Vulnerabilities exploitable today
365,446in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,324
- High9,977
- Medium4,917
- Low460
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-34864—0.1%
——0——CVE-2024-38406—0.1%
——0——CVE-2023-20746—0.1%
——0——CVE-2018-9461—0.1%
——0——CVE-2024-32910—0.1%
——0——CVE-2025-47346—0.1%
——0——CVE-2024-47015—0.1%
——0——CVE-2026-261037.1 HIG0.1%
——0A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.44dCVE-2025-596047.8 HIG0.1%
——0Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.36dCVE-2025-36931—0.1%
——0——CVE-2026-01007.8 HIG0.1%
——0In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2025-682437.0 HIG0.1%
——0In the Linux kernel, the following vulnerability has been resolved:
NFS: Check the TLS certificate fields in nfs_match_client()
If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the
cert_serial and privkey_serial fields need to match as well since they
define the client's identity, as presented to the server.28dCVE-2025-20028—0.1%
——0——CVE-2025-32320—0.1%
——0——CVE-2026-24082—0.1%
——0——CVE-2026-419855.1 MED0.1%
——0UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.35dCVE-2026-24929—0.1%
——0——CVE-2026-285814.0 MED0.1%
——0In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.36dCVE-2025-21455—0.1%
——0——CVE-2026-3428—0.1%
——0——CVE-2026-0123—0.1%
——0——CVE-2026-00967.8 HIG0.1%
——0In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2025-9142—0.1%
——0——CVE-2023-21260—0.1%
——0——CVE-2026-12374—0.1%
——0Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.56dCVE-2024-49742—0.1%
——0——CVE-2025-20800—0.1%
——0——CVE-2025-36751—0.1%
——0——CVE-2023-21120—0.1%
——0——CVE-2026-0152—0.1%
——0——CVE-2025-35054—0.1%
——0——CVE-2025-20806—0.1%
——0——CVE-2026-00435.5 MED0.1%
——0In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.36dCVE-2021-39660—0.1%
——0——CVE-2024-47034—0.1%
——0——CVE-2024-0028—0.1%
——0——CVE-2025-36921—0.1%
——0——CVE-2026-252717.8 HIG0.1%
——0Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.51dCVE-2026-11347—0.1%
——0——CVE-2025-52532—0.1%
——0——