Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,222
- High7,898
- Medium6,415
- Low710
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-67967—27.8%
——8——CVE-1999-1027—27.8%
——8——CVE-2001-1203—27.8%
——8——CVE-2024-8841—27.8%
——8——CVE-2024-8822—27.8%
——8——CVE-2022-2313—27.8%
——8——CVE-2025-23392—27.8%
——8——CVE-2026-34476—27.8%
——8——CVE-2016-3846—27.8%
——8——CVE-2025-31475—27.8%
——8——CVE-2021-29112—27.8%
——8——CVE-2015-5945—27.8%
——8——CVE-2014-2343—27.8%
——8——CVE-1999-1459—27.8%
——8——CVE-2021-38133—27.8%
——8——CVE-2026-56699—27.8%
——8Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.41dCVE-2022-36483—27.8%
——8——CVE-2024-32981—27.8%
——8——CVE-2022-36465—27.8%
——8——CVE-2023-4995—27.8%
——8——CVE-2014-2580—27.8%
——8——CVE-2010-0424—27.8%
——8——CVE-2014-4408—27.8%
——8——CVE-2012-2133—27.8%
——8——CVE-2026-5473510.0 CRI27.8%
——8Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.29dCVE-2019-25643—27.8%
——8——CVE-2023-5668—27.8%
——8——CVE-2016-3848—27.8%
——8——CVE-2024-32779—27.8%
——8——CVE-2007-4353—27.8%
——8——CVE-2002-0105—27.8%
——8——CVE-2002-0174—27.8%
——8——CVE-1999-1143—27.8%
——8——CVE-2025-68057—27.8%
——8——CVE-2018-0337—27.8%
——8——CVE-2026-160724.9 MED27.8%
——8A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.16dCVE-2026-592897.5 HIG27.8%
——8Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.2.0 - 1.3.914dCVE-1999-1019—27.8%
——8——CVE-2024-12185—27.8%
——8——CVE-2025-24310—27.8%
——8——