Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,347
- High8,411
- Medium6,454
- Low715
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-0314—26.2%
——8——CVE-2026-54715—26.2%
——8GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.7dCVE-2026-490896.5 MED26.2%
——8Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an unbounded amount of time evaluating it. An authenticated user with read-only privileges was able to send a single request that left Kibana unable to serve any user until the process was restarted.13dCVE-2017-6254—26.2%
——8——CVE-2025-15331—26.2%
——8——CVE-2026-172487.1 HIG26.2%
——8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.33dCVE-2017-0348—26.2%
——8——CVE-2017-0323—26.2%
——8——CVE-2017-0344—26.2%
——8——CVE-2023-25873—26.2%
——8——CVE-2026-54185—26.2%
——8——CVE-2026-40766—26.2%
——8——CVE-2025-2606—26.2%
——8——CVE-2022-42376—26.2%
——8——CVE-2023-25863—26.2%
——8——CVE-2024-39838—26.2%
——8——CVE-2017-0347—26.2%
——8——CVE-2026-42400—26.2%
——8——CVE-2026-281688.5 HIG26.2%
——8Subscriber SQL Injection in CubeWP <= 1.1.30 versions.32dCVE-2017-6252—26.2%
——8——CVE-2026-389679.8 CRI26.2%
——8CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.55dCVE-2026-345038.1 HIG26.2%
——8OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.53dCVE-2006-2464—26.2%
——8——CVE-2025-7677—26.2%
——8——CVE-2023-26348—26.2%
——8——CVE-2017-6255—26.2%
——8——CVE-2022-42387—26.2%
——8——CVE-2006-5737—26.2%
——8——CVE-2026-573776.5 MED26.2%
——8Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.64dCVE-2024-35228—26.2%
——8——CVE-2026-726796.5 MED26.2%
——8Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.14dCVE-2023-26343—26.2%
——8——CVE-2026-726786.5 MED26.2%
——8Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively large allocation. The resulting memory exhaustion raises a fatal error that terminates the Elasticsearch node process, causing a denial of service for the affected node and degrading cluster health. The defect is not volumetric, so a single request is sufficient regardless of the heap size configured on the target node.14dCVE-2026-48967—26.2%
——8——CVE-2022-42412—26.2%
——8——CVE-2026-32524—26.2%
——8——CVE-2026-48874—26.2%
——8——CVE-2026-48964—26.2%
——8——CVE-2023-26350—26.2%
——8——CVE-2023-26351—26.2%
——8——