Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,226
- High7,950
- Medium6,438
- Low714
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-43018—27.0%
——8——CVE-2026-57267.8 HIG27.0%
——8ASDA-Soft Stack-based Buffer Overflow Vulnerability54dCVE-2026-658188.5 HIG27.0%
——8Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.8dCVE-2022-45842—27.0%
——8——CVE-2014-3952—27.0%
——8——CVE-2022-510097.5 HIG27.0%
——8PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.6dCVE-2016-3465—27.0%
——8——CVE-2022-27644—27.0%
——8——CVE-2025-70030—27.0%
——8——CVE-2022-36139—27.0%
——8——CVE-2024-3625—27.0%
——8——CVE-2011-0726—27.0%
——8——CVE-2026-50196—27.0%
——8——CVE-2026-550006.4 MED27.0%
——8Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.54dCVE-2026-3953—27.0%
——8——CVE-2026-558277.5 HIG27.0%
——8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-default /cache:codec:rfx option pass desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data while allocating bitmap->data only for the smaller DstWidth and DstHeight in gdi_Bitmap_Decompress, allowing a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content. This issue is fixed in version 3.27.1.63dCVE-2002-1313—27.0%
——8——CVE-2026-860757.5 HIG27.0%
——8n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remote caller could repeatedly persist oversized values in oauth_clients and exhaust database storage. The affected validation is in packages/cli/src/modules/oauth-server/oauth-server.service.ts, including MAX_CLIENT_NAME_LENGTH and MAX_GRANT_TYPES. This issue is fixed in versions 2.37.7 and 2.38.2.5dCVE-2023-47047—27.0%
——8——CVE-2018-25193—27.0%
——8——CVE-2026-465457.5 HIG27.0%
——8Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-service vulnerability in MerkleRadixTrie::put_chunk allows any state-sync peer to crash any node performing state synchronization (freshly joining nodes and recovering nodes). This issue has been patched in version 1.5.0.55dCVE-2006-2288—27.0%
——8——CVE-2011-3570—27.0%
——8——CVE-2019-3901—27.0%
——8——CVE-2005-4762—27.0%
——8——CVE-2023-44346—27.0%
——8——CVE-2019-19349—27.0%
——8——CVE-2018-1000404—27.0%
——8——CVE-2026-31992—27.0%
——8——CVE-2014-2346—27.0%
——8——CVE-2025-31541—27.0%
——8——CVE-2024-20791—27.0%
——8——CVE-2023-44343—27.0%
——8——CVE-2024-29921—27.0%
——8——CVE-2017-2713—27.0%
——8——CVE-2009-1299—27.0%
——8——CVE-2024-32833—27.0%
——8——CVE-2020-8693—27.0%
——8——CVE-2024-31089—27.0%
——8——CVE-2009-0578—27.0%
——8——