Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,639
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-6309—33.8%
——10——CVE-2023-44195—33.8%
——10——CVE-2025-5858—33.8%
——10——CVE-2026-23542—33.8%
——10——CVE-2023-47069—33.8%
——10——CVE-2024-22288—33.8%
——10——CVE-2025-6308—33.8%
——10——CVE-2024-10879—33.8%
——10——CVE-2026-1229—33.8%
——10——CVE-2016-0447—33.8%
——10——CVE-2025-15435—33.8%
——10——CVE-2023-47227—33.8%
——10——CVE-2026-55792—33.8%
——10Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email templates. When those emails are sent, the server reads the target file and returns its contents as a base64-encoded data URL embedded in the email body. The .env file, which typically contains the database password, CRAFT_SECURITY_KEY, and third-party API keys, passes all of Craft’s existing dataUrl() protection checks and is fully exfiltrated. Obtaining CRAFT_SECURITY_KEY enables an attacker to forge session tokens and escalate to full admin account takeover. This issue has been fixed in versions 4.18.0 and 5.10.0.82dCVE-2025-11136—33.8%
——10——CVE-2025-5658—33.8%
——10——CVE-2024-6094—33.8%
——10——CVE-2026-367837.5 HIG33.8%
——10Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the domain parameter of the fromNetToolGet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.62dCVE-2009-0655—33.8%
——10——CVE-2024-29928—33.8%
——10——CVE-2024-25874—33.8%
——10——CVE-2025-5653—33.8%
——10——CVE-2025-5657—33.8%
——10——CVE-2023-21771—33.8%
——10——CVE-2024-13846—33.8%
——10——CVE-2026-367797.5 HIG33.8%
——10Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack overflows in the fromVirtualSer function via the puVar2, puVar1, __s2, __s1_00, and puVar3 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.62dCVE-2018-6253—33.8%
——10——CVE-2019-256808.2 HIG33.8%
——10Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.60dCVE-2023-26441—33.8%
——10——CVE-2024-34696—33.8%
——10——CVE-2026-6432—33.8%
——10——CVE-2026-922307.5 HIG33.8%
——10Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.4dCVE-2024-8283—33.8%
——10——CVE-2023-47181—33.8%
——10——CVE-2025-5654—33.8%
——10——CVE-2026-367997.5 HIG33.8%
——10Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.62dCVE-2016-11029—33.8%
——10——CVE-2023-27150—33.8%
——10——CVE-2016-0417—33.8%
——10——CVE-2026-33992—33.8%
——10——CVE-2024-12933—33.8%
——10——