Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,381
- High8,755
- Medium6,799
- Low731
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-12285—29.6%
——9——CVE-2023-30612—29.6%
——9——CVE-2015-0427—29.6%
——9——CVE-2009-2707—29.6%
——9——CVE-2019-25508—29.6%
——9——CVE-2007-4501—29.6%
——9——CVE-2021-3844—29.6%
——9——CVE-2021-44197—29.6%
——9——CVE-2023-48913—29.6%
——9——CVE-2017-8281—29.6%
——9——CVE-2026-418507.5 HIG29.6%
——9Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.57dCVE-2022-42379—29.6%
——9——CVE-2022-42380—29.6%
——9——CVE-2019-16007—29.6%
——9——CVE-2023-48914—29.6%
——9——CVE-2004-2591—29.6%
——9——CVE-2024-12222—29.6%
——9——CVE-2018-12193—29.6%
——9——CVE-2025-64387—29.6%
——9——CVE-2026-2264—29.6%
——9——CVE-2017-5940—29.6%
——9——CVE-2023-48912—29.6%
——9——CVE-2024-4994—29.6%
——9——CVE-2014-6588—29.6%
——9——CVE-2026-21075—29.6%
——9Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.31dCVE-2023-43989—29.6%
——9——CVE-2026-199137.5 HIG29.6%
——9The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the response is subsequently deserialized and its raw contents are reflected to the client in an error message; this enables an unauthenticated, remote attacker to read any arbitrary internal file reachable by the server. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable endpoint.15dCVE-2003-0014—29.6%
——9——CVE-2017-17113—29.6%
——9——CVE-2023-33058—29.6%
——9——CVE-2026-418515.3 MED29.6%
——9Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.57dCVE-2017-17469—29.6%
——9——CVE-2026-44859—29.6%
——9——CVE-2023-32163—29.6%
——9——CVE-2024-13447—29.6%
——9——CVE-2014-3917—29.6%
——9——CVE-2024-32466—29.6%
——9——CVE-2005-2657—29.6%
——9——CVE-2004-0108—29.6%
——9——CVE-2024-2508—29.6%
——9——