Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-28971—32.3%
——10——CVE-2024-7233—32.3%
——10——CVE-2025-22138—32.3%
——10——CVE-2023-49610—32.3%
——10——CVE-2025-39597—32.3%
——10——CVE-2024-37154—32.3%
——10——CVE-2025-40714—32.3%
——10——CVE-2025-26854—32.3%
——10——CVE-2026-119734.9 MED32.3%
——10The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.36dCVE-2024-11509—32.3%
——10——CVE-2024-22813—32.3%
——10——CVE-2025-48038—32.3%
——10Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.59dCVE-2016-8007—32.3%
——10——CVE-2024-20815—32.3%
——10——CVE-2020-27366—32.3%
——10——CVE-2023-5835—32.3%
——10——CVE-2022-24669—32.3%
——10——CVE-2023-44308—32.3%
——10——CVE-2024-32684—32.3%
——10——CVE-2023-4892—32.3%
——10——CVE-2024-29319—32.3%
——10——CVE-2005-2237—32.3%
——10——CVE-2026-53533—32.3%
——10aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who influences an envelope sender or recipient to inject commands such as MAIL FROM, RCPT TO, RSET, DATA, or AUTH. SMTP.sendmail() and SMTP.send() without a Message object pass addresses through the affected methods, while SMTP.send_message() is not affected. Successful injection can desynchronize the command-response pipeline, hang the SMTP instance, or send an arbitrary message without requiring attacker control of the SMTP server. This issue is fixed in version 5.1.1.3dCVE-2022-29431—32.3%
——10——CVE-2025-59368—32.3%
——10——CVE-2024-25155—32.3%
——10——CVE-2005-2597—32.3%
——10——CVE-2024-0030—32.3%
——10——CVE-2025-59010—32.3%
——10——CVE-2018-3667—32.3%
——10——CVE-2024-39318—32.3%
——10——CVE-2026-4712—32.3%
——10——CVE-2025-59944—32.3%
——10——CVE-2026-24525—32.3%
——10——CVE-2024-2519—32.3%
——10——CVE-2024-42006—32.3%
——10——CVE-2006-2932—32.3%
——10——CVE-2017-4938—32.3%
——10——CVE-2024-2291—32.3%
——10——CVE-2017-5670—32.3%
——10——