Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,379
- High8,748
- Medium6,793
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2022-45818—29.8%
——9——CVE-2021-28705—29.8%
——9——CVE-2026-354416.5 MED29.8%
——9Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user could exploit GraphQL aliasing to repeat an expensive relational query many times in a single request, forcing the server to execute a large number of independent complex database queries concurrently, multiplying database load linearly with the number of aliases. The existing token limit on GraphQL queries still permitted enough aliases for significant resource exhaustion, while the relational depth limit applied per alias without reducing the total number executed. Rate limiting is disabled by default, meaning no built-in throttle prevented this from causing CPU, memory, and I/O exhaustion that could degrade or crash the service. Any authenticated user, including those with minimal read-only permissions, could trigger this condition. This vulnerability is fixed in 11.17.0.56dCVE-2023-37454—29.8%
——9——CVE-2023-23889—29.8%
——9——CVE-2023-23676—29.8%
——9——CVE-2023-22696—29.8%
——9——CVE-2023-31079—29.8%
——9——CVE-2023-1916—29.8%
——9——CVE-2024-7079—29.8%
——9——CVE-2023-22713—29.8%
——9——CVE-2012-4518—29.8%
——9——CVE-2017-5042—29.8%
——9——CVE-2026-692137.5 HIG29.8%
——9Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue sending PING, SETTINGS, or DATA frames that cause Ember to enqueue acknowledgments or WINDOW_UPDATE frames faster than the writer drains them, exhausting heap memory on a server built with withHttp2. The shared behavior also affects an ember-client connected to a hostile HTTP/2 server, and the patch replaces the unbounded path with bounded, backpressured outbound queues. This issue is fixed in versions 0.23.35 and 1.0.0-M47.2dCVE-2012-3212—29.8%
——9——CVE-2020-0513—29.8%
——9——CVE-2022-45812—29.8%
——9——CVE-2011-1375—29.8%
——9——CVE-2023-23685—29.8%
——9——CVE-2023-23826—29.8%
——9——CVE-2025-47985—29.8%
——9——CVE-2023-23709—29.8%
——9——CVE-2026-58071—29.8%
——9A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.15dCVE-2026-629607.4 HIG29.8%
——9Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.23dCVE-2025-46345—29.8%
——9——CVE-2023-41728—29.8%
——9——CVE-2025-11345—29.8%
——9——CVE-2023-23641—29.8%
——9——CVE-2016-3750—29.8%
——9——CVE-2024-6938—29.8%
——9——CVE-2024-3071—29.8%
——9——CVE-2025-69197—29.8%
——9——CVE-2023-23817—29.8%
——9——CVE-2025-11211—29.8%
——9——CVE-2016-4627—29.8%
——9——CVE-2023-27443—29.8%
——9——CVE-2024-45999—29.8%
——9——CVE-2023-23701—29.8%
——9——CVE-2011-5032—29.8%
——9——CVE-2021-286917.8 HIG29.8%
——9Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.23d