Vulnerabilities exploitable today
369,392in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,695
New KEV · 24H0
Exploit Today ≥ 701,636
Distribution · last window
- Critical2,099
- High7,540
- Medium5,594
- Low539
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-770766.5 MED20.9%
——6n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged instead of wrapping it in n8n's standard error type. That error contains the live request's headers, including a decrypted credential secret, which the execution engine persists verbatim. Any authenticated user able to read the resulting execution can retrieve the decrypted credential secret from the stored run data.6dCVE-2025-545187.0 HIG20.9%
——6Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.3dCVE-2025-30022—20.9%
——6——CVE-2026-5124—20.9%
——6——CVE-2026-32072—20.9%
——6——CVE-2023-33757—20.9%
——6——CVE-2020-37092—20.9%
——6——CVE-2024-49647—20.9%
——6——CVE-2024-51697—20.9%
——6——CVE-2020-3520—20.9%
——6——CVE-2026-77358—20.9%
——6cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client's destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.7dCVE-2024-51703—20.9%
——6——CVE-2025-51479—20.9%
——6——CVE-2026-33446—20.9%
——6——CVE-2021-43074—20.9%
——6——CVE-2011-5060—20.9%
——6——CVE-2025-60038—20.9%
——6——CVE-2017-18224—20.9%
——6——CVE-2021-29612—20.9%
——6——CVE-2018-25230—20.9%
——6——CVE-2025-20258—20.9%
——6——CVE-2021-21574—20.9%
——6——CVE-2026-186966.5 MED20.9%
——6An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.10dCVE-2026-44599—20.9%
——6——CVE-2025-9698—20.9%
——6——CVE-2022-1746—20.9%
——6——CVE-2025-59133—20.9%
——6——CVE-2025-1405—20.9%
——6——CVE-2004-0481—20.9%
——6——CVE-2005-2864—20.9%
——6——CVE-2023-22316—20.9%
——6——CVE-2026-632594.3 MED20.8%
——6Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.35dCVE-2012-0450—20.9%
——6——CVE-2026-740207.5 HIG20.9%
——6Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.18dCVE-2024-26900—20.9%
——6——CVE-2026-664256.5 MED20.9%
——6Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.26dCVE-2022-45448—20.9%
——6——CVE-2025-27726—20.9%
——6——CVE-2020-37256—20.9%
——6——CVE-2023-32417—20.9%
——6——