Vulnerabilities exploitable today
361,124in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,670
New KEV · 24H0
Exploit Today ≥ 701,609
Distribution · last window
- Critical2,672
- High11,546
- Medium7,179
- Low661
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-7007—88.5%
——27——CVE-2017-13752—88.5%
——27——CVE-2023-2246—88.5%
——27——CVE-2017-17622—88.5%
——27——CVE-2013-2602—88.5%
——27——CVE-2018-20743—88.5%
——27——CVE-2017-13751—88.5%
——27——CVE-2007-6604—88.5%
——27——CVE-2011-2992—88.5%
——27——CVE-2022-34121—88.5%
——27——CVE-2014-2606—88.5%
——27——CVE-2018-2818—88.5%
——27——CVE-2008-3128—88.5%
——27——CVE-2025-594657.5 HIG88.5%
——27A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:
```
server.on('secureConnection', socket => {
socket.on('error', err => {
console.log(err)
})
})
```35dCVE-2020-2773—88.5%
——27——CVE-2019-9927—88.5%
——27——CVE-2009-1609—88.5%
——27——CVE-2014-9842—88.5%
——27——CVE-2006-1909—88.5%
——27——CVE-2026-4368—88.5%
——27——CVE-2019-6334—88.5%
——27——CVE-2014-9850—88.5%
——27——CVE-2016-3086—88.5%
——27——CVE-2004-1467—88.5%
——27——CVE-2012-2290—88.5%
——27——CVE-2014-6609—88.5%
——27——CVE-2014-1245—88.5%
——27——CVE-2005-1677—88.5%
——27——CVE-2015-0980—88.5%
——27——CVE-2006-3744—88.5%
——27——CVE-1999-1128—88.5%
——27——CVE-2016-4293—88.5%
——27——CVE-2018-20252—88.5%
——27——CVE-2019-19499—88.5%
——27——CVE-2019-17556—88.5%
——27——CVE-2022-3634—88.5%
——27——CVE-2022-21350—88.5%
——27——CVE-2019-20218—88.5%
——27——CVE-2006-3528—88.5%
——27——CVE-2018-10844—88.5%
——27——