Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-01948.4 HIG0.3%
——0In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.20hCVE-2025-48632—0.3%
——0——CVE-2026-114812.5 LOW0.3%
——0A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.57dCVE-2025-13492—0.3%
——0——CVE-2026-567977.3 HIG0.3%
——0Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.27dCVE-2026-586787.8 HIG0.3%
——0In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.20hCVE-2025-20775—0.3%
——0——CVE-2024-31327—0.3%
——0——CVE-2024-47032—0.3%
——0——CVE-2025-48629—0.3%
——0——CVE-2023-48356—0.3%
——0——CVE-2023-40631—0.3%
——0——CVE-2026-41971—0.3%
——0——CVE-2025-0076—0.2%
——0——CVE-2024-20099—0.2%
——0——CVE-2023-38445—0.2%
——0——CVE-2023-38462—0.2%
——0——CVE-2025-22428—0.2%
——0——CVE-2024-40664—0.2%
——0——CVE-2023-38446—0.2%
——0——CVE-2022-48457—0.2%
——0——CVE-2025-32322—0.2%
——0——CVE-2025-20783—0.2%
——0——CVE-2022-47354—0.2%
——0——CVE-2025-20804—0.2%
——0——CVE-2022-48458—0.2%
——0——CVE-2024-29784—0.2%
——0——CVE-2025-47353—0.2%
——0——CVE-2025-58311—0.2%
——0——CVE-2024-27222—0.2%
——0——CVE-2025-47320—0.2%
——0——CVE-2025-20787—0.2%
——0——CVE-2025-20785—0.2%
——0——CVE-2026-27670—0.2%
——0——CVE-2023-48346—0.2%
——0——CVE-2026-499585.0 MED0.2%
——0Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete files outside the configured workspace boundary by replacing a validated path component with a symlink after validation but before deletion. Attackers can substitute a workspace-controlled path component with a symlink pointing to an external directory between the safe_resolve_ws() validation step and the subsequent Path.unlink() or shutil.rmtree() deletion call, causing the delete operation to follow the symlink and remove arbitrary files outside the workspace.57dCVE-2026-568886.2 MED0.2%
——0In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.1dCVE-2026-31430—0.2%
——0——CVE-2023-48347—0.2%
——0——CVE-2023-48341—0.2%
——0——