Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,758
- Medium6,799
- Low733
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-81322—0.4%
——0Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with access to logs, error trackers, or crash reports, or anyone who can trigger a validation error, to recover the plaintext of a field the library encrypts.
AshCloak.Transformers.SetUpEncryption removes each cloaked attribute from the action's accept list and adds an action argument that carries the plaintext into the encryption change. That argument is built with sensitive?: attr.sensitive?, inheriting the flag from the source attribute, so a cloaked attribute declared without sensitive? true produces a non-sensitive argument. It is the only place the cleartext value lives, and the one place Ash will not redact: it appears verbatim in inspect(changeset), Ash.Error.Invalid and validation error messages, telemetry, :sys dumps, and error-tracker payloads. The generated encrypted attribute and decrypt calculation are already hardcoded sensitive.
This issue affects ash_cloak: from 0.1.0 before 0.4.0.16dCVE-2024-23712—0.4%
——0——CVE-2024-29750—0.4%
——0——CVE-2024-40677—0.4%
——0——CVE-2025-48636—0.4%
——0——CVE-2023-32823—0.4%
——0——CVE-2023-30913—0.4%
——0——CVE-2026-801714.7 MED0.4%
——0Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.8dCVE-2023-21143—0.4%
——0——CVE-2025-32326—0.4%
——0——CVE-2025-6177—0.4%
——0——CVE-2022-21776—0.4%
——0——CVE-2023-32834—0.4%
——0——CVE-2026-33697—0.4%
——0——CVE-2025-66592—0.4%
——0——CVE-2023-2197—0.4%
——0——CVE-2023-40106—0.4%
——0——CVE-2023-33881—0.4%
——0——CVE-2023-30938—0.4%
——0——CVE-2023-30925—0.4%
——0——CVE-2023-30865—0.4%
——0——CVE-2026-57916—0.4%
——0proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
This issue was fixed in version 9.4.3.90.49dCVE-2023-32836—0.4%
——0——CVE-2023-30921—0.4%
——0——CVE-2023-30922—0.4%
——0——CVE-2026-64158—0.4%
——0Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.30dCVE-2023-33911—0.4%
——0——CVE-2023-30923—0.4%
——0——CVE-2023-30926—0.4%
——0——CVE-2025-48541—0.4%
——0——CVE-2023-42750—0.4%
——0——CVE-2023-40131—0.4%
——0——CVE-2025-66593—0.4%
——0——CVE-2023-21367—0.4%
——0——CVE-2023-30930—0.4%
——0——CVE-2023-30866—0.4%
——0——CVE-2025-4618—0.4%
——0——CVE-2018-9378—0.4%
——0——CVE-2023-21369—0.3%
——0——CVE-2018-9403—0.3%
——0——