Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,322
- High9,974
- Medium4,913
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-168026.5 MED0.1%
——0Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.29dCVE-2024-20112—0.1%
——0——CVE-2023-21179—0.1%
——0——CVE-2026-41964—0.1%
——0——CVE-2023-38457—0.1%
——0——CVE-2025-58303—0.1%
——0——CVE-2023-38448—0.1%
——0——CVE-2025-47343—0.1%
——0——CVE-2025-20730—0.1%
——0——CVE-2026-11330—0.1%
——0——CVE-2025-20786—0.1%
——0——CVE-2025-596057.8 HIG0.1%
——0Memory Corruption when processing device identifier strings that exceed the expected maximum length.36dCVE-2025-47408—0.1%
——0——CVE-2023-40640—0.1%
——0——CVE-2024-38407—0.1%
——0——CVE-2025-47393—0.1%
——0——CVE-2023-20733—0.1%
——0——CVE-2026-419795.5 MED0.1%
——0Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.35dCVE-2024-47024—0.1%
——0——CVE-2023-38463—0.1%
——0——CVE-2025-20980—0.1%
——0——CVE-2026-41051—0.1%
——0——CVE-2026-623816.6 MED0.1%
——0luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256 bytes, requiring one additional DER length octet. As a result the allocation is 259 bytes while the tag, length, unused-bits byte, and signature require 260 bytes, and the final memcpy writes one byte beyond the heap buffer. The overflow is reachable through the exported Lua interface via create_selfsigned(); whether it is remotely exploitable depends on the embedding application. The vulnerable code is present on the openwrt-18.06 through openwrt-25.12 release branches and is absent from master, where the luci-lib-px5g package has been removed rather than patched.3dCVE-2024-32904—0.1%
——0——CVE-2024-39440—0.1%
——0——CVE-2018-9421—0.1%
——0——CVE-2026-108003.6 LOW0.1%
——0A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is associated with this attack. The exploitation is known to be difficult. This patch is called 374945747652a8d32965591c0c01a00c88b7067f. Applying a patch is advised to resolve this issue.36dCVE-2024-32921—0.1%
——0——CVE-2022-20219—0.1%
——0——CVE-2024-44095—0.1%
——0——CVE-2026-00866.8 MED0.1%
——0In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2025-20783—0.1%
——0——CVE-2025-10227—0.1%
——0——CVE-2025-596067.8 HIG0.1%
——0Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.36dCVE-2024-39433—0.1%
——0——CVE-2024-32930—0.1%
——0——CVE-2022-20117—0.1%
——0——CVE-2025-36919—0.1%
——0——CVE-2025-58279—0.1%
——0——CVE-2018-9420—0.1%
——0——