Vulnerabilities exploitable today
358,987in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,608
Distribution · last window
- Critical2,467
- High11,018
- Medium6,965
- Low652
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-33896—89.7%
——27——CVE-2011-1035—89.6%
——27——CVE-2018-11797—89.7%
——27——CVE-2008-3464—89.7%
——27——CVE-2018-16023—89.7%
——27——CVE-2008-6926—89.7%
——27——CVE-2009-0585—89.7%
——27——CVE-2013-0807—89.7%
——27——CVE-2002-1307—89.7%
——27——CVE-2014-0045—89.7%
——27——CVE-2008-5101—89.7%
——27——CVE-2006-1212—89.7%
——27——CVE-2008-7160—89.7%
——27——CVE-2018-1000850—89.7%
——27——CVE-2016-1482—89.7%
——27——CVE-2006-3789—89.7%
——27——CVE-2018-0431—89.7%
——27——CVE-2026-420558.1 HIG89.7%
——27NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.3dCVE-2012-1162—89.7%
——27——CVE-2008-5658—89.7%
——27——CVE-2010-2801—89.7%
——27——CVE-2008-5231—89.7%
——27——CVE-2018-16061—89.7%
——27——CVE-2020-17107—89.7%
——27——CVE-2017-15284—89.7%
——27——CVE-2018-0430—89.7%
——27——CVE-2009-4016—89.7%
——27——CVE-2006-1672—89.7%
——27——CVE-2024-51503—89.7%
——27——CVE-2010-3761—89.7%
——27——CVE-2015-5693—89.7%
——27——CVE-2017-10954—89.7%
——27——CVE-2022-35761—89.7%
——27——CVE-2019-13161—89.7%
——27——CVE-2018-16024—89.7%
——27——CVE-2021-35936—89.7%
——27——CVE-2020-1564—89.7%
——27——CVE-2021-23412—89.7%
——27——CVE-2019-13392—89.6%
——27——CVE-2019-11929—89.7%
——27——