Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47339—0.2%
——0——CVE-2023-20618—0.2%
——0——CVE-2026-641715.5 MED0.2%
——0In the Linux kernel, the following vulnerability has been resolved:
i2c: tegra: fix pm_runtime leak on mutex_lock failure
If tegra_i2c_mutex_lock() fails, the function returns without calling
pm_runtime_put(), leaking the runtime PM reference acquired by the
preceding pm_runtime_get_sync(). This prevents the device from ever
entering runtime suspend.
Add the missing pm_runtime_put() before returning on lock failure.35dCVE-2024-56192—0.2%
——0——CVE-2023-20619—0.2%
——0——CVE-2026-213845.3 MED0.2%
——0Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.72dCVE-2023-37396—0.2%
——0——CVE-2023-42634—0.2%
——0——CVE-2025-36922—0.2%
——0——CVE-2023-42638—0.2%
——0——CVE-2024-40654—0.2%
——0——CVE-2022-36848—0.2%
——0——CVE-2025-486497.8 HIG0.2%
——0In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.58dCVE-2024-20114—0.2%
——0——CVE-2023-42642—0.2%
——0——CVE-2023-42644—0.2%
——0——CVE-2025-35054—0.2%
——0——CVE-2026-588397.8 HIG0.2%
——0In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.9dCVE-2023-42637—0.2%
——0——CVE-2025-20766—0.2%
——0——CVE-2026-499327.8 HIG0.2%
——0In parseParts of PduParser.java, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.9dCVE-2026-28546—0.2%
——0——CVE-2025-26432—0.2%
——0——CVE-2024-40655—0.2%
——0——CVE-2024-49733—0.2%
——0——CVE-2023-21234—0.2%
——0——CVE-2025-20636—0.2%
——0——CVE-2025-20763—0.2%
——0——CVE-2023-21362—0.2%
——0——CVE-2025-47388—0.2%
——0——CVE-2026-184774.4 MED0.2%
——0A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.7dCVE-2025-20743—0.2%
——0——CVE-2023-42643—0.2%
——0——CVE-2026-67433—0.2%
——0Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would be followed by sqlite3.connect() during a root-run check.49dCVE-2026-169237.0 HIG0.2%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.24dCVE-2026-493063.3 LOW0.2%
——0UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.22dCVE-2023-42632—0.2%
——0——CVE-2025-41762—0.2%
——0——CVE-2025-27725—0.2%
——0——CVE-2018-9424—0.2%
——0——