Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,921
- High12,266
- Medium7,474
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-596057.8 HIG0.1%
——0Memory Corruption when processing device identifier strings that exceed the expected maximum length.30dCVE-2025-598663.3 LOW0.1%
——0The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.35dCVE-2025-20786—0.1%
——0——CVE-2026-108003.6 LOW0.1%
——0A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.30dCVE-2026-419775.0 MED0.1%
——0DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.29dCVE-2025-47337—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-285814.0 MED0.1%
——0In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.30dCVE-2026-43053—0.1%
——0——CVE-2026-418608.8 HIG0.1%
——0CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later30dCVE-2026-41051—0.1%
——0——CVE-2024-53839—0.1%
——0——CVE-2025-35054—0.1%
——0——CVE-2026-252778.8 HIG0.1%
——0Memory corruption while using Strongbox due to buffer overflow.30dCVE-2025-47336—0.1%
——0——CVE-2024-38406—0.1%
——0——CVE-2025-36935—0.1%
——0——CVE-2025-47405—0.1%
——0——CVE-2026-23115—0.1%
——0——CVE-2025-47335—0.1%
——0——CVE-2026-108133.6 LOW0.1%
——0A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.30dCVE-2024-44095—0.1%
——0——CVE-2017-6284—0.1%
——0——CVE-2025-20784—0.1%
——0——CVE-2025-20765—0.1%
——0——CVE-2025-32320—0.1%
——0——CVE-2025-58279—0.1%
——0——CVE-2026-467326.7 MED0.1%
——0Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.42dCVE-2025-20980—0.1%
——0——CVE-2026-0108—0.1%
——0——CVE-2024-23716—0.1%
——0——CVE-2026-21380—0.1%
——0——CVE-2022-20117—0.1%
——0——CVE-2026-28547—0.1%
——0——CVE-2022-48441—0.1%
——0——CVE-2024-29778—0.1%
——0——CVE-2025-596047.8 HIG0.1%
——0Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.30dCVE-2026-34849—0.1%
——0——CVE-2023-21179—0.1%
——0——CVE-2024-32914—0.1%
——0——