has been resolved:
NFS: Check the TLS certificate fields in nfs_match_client()
If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the
cert_serial and privkey_serial fields need to match as well since they
define the client's identity, as presented to the server.22dCVE-2024-25990—0.1%
——0——CVE-2023-40640—0.1%
——0——CVE-2023-21000—0.1%
——0——CVE-2026-20707—0.1%
——0Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.9dCVE-2023-20826—0.1%
——0——CVE-2025-20789—0.1%
——0——CVE-2026-47334—0.1%
——0——CVE-2025-48568—0.1%
——0——CVE-2025-27062—0.1%
——0——CVE-2023-38442—0.1%
——0——CVE-2023-38454—0.1%
——0——CVE-2026-149694.4 MED0.1%
——0A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.43dCVE-2024-32904—0.1%
——0——CVE-2017-13309—0.1%
——0——CVE-2024-39433—0.1%
——0——CVE-2024-20112—0.1%
——0——CVE-2024-47018—0.1%
——0——CVE-2023-38440—0.1%
——0——CVE-2026-21373—0.1%
——0——CVE-2026-105405.6 MED0.1%
——0The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions51dCVE-2025-58312—0.1%
——0——CVE-2022-20097—0.1%
——0——CVE-2026-20428—0.1%
——0——CVE-2023-42631—0.1%
——0——CVE-2026-41520—0.1%
——0——CVE-2026-204546.4 MED0.1%
——0In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.30dCVE-2023-21466—0.1%
——0——CVE-2023-38466—0.1%
——0——CVE-2025-32316—0.1%
——0——CVE-2023-38446—0.1%
——0——CVE-2018-9432—0.1%
——0——CVE-2018-9382—0.1%
——0——CVE-2026-466934.1 MED0.1%
——0ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.29dCVE-2023-40642—0.1%
——0——CVE-2024-53835—0.1%
——0——CVE-2025-22416—0.1%
——0——CVE-2018-9421—0.1%
——0——CVE-2023-38465—0.1%
——0——