Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-5062—33.0%
——10——CVE-2017-14556—33.0%
——10——CVE-2024-20264—33.0%
——10——CVE-2023-30314—33.0%
——10——CVE-2017-14290—33.0%
——10——CVE-2022-0071—33.0%
——10——CVE-2017-14548—33.0%
——10——CVE-2017-14538—33.0%
——10——CVE-2016-8813—33.0%
——10——CVE-2025-26306—33.0%
——10——CVE-2025-65075—33.0%
——10——CVE-2022-2454—33.0%
——10——CVE-2013-5866—33.0%
——10——CVE-2015-1992—33.0%
——10——CVE-2023-29192—33.0%
——10——CVE-2017-10749—33.0%
——10——CVE-2024-49764—33.0%
——10——CVE-2017-14575—33.0%
——10——CVE-2025-5096—33.0%
——10——CVE-2017-10750—33.0%
——10——CVE-2024-45786—33.0%
——10——CVE-2017-14692—33.0%
——10——CVE-2016-8815—33.0%
——10——CVE-2026-193635.3 MED33.0%
——10A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs` logs raw Authorization header values and complete bearer tokens/JWTs on authentication failure paths, potentially exposing credentials through CloudWatch Logs. `src/models.rs` serializes the complete validated JWT claims set with `serde_json::to_string(token_claims).unwrap()` and propagates it through `context["jwtClaims"]` to downstream integrations. This code performs serialization, not deserialization, and does not process attacker-controlled `jwtClaims` input. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.41dCVE-2017-14573—33.0%
——10——CVE-2026-27125—33.0%
——10——CVE-2024-30618—33.0%
——10——CVE-2017-14580—33.0%
——10——CVE-2022-29580—33.0%
——10——CVE-2025-2910—33.0%
——10——CVE-2022-3267—33.0%
——10——CVE-2023-32260—33.0%
——10——CVE-2026-635236.5 MED33.0%
——10Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.6dCVE-2025-26309—33.0%
——10——CVE-2026-25165—33.0%
——10——CVE-2023-51553—33.0%
——10——CVE-2025-26307—33.0%
——10——CVE-2024-32315—33.0%
——10——CVE-2025-43308—33.0%
——10——CVE-2024-12184—33.0%
——10——