Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-5525—34.0%
——10——CVE-2024-96664.7 MED34.0%
——10A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service.
The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.2dCVE-2010-5224—34.0%
——10——CVE-2024-35229—34.0%
——10——CVE-2026-32733—34.0%
——10——CVE-2025-8519—34.0%
——10——CVE-2010-5231—34.0%
——10——CVE-2020-15304—34.0%
——10——CVE-2022-2237—34.0%
——10——CVE-2025-30944—34.0%
——10——CVE-2025-63679—34.0%
——10——CVE-2010-5229—34.0%
——10——CVE-2010-5273—34.0%
——10——CVE-2002-2293—34.0%
——10——CVE-2010-5235—34.0%
——10——CVE-2023-4105—34.0%
——10——CVE-2001-1593—34.0%
——10——CVE-2024-3261—34.0%
——10——CVE-2024-12559—34.0%
——10——CVE-2023-32105—34.0%
——10——CVE-2024-1868—34.0%
——10——CVE-2026-845048.1 HIG34.0%
——10fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make nested data replace the validated body and trigger an operation the route schema did not authorize, leading to unauthorized state changes and data disclosure. Users should upgrade to fastify 5.12.2 or later.7dCVE-2021-1277—34.0%
——10——CVE-2024-47417—34.0%
——10——CVE-2026-115467.1 HIG34.0%
——10IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-1.0 feature enabled.83dCVE-2026-862894.3 MED34.0%
——10A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.11dCVE-2023-46448—34.0%
——10——CVE-2024-6888—34.0%
——10——CVE-2026-15310—34.0%
——10When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.6dCVE-2025-63019—34.0%
——10——CVE-2026-21676—34.0%
——10——CVE-2010-5248—34.0%
——10——CVE-2026-87791—34.0%
——10A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.5dCVE-2025-24432—34.0%
——10——CVE-2005-3629—34.0%
——10——CVE-2006-3786—34.0%
——10——CVE-2026-866697.3 HIG34.0%
——10A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.15dCVE-2007-5936—34.0%
——10——CVE-2023-32742—34.0%
——10——CVE-2023-32801—34.0%
——10——