Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-20779—0.3%
——0——CVE-2026-23165—0.3%
——0——CVE-2026-30785—0.3%
——0——CVE-2023-21321—0.3%
——0——CVE-2026-569796.7 MED0.3%
——0In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.20hCVE-2026-553026.7 MED0.3%
——0In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.1dCVE-2026-553597.8 HIG0.3%
——0In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.20hCVE-2026-00777.8 HIG0.3%
——0In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.57dCVE-2023-48355—0.3%
——0——CVE-2024-13454—0.3%
——0——CVE-2024-32907—0.3%
——0——CVE-2025-36906—0.3%
——0——CVE-2026-41971—0.3%
——0——CVE-2023-40631—0.3%
——0——CVE-2023-48356—0.3%
——0——CVE-2022-39887—0.3%
——0——CVE-2023-21345—0.3%
——0——CVE-2023-48359—0.3%
——0——CVE-2026-45413—0.3%
——0MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute force (hashcat). This vulnerability is fixed in 2.9.1.57dCVE-2026-328484.7 MED0.3%
——0NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.65dCVE-2023-21350—0.3%
——0——CVE-2023-32825—0.3%
——0——CVE-2023-40113—0.3%
——0——CVE-2023-42655—0.3%
——0——CVE-2023-33046—0.3%
——0——CVE-2025-20770—0.3%
——0——CVE-2026-24921—0.3%
——0——CVE-2024-32927—0.3%
——0——CVE-2025-48607—0.3%
——0——CVE-2025-48601—0.3%
——0——CVE-2023-52350—0.3%
——0——CVE-2025-20777—0.3%
——0——CVE-2026-800477.8 HIG0.3%
——0A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent check, inverting the security model enforced by other code-loading paths (such as AutoConfig, AutoModel, and AutoTokenizer). As a result, attacker‑controlled Python code from custom_generate/generate.py is copied into the user’s ~/.cache/huggingface/modules directory even if the user declines the trust prompt. Although execution is correctly gated, the file write is not reversible and can persist across sessions. This can lead to persistent, unauthorized files on disk and stale cache collisions where cached attacker code may later be executed during trusted model loads. The issue stems from an unconditional file write in dynamic_module_utils.py prior to any trust verification.14dCVE-2025-26448—0.3%
——0——CVE-2026-28758—0.3%
——0——CVE-2025-48554—0.3%
——0——CVE-2018-9428—0.3%
——0——CVE-2023-21141—0.3%
——0——CVE-2023-40653—0.3%
——0——CVE-2025-20773—0.3%
——0——