Vulnerabilities exploitable today
378,377in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H0
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,329
- High8,527
- Medium6,840
- Low772
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-47976—32.8%
——10——CVE-2017-5683—32.8%
——10——CVE-2026-100356.6 MED32.8%
——10The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore() settings-restore handler). The function reads the raw contents of an administrator-uploaded file and passes them directly to unserialize() without any validation. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin itself; however, if a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.33dCVE-2025-69301—32.8%
——10——CVE-2025-68133—32.8%
——10——CVE-2024-52893—32.8%
——10——CVE-2016-8228—32.8%
——10——CVE-2024-36625—32.8%
——10——CVE-2015-1117—32.8%
——10——CVE-2007-4693—32.8%
——10——CVE-2025-14577—32.8%
——10——CVE-2004-2660—32.8%
——10——CVE-2025-28235—32.8%
——10——CVE-2024-39780—32.8%
——10——CVE-2000-0956—32.8%
——10——CVE-2024-46956—32.8%
——10——CVE-2024-10412—32.8%
——10——CVE-2025-10977—32.8%
——10——CVE-2026-31676—32.8%
——10——CVE-2023-3547—32.8%
——10——CVE-2023-35057—32.8%
——10——CVE-2020-5727—32.8%
——10——CVE-2026-471836.5 MED32.8%
——10Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup methods stored an unbounded _seen_logs dictionary keyed by attacker-influenced IncomingDecodeError messages, retaining sys.exc_info() tracebacks whose frame locals kept raw packet self.data buffers and allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to drive memory growth until mDNS-dependent features degrade or the process is OOM-killed. This issue is fixed in version 0.149.6.36dCVE-2025-63532—32.8%
——10——CVE-2000-0701—32.8%
——10——CVE-2009-0787—32.8%
——10——CVE-2023-47231—32.7%
——10——CVE-2024-11863—32.7%
——10——CVE-2018-8991—32.7%
——10——CVE-2018-9006—32.7%
——10——CVE-2018-6631—32.7%
——10——CVE-2025-47968—32.7%
——10——CVE-2018-6787—32.7%
——10——CVE-2023-32516—32.7%
——10——CVE-2018-6207—32.7%
——10——CVE-2018-6775—32.7%
——10——CVE-2018-9005—32.7%
——10——CVE-2018-6776—32.7%
——10——CVE-2020-10570—32.7%
——10——CVE-2018-5087—32.7%
——10——