Vulnerabilities exploitable today
361,121in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,666
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,674
- High11,555
- Medium7,180
- Low661
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2012-0866—88.5%
——27——CVE-2006-3703—88.5%
——27——CVE-2019-5597—88.5%
——27——CVE-2005-3026—88.5%
——27——CVE-2017-1002022—88.5%
——27——CVE-2013-0845—88.5%
——27——CVE-2007-6316—88.5%
——27——CVE-2022-25900—88.5%
——27——CVE-2022-33140—88.5%
——27——CVE-2004-2646—88.5%
——27——CVE-2022-24681—88.5%
——27——CVE-2004-0221—88.5%
——27——CVE-2003-1511—88.5%
——27——CVE-2020-7238—88.5%
——27——CVE-2004-2127—88.5%
——27——CVE-2010-3692—88.5%
——27——CVE-2005-2010—88.5%
——27——CVE-2004-2647—88.5%
——27——CVE-2018-12603—88.5%
——27——CVE-2014-1250—88.5%
——27——CVE-2024-57376—88.5%
——27——CVE-2013-4785—88.5%
——27——CVE-2022-23088—88.5%
——27——CVE-2014-9849—88.5%
——27——CVE-2019-9915—88.5%
——27——CVE-2016-6645—88.5%
——27——CVE-2022-28330—88.5%
——27——CVE-2025-594657.5 HIG88.5%
——27A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:
```
server.on('secureConnection', socket => {
socket.on('error', err => {
console.log(err)
})
})
```35dCVE-2005-2952—88.5%
——27——CVE-2022-21350—88.5%
——27——CVE-2019-17556—88.5%
——27——CVE-2021-1668—88.5%
——27——CVE-2019-20218—88.5%
——27——CVE-2025-68614—88.5%
——27——CVE-2017-2963—88.5%
——27——CVE-2007-6604—88.5%
——27——CVE-2018-10844—88.5%
——27——CVE-2017-13751—88.5%
——27——CVE-2007-6480—88.5%
——27——CVE-2005-0782—88.5%
——27——