Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,474
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-38442—0.1%
——0——CVE-2026-41520—0.1%
——0——CVE-2022-20097—0.1%
——0——CVE-2025-48568—0.1%
——0——CVE-2025-27062—0.1%
——0——CVE-2017-13309—0.1%
——0——CVE-2026-20428—0.1%
——0——CVE-2026-204546.4 MED0.1%
——0In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.30dCVE-2026-149694.4 MED0.1%
——0A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.43dCVE-2026-47334—0.1%
——0——CVE-2025-36935—0.1%
——0——CVE-2025-47405—0.1%
——0——CVE-2025-47336—0.1%
——0——CVE-2025-47335—0.1%
——0——CVE-2024-38406—0.1%
——0——CVE-2024-53839—0.1%
——0——CVE-2025-35054—0.1%
——0——CVE-2022-20219—0.1%
——0——CVE-2026-3428—0.1%
——0——CVE-2025-20786—0.1%
——0——CVE-2025-598663.3 LOW0.1%
——0The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.35dCVE-2026-167926.1 MED0.1%
——0An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.16dCVE-2025-20805—0.1%
——0——CVE-2026-419775.0 MED0.1%
——0DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.29dCVE-2026-21382—0.1%
——0——CVE-2026-24082—0.1%
——0——CVE-2024-32912—0.1%
——0——CVE-2026-41964—0.1%
——0——CVE-2026-107663.6 LOW0.1%
——0A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Handler. The manipulation leads to use of weak hash. The attack can only be performed from a local environment. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.30dCVE-2023-20743—0.1%
——0——CVE-2025-36931—0.1%
——0——CVE-2026-23153—0.1%
——0——CVE-2024-47024—0.1%
——0——CVE-2026-21378—0.1%
——0——CVE-2025-58303—0.1%
——0——CVE-2026-35374—0.1%
——0——CVE-2023-21179—0.1%
——0——CVE-2022-48440—0.1%
——0——CVE-2025-36925—0.1%
——0——CVE-2025-20783—0.1%
——0——