Vulnerabilities exploitable today
370,813in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,637
Distribution · last window
- Critical2,187
- High8,406
- Medium6,046
- Low572
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-15002—21.9%
——7——CVE-2025-463977.8 HIG21.9%
——7A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.71dCVE-2025-3478—21.9%
——7——CVE-2026-28917—21.9%
——7——CVE-2023-22395—21.9%
——7——CVE-2025-57956—21.9%
——7——CVE-2025-15445—21.9%
——7——CVE-2020-7566—21.9%
——7——CVE-2026-726286.5 MED21.9%
——7Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory available to Kibana. The Kibana process is terminated by the host and remains unavailable to all users until the service is restarted.6dCVE-2021-27759—21.9%
——7——CVE-2024-53026—21.9%
——7——CVE-2019-9423—21.9%
——7——CVE-2023-44315—21.9%
——7——CVE-2021-22042—21.9%
——7——CVE-2025-13758—21.9%
——7——CVE-2025-57908—21.9%
——7——CVE-2023-7300—21.9%
——7——CVE-2026-785866.5 MED21.9%
——7Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded amount of memory, rendering it unavailable to all users.5dCVE-2026-477065.3 MED21.9%
——7Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue.48dCVE-2024-13482—21.9%
——7——CVE-2026-99768.8 HIG21.9%
——7Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)50dCVE-2025-8942—21.9%
——7——CVE-2024-44032—21.9%
——7——CVE-2025-27298—21.9%
——7——CVE-2021-23827—21.9%
——7——CVE-2025-31544—21.9%
——7——CVE-2021-32000—21.9%
——7——CVE-2021-22573—21.9%
——7——CVE-2025-53464—21.9%
——7——CVE-2025-53467—21.9%
——7——CVE-2026-27044—21.9%
——7——CVE-2026-193594.7 MED21.9%
——7A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."27dCVE-2022-39071—21.9%
——7——CVE-2025-53458—21.9%
——7——CVE-2026-692787.8 HIG21.9%
——7Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.6dCVE-2026-39530—21.9%
——7——CVE-2026-34375—21.9%
——7——CVE-2025-24398—21.9%
——7——CVE-2022-29527—21.9%
——7——CVE-2017-6346—21.9%
——7——