Vulnerabilities exploitable today
358,695in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,671
- High11,572
- Medium7,375
- Low684
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-24411—90.1%
——27——CVE-2025-61812—90.1%
——27——CVE-2020-28035—90.1%
——27——CVE-2018-8710—90.1%
——27——CVE-2021-23937—90.1%
——27——CVE-2018-20150—90.1%
——27——CVE-2020-5341—90.1%
——27——CVE-2025-45859—90.1%
——27——CVE-2007-1885—90.1%
——27——CVE-2012-5645—90.1%
——27——CVE-2008-3075—90.1%
——27——CVE-2011-3850—90.1%
——27——CVE-2002-1708—90.1%
——27——CVE-2006-4531—90.1%
——27——CVE-2019-8199—90.1%
——27——CVE-2009-2299—90.1%
——27——CVE-2024-300917.8 HIG90.1%
——27Win32k Elevation of Privilege Vulnerability23dCVE-2022-25008—90.1%
——27——CVE-2020-6110—90.1%
——27——CVE-2005-4654—90.1%
——27——CVE-2009-3868—90.1%
——27——CVE-2002-0608—90.1%
——27——CVE-2017-6413—90.1%
——27——CVE-2011-4256—90.1%
——27——CVE-2018-12018—90.1%
——27——CVE-2014-5181—90.1%
——27——CVE-2013-7439—90.1%
——27——CVE-2014-0862—90.1%
——27——CVE-2024-43045—90.1%
——27——CVE-2026-420558.1 HIG90.1%
——27NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.1dCVE-2013-3480—90.1%
——27——CVE-2008-0939—90.1%
——27——CVE-2013-4539—90.1%
——27——CVE-2024-30284—90.1%
——27——CVE-2015-2709—90.1%
——27——CVE-2012-2316—90.1%
——27——CVE-2018-18751—90.1%
——27——CVE-2023-36400—90.1%
——27——CVE-2009-3466—90.1%
——27——CVE-2019-19943—90.1%
——27——