Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,210
- High7,852
- Medium6,391
- Low708
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-694787.8 HIG28.1%
——8Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.7dCVE-2024-40277.5 HIG28.1%
——8A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.15dCVE-2022-41843—28.1%
——8——CVE-2023-22418—28.1%
——8——CVE-2024-2656—28.1%
——8——CVE-2020-37089—28.1%
——8——CVE-2026-699217.8 HIG28.1%
——8Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.7dCVE-2001-0984—28.1%
——8——CVE-2001-1111—28.1%
——8——CVE-1999-1025—28.1%
——8——CVE-2026-52866—28.1%
——8——CVE-2002-0973—28.1%
——8——CVE-2025-4744—28.1%
——8——CVE-2006-0386—28.1%
——8——CVE-2025-54132—28.1%
——8——CVE-1999-1562—28.1%
——8——CVE-2025-53474—28.1%
——8——CVE-2010-0119—28.1%
——8——CVE-2026-702897.8 HIG28.1%
——8Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.1dCVE-2014-4425—28.1%
——8——CVE-2023-47727—28.1%
——8——CVE-2024-12014—28.1%
——8——CVE-2026-338967.4 HIG28.1%
——8Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.12dCVE-2024-37157—28.1%
——8——CVE-2026-59825—28.1%
——8——CVE-2025-54854—28.1%
——8——CVE-2026-101427.5 HIG28.1%
——8kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame length through the receive_bytes() function to trigger either a multi-gigabyte memory allocation or an uncaught ValueError that leaves the connection in a broken state, causing requests to hang and consumers to stop heartbeating until restart.55dCVE-2026-191728.3 HIG28.0%
——8Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)40dCVE-2016-3676—28.0%
——8——CVE-2006-2790—28.0%
——8——CVE-2026-160746.3 MED28.0%
——8A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plugins of the file astrbot/dashboard/routes/plugin.py of the component Plugin Update Handler. The manipulation of the argument download_url/download_urls/proxy results in server-side request forgery. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.58dCVE-2026-153746.3 MED28.0%
——8A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.65dCVE-2022-22596—28.0%
——8——CVE-2026-5289—28.0%
——8——CVE-2024-32718—28.0%
——8——CVE-2018-20893—28.0%
——8——CVE-2026-28392—28.0%
——8——CVE-2019-3593—28.0%
——8——CVE-2017-18465—28.0%
——8——CVE-2025-27583—28.0%
——8——