Vulnerabilities exploitable today
378,631in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H4
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,396
- High8,640
- Medium6,936
- Low787
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-42125—33.6%
——10——CVE-2019-5679—33.6%
——10——CVE-2007-4526—33.6%
——10——CVE-2015-7869—33.6%
——10——CVE-2021-27704—33.6%
——10——CVE-2026-73648—33.6%
——10rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.4dCVE-2026-408985.3 MED33.6%
——10quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.62dCVE-2002-0971—33.6%
——10——CVE-2006-0576—33.6%
——10——CVE-2024-51737—33.6%
——10——CVE-2012-6333—33.6%
——10——CVE-2023-42126—33.6%
——10——CVE-2019-8529—33.6%
——10——CVE-2026-342278.8 HIG33.6%
——10Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.60dCVE-2024-4363—33.6%
——10——CVE-2023-23672—33.6%
——10——CVE-2010-4656—33.6%
——10——CVE-2024-31525—33.6%
——10——CVE-2004-0966—33.6%
——10——CVE-2023-5211—33.6%
——10——CVE-2003-0607—33.6%
——10——CVE-2006-1451—33.6%
——10——CVE-2014-0972—33.6%
——10——CVE-2009-1295—33.6%
——10——CVE-2017-11130—33.6%
——10——CVE-2013-4361—33.6%
——10——CVE-2010-5331—33.6%
——10——CVE-2010-3846—33.6%
——10——CVE-2019-2955—33.6%
——10——CVE-2019-0070—33.6%
——10——CVE-2026-56701—33.6%
——10——CVE-2014-9715—33.6%
——10——CVE-2025-8436—33.6%
——10——CVE-2024-22473—33.6%
——10——CVE-2018-15371—33.6%
——10——CVE-2026-733508.2 HIG33.6%
——10Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.33dCVE-2025-58716—33.6%
——10——CVE-2024-0007—33.6%
——10——CVE-2025-7518—33.6%
——10——CVE-2026-117217.5 HIG33.6%
——10It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default).
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.62d