Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-169317.5 HIG32.5%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.39dCVE-2026-168527.5 HIG32.5%
——10IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow.28dCVE-2023-23456—32.5%
——10——CVE-2025-6237—32.5%
——10——CVE-2026-123587.5 HIG32.5%
——10IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.5dCVE-2025-69127—32.5%
——10——CVE-2023-47837—32.5%
——10——CVE-2024-2432—32.5%
——10——CVE-2005-4552—32.5%
——10——CVE-2025-69111—32.5%
——10——CVE-2023-26544—32.5%
——10——CVE-2024-11820—32.5%
——10——CVE-2023-45150—32.5%
——10——CVE-2021-0079—32.5%
——10——CVE-2025-47478—32.5%
——10——CVE-2026-592797.5 HIG32.5%
——10The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients.
Affected versions:
Spring AI: 2.0.05dCVE-2022-45871—32.5%
——10——CVE-2021-0063—32.5%
——10——CVE-2022-42372—32.5%
——10——CVE-2026-171997.5 HIG32.5%
——10IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.35dCVE-2023-39500—32.5%
——10——CVE-2024-575296.1 MED32.5%
——10Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.79dCVE-2024-8718—32.5%
——10——CVE-2019-3742—32.5%
——10——CVE-2025-60233—32.5%
——10——CVE-2026-28464—32.5%
——10——CVE-2022-41151—32.5%
——10——CVE-2022-41150—32.5%
——10——CVE-2024-9384—32.5%
——10——CVE-2022-42395—32.5%
——10——CVE-2020-3423—32.5%
——10——CVE-2009-5066—32.5%
——10——CVE-2017-16646—32.5%
——10——CVE-2026-34692.7 LOW32.5%
——10A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.59dCVE-2022-42373—32.5%
——10——CVE-2026-716757.5 HIG32.5%
——10An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c21dCVE-2024-13504—32.5%
——10——CVE-2024-8800—32.5%
——10——CVE-2013-4426—32.5%
——10——CVE-2026-666729.8 CRI32.5%
——10Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.32d