Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,326
- High8,522
- Medium6,833
- Low770
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-552537.7 HIG32.9%
——10LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively rejecting keys prefixed with $. An authenticated caller who controls a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi-tenant deployment that uses the filter to enforce per-user or per-tenant isolation, injected operators can bypass intended equality filtering and expose other tenants' checkpoint or store data. Filters constructed entirely from trusted server-side values have lower practical risk. This issue is fixed in langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0.8dCVE-2017-17224—32.9%
——10——CVE-2025-24319—32.9%
——10——CVE-2024-32063—32.9%
——10——CVE-2014-4455—32.9%
——10——CVE-2026-542646.1 MED32.9%
——10Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm. This allows a remote attacker to obtain sensitive credentials (e.g., Authorization tokens, Proxy-Authorization credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.75dCVE-2016-5995—32.9%
——10——CVE-2017-3301—32.9%
——10——CVE-2016-20080—32.9%
——10——CVE-2024-39097—32.9%
——10——CVE-2024-32062—32.9%
——10——CVE-2010-3079—32.9%
——10——CVE-2024-51838—32.9%
——10——CVE-2024-51836—32.9%
——10——CVE-2024-51831—32.9%
——10——CVE-2024-51832—32.9%
——10——CVE-2021-46657—32.9%
——10——CVE-2024-51830—32.9%
——10——CVE-2025-9464—32.9%
——10——CVE-2025-20060—32.9%
——10——CVE-2024-11479—32.9%
——10——CVE-2024-48712—32.9%
——10——CVE-2023-5001—32.9%
——10——CVE-2010-2537—32.9%
——10——CVE-2006-1444—32.9%
——10——CVE-2024-54935—32.9%
——10——CVE-2018-11506—32.9%
——10——CVE-2018-25379—32.9%
——10——CVE-2024-50515—32.9%
——10——CVE-2024-51804—32.9%
——10——CVE-2024-50841—32.9%
——10——CVE-2001-0914—32.9%
——10——CVE-2025-31123—32.9%
——10——CVE-2024-51842—32.9%
——10——CVE-2026-242338.4 HIG32.9%
——10NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.69dCVE-2024-51844—32.9%
——10——CVE-2023-4218—32.9%
——10——CVE-2025-9685—32.9%
——10——CVE-2024-51855—32.9%
——10——CVE-2019-19578—32.9%
——10——