Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2016-0447—33.8%
——10——CVE-2023-47227—33.8%
——10——CVE-2025-15435—33.8%
——10——CVE-2025-11136—33.8%
——10——CVE-2025-6308—33.8%
——10——CVE-2023-47069—33.8%
——10——CVE-2023-26441—33.8%
——10——CVE-2026-1229—33.8%
——10——CVE-2019-256808.2 HIG33.8%
——10Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.60dCVE-2015-0296—33.8%
——10——CVE-2024-44851—33.8%
——10——CVE-2018-6253—33.8%
——10——CVE-2012-2319—33.8%
——10——CVE-2026-6432—33.8%
——10——CVE-2026-922307.5 HIG33.8%
——10Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.4dCVE-2024-8283—33.8%
——10——CVE-2024-34696—33.8%
——10——CVE-2025-65036—33.8%
——10——CVE-2025-5859—33.8%
——10——CVE-2023-47226—33.8%
——10——CVE-2024-12932—33.8%
——10——CVE-2025-5838—33.8%
——10——CVE-2025-11243—33.8%
——10——CVE-2021-0240—33.8%
——10——CVE-2016-0445—33.8%
——10——CVE-2026-54226—33.8%
——10——CVE-2026-367937.5 HIG33.8%
——10Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the formwrlSSIDset function via the mit_ssid and mis_ssid_index parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.62dCVE-2026-58486—33.8%
——10HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (js-yaml v3) via @hedgedoc/meta-marked, which resolved YAML anchor aliases. A compact malicious payload could therefore expand into a huge object structure, consuming excessive CPU. This expansion ran on every request to the publish view (/s/<shortid>) and, when placed under the opengraph key, the editor view (/<noteId>). A ten-level alias bomb could block the single Node.js event loop for roughly 235 seconds per request, causing concurrent requests to hang or drop and rendering the instance unavailable (DoS). Because the note was stored in the database, the impact survived process restarts until the note was removed. toobusy-js did not reliably mitigate the worst cases, as the event loop was saturated before the middleware could respond. This issue was fixed in version 1.11.0.70dCVE-2025-55586—33.8%
——10——CVE-2025-55588—33.8%
——10——CVE-2021-47979—33.8%
——10——CVE-2026-122908.1 HIG33.8%
——10Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.70dCVE-2025-59413—33.8%
——10——CVE-2016-11029—33.8%
——10——CVE-2026-367997.5 HIG33.8%
——10Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.62dCVE-2026-471605.8 MED33.8%
——10Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations, allowing SSRF through the icon-fetching HTTP client for blind internal network or port discovery. This issue is fixed in version 1.36.0.69dCVE-2023-27150—33.8%
——10——CVE-2016-0417—33.8%
——10——CVE-2024-13213—33.8%
——10——CVE-2026-732569.1 CRI33.8%
——10Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol string, so is_http_1_0 is never set. Mongoose consequently processes chunked encoding that an HTTP/1.0 proxy can ignore, enabling request smuggling and unauthorized access or state changes. This issue is fixed in version 7.22.13d