Vulnerabilities exploitable today
365,633in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,682
New KEV · 24H0
Exploit Today ≥ 701,626
Distribution · last window
- Critical2,365
- High10,105
- Medium4,998
- Low469
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-49386—14.9%
——4——CVE-2024-31955—14.9%
——4——CVE-2025-6259—14.9%
——4——CVE-2026-631406.5 MED14.9%
——4Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats assertion failures as fatal errors, this terminates the affected node process. A low-privileged authenticated user with read access to at least one index can exploit this condition with a single request to cause a node to terminate, disrupting search availability. In a single-node deployment this fully stops Elasticsearch; in a multi-node cluster it reduces cluster capacity for each affected node.20dCVE-2026-73829—14.9%
——4Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses.
The type="hash" credential path in MPP.Methods.Tempo.verify/2 guards against replay with a non-atomic check-then-mark sequence: check_hash_unused/2 reads the dedup store, an eth_getTransactionReceipt round trip verifies the payment on chain, and only then does mark_hash_used/2 write the mark. Concurrent requests carrying the same settled payment hash all pass the read before any of them writes, so each is issued a receipt. The store's atomic check_and_mark/2 primitive is available and used by the type="transaction" path, but the hash path calls plain get and put even when the configured store implements it. Exploitation requires a dedup store to be configured; the default nil store is stateless and documented as offering no replay protection at all.
This issue affects mpp: from 0.2.0 before 0.6.1.7dCVE-2026-740075.3 MED14.9%
——4Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.7dCVE-2026-628767.8 HIG14.9%
——4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11dCVE-2025-5336—14.9%
——4——CVE-2020-37018—14.9%
——4——CVE-2025-43410—14.9%
——4——CVE-2026-627797.8 HIG14.9%
——4Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.14dCVE-2026-1395—14.9%
——4——CVE-2024-51587—14.9%
——4——CVE-2024-51576—14.9%
——4——CVE-2025-25269—14.9%
——4——CVE-2023-26242—14.9%
——4——CVE-2025-33124—14.9%
——4——CVE-2026-627557.8 HIG14.9%
——4Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.11dCVE-2026-628807.8 HIG14.9%
——4Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.11dCVE-2024-50472—14.9%
——4——CVE-2018-13811—14.9%
——4——CVE-2021-29571—14.9%
——4——CVE-2025-59398—14.9%
——4——CVE-2026-25399—14.9%
——4——CVE-2024-51583—14.9%
——4——CVE-2025-57935—14.9%
——4——CVE-2024-410227.0 HIG14.9%
——4In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
The "instance" variable needs to be signed for the error handling to work.23dCVE-2025-0272—14.9%
——4——CVE-2024-51590—14.9%
——4——CVE-2022-46706—14.9%
——4——CVE-2026-417276.5 MED14.9%
——4Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.36dCVE-2026-6936—14.9%
——4——CVE-2026-763367.1 HIG14.9%
——4In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service disruption. The vulnerability does not affect Splunk Enterprise versions below 10.2. The vulnerability is possible because the SPL2 module management REST API does not sufficiently authorize and validate module deletion requests. For more information see Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) and Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) in the Splunk documentation.6dCVE-2024-51580—14.9%
——4——CVE-2026-28833—14.9%
——4——CVE-2024-9875—14.9%
——4——CVE-2026-657867.8 HIG14.9%
——4Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.11dCVE-2026-30791—14.9%
——4——CVE-2026-627337.8 HIG14.9%
——4Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.11dCVE-2023-52898—14.9%
——4——