Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-14394—32.3%
——10——CVE-2020-14150—32.3%
——10——CVE-2024-7232—32.3%
——10——CVE-2018-12150—32.3%
——10——CVE-2024-24257—32.3%
——10——CVE-2025-27388—32.3%
——10——CVE-2026-203207.5 HIG32.3%
——10A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.
This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.32dCVE-2026-45617—32.3%
——10——CVE-2026-34386.1 MED32.3%
——10A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.3dCVE-2023-30480—32.3%
——10——CVE-2025-48041—32.3%
——10Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.59dCVE-2023-5190—32.3%
——10——CVE-2025-32973—32.3%
——10——CVE-2024-23388—32.3%
——10——CVE-2025-31694—32.3%
——10——CVE-2021-34971—32.3%
——10——CVE-2024-33791—32.3%
——10——CVE-2025-30844—32.3%
——10——CVE-2023-4658—32.3%
——10——CVE-2025-40715—32.3%
——10——CVE-2024-40407—32.3%
——10——CVE-2026-454663.3 LOW32.3%
——10Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.61dCVE-2025-40716—32.3%
——10——CVE-2025-26855—32.3%
——10——CVE-2026-137556.4 MED32.3%
——10The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful execution of the injected script is limited to victims who have the referenced ticket ID present in their cart cookie, meaning the payload only fires for users who have previously added that ticket to their cart.67dCVE-2024-8486—32.3%
——10——CVE-2025-28993—32.3%
——10——CVE-2022-4631—32.3%
——10——CVE-2021-4272—32.3%
——10——CVE-2026-797734.9 MED32.3%
——10Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.24dCVE-2025-11189—32.3%
——10——CVE-2026-1721—32.3%
——10——CVE-2024-8646—32.3%
——10——CVE-2024-27334—32.3%
——10——CVE-2026-33334—32.3%
——10——CVE-2024-5371—32.3%
——10——CVE-2026-81906—32.3%
——10Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback response, with the login recorded and login events dispatched. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 6.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.10dCVE-2025-48038—32.3%
——10Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.59dCVE-2024-11509—32.3%
——10——CVE-2026-73213—32.3%
——10Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.12d