Vulnerabilities exploitable today
367,284in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,687
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,295
- High9,357
- Medium5,357
- Low528
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-7586—17.8%
——5——CVE-2024-4208—17.8%
——5——CVE-2026-547125.3 MED17.8%
——5OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive memory allocation while the JVM reads the payload, potentially leading to denial of service. The issue affects only deployments where RMI instrumentation is enabled and an RMI endpoint is network-reachable. This issue has been fixed in version 2.27.0.57dCVE-2026-34388—17.8%
——5——CVE-2022-0987—17.8%
——5——CVE-2024-23960—17.8%
——5——CVE-2022-49381—17.8%
——5——CVE-2022-49276—17.8%
——5——CVE-2026-769987.3 HIG17.8%
——5A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.8dCVE-2026-150577.5 HIG17.8%
——5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.27dCVE-2026-463747.5 HIG17.8%
——5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion. This issue has been patched in version 4.2.0.40dCVE-2025-15087—17.8%
——5——CVE-2024-5061—17.8%
——5——CVE-2022-49224—17.8%
——5——CVE-2024-23363—17.8%
——5——CVE-2025-25609—17.8%
——5——CVE-2026-3073—17.8%
——5——CVE-2026-3041—17.8%
——5——CVE-2026-149817.5 HIG17.8%
——5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.27dCVE-2025-63602—17.8%
——5——CVE-2022-49243—17.8%
——5——CVE-2024-5025—17.8%
——5——CVE-2024-0627—17.8%
——5——CVE-2026-29079—17.8%
——5——CVE-2026-42920—17.8%
——5——CVE-2024-5173—17.8%
——5——CVE-2026-725558.1 HIG17.8%
——5A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account.21dCVE-2025-11221—17.8%
——5——CVE-2026-781987.3 HIG17.8%
——5A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.5dCVE-2024-531647.8 HIG17.8%
——5In the Linux kernel, the following vulnerability has been resolved:
net: sched: fix ordering of qlen adjustment
Changes to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen
_before_ a call to said function because otherwise it may fail to notify
parent qdiscs when the child is about to become empty.28dCVE-2024-21459—17.8%
——5——CVE-2026-120687.4 HIG17.8%
——5Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection.
This issue affects Avira Password Manager when used with Mozilla Firefox on Windows, macOS, and Linux.40dCVE-2025-48282—17.8%
——5——CVE-2026-22576—17.8%
——5——CVE-2024-250397.5 HIG17.8%
——5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.20dCVE-2026-40423—17.8%
——5——CVE-2026-45061—17.8%
——5——CVE-2022-49302—17.8%
——5——CVE-2024-4703—17.8%
——5——CVE-2026-472197.5 HIG17.8%
——5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find() indexes this.trees[method]. Since this.trees is a normal object, HTTP/2 method values like constructor, toString, or __proto__ can resolve inherited object properties instead of returning undefined. The code then treats that value like a router node and crashes when it reaches currentNode.prefix.length. This issue has been fixed in version 9.0.7.33d