Vulnerabilities exploitable today
363,458in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,907
- High12,362
- Medium7,578
- Low709
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-5103—88.2%
——26——CVE-2022-27373—88.2%
——26——CVE-2005-1164—88.2%
——26——CVE-2026-503437.8 HIG88.2%
——26Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.29dCVE-2004-0156—88.2%
——26——CVE-2021-25916—88.2%
——26——CVE-2018-0969—88.2%
——26——CVE-2024-12483—88.2%
——26——CVE-2015-5382—88.2%
——26——CVE-2021-3537—88.2%
——26——CVE-2008-3616—88.2%
——26——CVE-2023-33443—88.2%
——26——CVE-2009-5087—88.2%
——26——CVE-2006-5288—88.2%
——26——CVE-2014-4690—88.2%
——26——CVE-2019-19459—88.2%
——26——CVE-2022-24311—88.2%
——26——CVE-2001-1184—88.2%
——26——CVE-2013-2021—88.2%
——26——CVE-2022-0730—88.2%
——26——CVE-2018-0973—88.2%
——26——CVE-2014-4263—88.2%
——26——CVE-2017-11356—88.2%
——26——CVE-2016-7794—88.2%
——26——CVE-2014-3158—88.2%
——26——CVE-2018-10110—88.2%
——26——CVE-2015-5459—88.2%
——26——CVE-2019-6263—88.2%
——26——CVE-2020-9594—88.2%
——26——CVE-2026-425338.1 HIG88.2%
——26A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Impact:
This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.10dCVE-2019-10746—88.2%
——26——CVE-2002-0578—88.2%
——26——CVE-2022-1163—88.2%
——26——CVE-2019-19505—88.2%
——26——CVE-2017-8287—88.2%
——26——CVE-2015-5690—88.2%
——26——CVE-2022-47943—88.2%
——26——CVE-2017-14586—88.2%
——26——CVE-2014-4244—88.2%
——26——CVE-2022-42493—88.2%
——26——