Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,383
- High8,771
- Medium6,812
- Low735
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-33231—0.2%
——0——CVE-2023-20618—0.2%
——0——CVE-2025-20764—0.2%
——0——CVE-2025-62311—0.2%
——0——CVE-2024-39435—0.2%
——0——CVE-2022-39847—0.2%
——0——CVE-2023-42633—0.2%
——0——CVE-2023-42632—0.2%
——0——CVE-2026-493063.3 LOW0.2%
——0UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.22dCVE-2025-20744—0.2%
——0——CVE-2026-169237.0 HIG0.2%
——0IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.24dCVE-2017-13308—0.2%
——0——CVE-2026-642385.5 MED0.2%
——0In the Linux kernel, the following vulnerability has been resolved:
gpio: shared: fix deadlock on shared proxy's parent removal
Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set")
used the mutex embedded in struct gpio_shared_entry to protect the
offset field which now can be modified after assignment. The critical
section however is too wide and introduced a potential deadlock on the
removal of the shared GPIO proxy's parent.
Make the critical section shorter - only protect the offset when it's
being read.
While at it: mention the fact that the entry lock is now also used to
protect against concurrent access to the offset field in the structure's
documentation.35dCVE-2023-42650—0.2%
——0——CVE-2025-32346—0.2%
——0——CVE-2026-41968—0.2%
——0——CVE-2023-21234—0.2%
——0——CVE-2025-20636—0.2%
——0——CVE-2023-42635—0.2%
——0——CVE-2024-40655—0.2%
——0——CVE-2023-42642—0.2%
——0——CVE-2025-27039—0.2%
——0——CVE-2024-29787—0.2%
——0——CVE-2024-20122—0.2%
——0——CVE-2026-843818.1 HIG0.2%
——0HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query parameters, Authorization headers, cookies, and subsequent frames can cross the proxy path in plaintext without certificate verification. An attacker controlling or observing that path can read or modify traffic and impersonate the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 2.10.0.13dCVE-2026-150604.7 MED0.2%
——0When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones.
- versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file
- versions older than v258 are not affected
- unrelated to the systemd service manager (pid 1 or user session managers)
- systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container)
- terminal-only or remote sessions (e.g.: ssh) are not affected16dCVE-2026-874578.1 HIG0.2%
——0Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)8dCVE-2026-40224—0.2%
——0——CVE-2024-42186—0.2%
——0——CVE-2026-498847.8 HIG0.2%
——0In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.7dCVE-2025-27064—0.2%
——0——CVE-2026-01866.7 MED0.2%
——0In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.1dCVE-2023-40648—0.1%
——0——CVE-2023-40644—0.2%
——0——CVE-2026-01876.7 MED0.2%
——0In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.1dCVE-2026-286127.8 HIG0.2%
——0In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2026-204546.4 MED0.2%
——0In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.58dCVE-2022-26450—0.2%
——0——CVE-2025-48558—0.2%
——0——CVE-2026-21444—0.2%
——0——