Vulnerabilities exploitable today
377,415in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H3
Exploit Today ≥ 701,647
Distribution · last window
- Critical2,355
- High8,510
- Medium6,633
- Low715
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-21190—0.1%
——0——CVE-2026-569868.4 HIG0.1%
——0In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.3hCVE-2026-02957.0 HIG0.1%
——0A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.8dCVE-2026-462984.7 MED0.1%
——0In the Linux kernel, the following vulnerability has been resolved:
pseries/papr-hvpipe: Fix race with interrupt handler
While executing ->ioctl handler or ->release handler, if an interrupt
fires on the same cpu, then we can enter into a deadlock.
This patch fixes both these handlers to take spin_lock_irq{save|restore}
versions of the lock to prevent this deadlock.58dCVE-2022-20117—0.1%
——0——CVE-2024-45560—0.1%
——0——CVE-2024-38418—0.1%
——0——CVE-2026-419743.6 LOW0.1%
——0Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.58dCVE-2026-419795.5 MED0.1%
——0Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.58dCVE-2025-2909—0.1%
——0——CVE-2024-47016—0.1%
——0——CVE-2026-252768.8 HIG0.1%
——0Memory corruption while using Strongbox due to missing bounds check.58dCVE-2024-49744—0.1%
——0——CVE-2026-01454.0 MED0.1%
——0In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2024-49736—0.1%
——0——CVE-2026-218104.4 MED0.1%
——0HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.21dCVE-2026-41307.1 HIG0.1%
——0There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.2dCVE-2025-596057.8 HIG0.1%
——0Memory Corruption when processing device identifier strings that exceed the expected maximum length.58dCVE-2026-455253.3 LOW0.1%
——0In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.8dCVE-2024-47024—0.1%
——0——CVE-2026-34849—0.1%
——0——CVE-2026-0138—0.1%
——0——CVE-2026-419775.0 MED0.1%
——0DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.58dCVE-2026-24509—0.1%
——0——CVE-2026-00866.8 MED0.1%
——0In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.58dCVE-2026-26104—0.1%
——0——CVE-2026-168026.5 MED0.1%
——0Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.51dCVE-2023-20743—0.1%
——0——CVE-2026-252717.8 HIG0.1%
——0Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.73dCVE-2022-48441—0.1%
——0——CVE-2024-47033—0.1%
——0——CVE-2025-47405—0.1%
——0——CVE-2026-11330—0.1%
——0——CVE-2022-48440—0.1%
——0——CVE-2025-596047.8 HIG0.1%
——0Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.58dCVE-2026-01424.0 MED0.1%
——0In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2026-108013.6 LOW0.1%
——0A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.58dCVE-2026-286603.3 LOW0.1%
——0In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.3dCVE-2024-38407—0.1%
——0——CVE-2024-47041—0.1%
——0——