Vulnerabilities exploitable today
363,707in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,925
- High12,301
- Medium7,512
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34857—0.0%
——0——CVE-2023-20788—0.0%
——0——CVE-2026-0125—0.0%
——0——CVE-2023-20684—0.0%
——0——CVE-2025-58316—0.0%
——0——CVE-2026-213667.8 HIG0.0%
——0Memory corruption while processing a packet with a size close to the maximum allowed value.15dCVE-2026-130676.3 MED0.0%
——0When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.16dCVE-2025-463713.6 LOW0.0%
——0Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the ssh. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.29dCVE-2026-20437—0.0%
——0——CVE-2025-21485—0.0%
——0——CVE-2026-28537—0.0%
——0——CVE-2025-41743—0.0%
——0——CVE-2026-00897.8 HIG0.0%
——0In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2026-0153—0.0%
——0——CVE-2026-0142—0.0%
——0——CVE-2026-213797.8 HIG0.0%
——0Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.45dCVE-2026-0150—0.0%
——0——CVE-2026-240807.8 HIG0.0%
——0Memory Corruption when handling malformed request parameters in the fingerprint TA.15dCVE-2023-20801—0.0%
——0——CVE-2026-0133—0.0%
——0——CVE-2026-28538—0.0%
——0——CVE-2022-20243—0.0%
——0——CVE-2023-20687—0.0%
——0——CVE-2025-486485.5 MED0.0%
——0In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2024-45547—0.0%
——0——CVE-2025-48641—0.0%
——0——CVE-2025-47333—0.0%
——0——CVE-2026-34862—0.0%
——0——CVE-2026-00987.8 HIG0.0%
——0In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.30dCVE-2019-20775—0.0%
——0——CVE-2026-28543—0.0%
——0——CVE-2021-25502—0.0%
——0——CVE-2026-440594.5 MED0.0%
——0A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain limited information, modify limited data, or cause a minor service disruption.29dCVE-2024-53018—0.0%
——0——CVE-2026-24930—0.0%
——0——CVE-2026-16458—0.0%
——0Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.8dCVE-2025-596166.6 MED0.0%
——0Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.45dCVE-2026-252597.8 HIG0.0%
——0Memory corruption while processing multiple IOCTL command for escape operations.30dCVE-2026-21002—0.0%
——0——CVE-2025-57806—0.0%
——0——