Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,280
- High8,398
- Medium6,460
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-18847—23.6%
——7——CVE-2026-108024.3 MED23.6%
——7A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.51dCVE-2024-53241—23.6%
——7——CVE-2025-9823—23.6%
——7——CVE-2026-145056.6 MED23.6%
——7Tanium addressed a path traversal vulnerability in Tanium Data Service.2dCVE-2025-49723—23.6%
——7——CVE-2025-41711—23.6%
——7——CVE-2026-613086.8 MED23.6%
——7Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).21dCVE-2026-288614.3 MED23.6%
——7A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. A malicious website may be able to access script message handlers intended for other origins.59dCVE-2026-561434.9 MED23.6%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.7dCVE-2026-35222—23.6%
——7——CVE-2022-42810—23.6%
——7——CVE-2024-0568—23.6%
——7——CVE-2025-13259—23.6%
——7——CVE-2025-69202—23.6%
——7——CVE-2026-54826—23.6%
——7——CVE-2024-29960—23.6%
——7——CVE-2024-5754—23.6%
——7——CVE-2025-15610—23.6%
——7——CVE-2025-11891—23.6%
——7——CVE-2023-24463—23.6%
——7——CVE-2026-2976—23.6%
——7——CVE-2024-38314—23.6%
——7——CVE-2026-7387—23.6%
——7——CVE-2023-41949—23.6%
——7——CVE-2025-10571—23.6%
——7——CVE-2024-43288—23.6%
——7——CVE-2020-29480—23.6%
——7——CVE-2023-46093—23.6%
——7——CVE-2024-1683—23.6%
——7——CVE-2026-825894.3 MED23.6%
——7A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message Handler. Performing a manipulation of the argument N1N2MessageTransferReqData.n2InfoContainer.smInfo.n2InfoContent.ngapIeType results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.8.0 is recommended to address this issue. The patch is named abf8a836564b966b5141110fc25ed413c4f17522. It is advisable to upgrade the affected component.11dCVE-2025-4665—23.6%
——7——CVE-2026-42551—23.6%
——7——CVE-2023-46091—23.6%
——7——CVE-2013-0411—23.6%
——7——CVE-2011-2398—23.6%
——7——CVE-2026-124368.4 HIG23.6%
——7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.39dCVE-2026-1509—23.6%
——7——CVE-2022-42540—23.5%
——7——CVE-2023-6514—23.6%
——7——