Vulnerabilities exploitable today
378,183in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,717
New KEV · 24H1
Exploit Today ≥ 701,649
Distribution · last window
- Critical2,332
- High8,494
- Medium6,769
- Low765
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-36741—32.3%
——10——CVE-2024-20507—32.3%
——10——CVE-2026-25326—32.3%
——10——CVE-2023-1904—32.3%
——10——CVE-2025-0441—32.3%
——10——CVE-2021-1961—32.3%
——10——CVE-2023-23618—32.3%
——10——CVE-2024-50829—32.3%
——10——CVE-2023-35800—32.3%
——10——CVE-2024-28765—32.3%
——10——CVE-2025-11681—32.3%
——10——CVE-2025-29841—32.3%
——10——CVE-2026-636718.1 HIG32.3%
——10MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.3dCVE-2026-713849.6 CRI32.3%
——10is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.25dCVE-2020-36742—32.3%
——10——CVE-2026-36465.3 MED32.3%
——10The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that directly processes GET parameters and updates WordPress options. This makes it possible for unauthenticated attackers to modify the plugin's subscription plan settings, effectively downgrading the store from a paid plan to the Trial Plan, changing the store type, and manipulating subscription expiration dates, potentially disabling premium features such as Dropship and Hazardous Material handling.59dCVE-2025-7137—32.3%
——10——CVE-2024-50825—32.3%
——10——CVE-2024-24558—32.3%
——10——CVE-2007-6305—32.3%
——10——CVE-2022-35205—32.3%
——10——CVE-2026-242557.5 HIG32.3%
——10NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.45dCVE-2024-7317—32.3%
——10——CVE-2024-32803—32.3%
——10——CVE-2024-50828—32.3%
——10——CVE-2024-11942—32.3%
——10——CVE-2020-36744—32.3%
——10——CVE-2024-32827—32.3%
——10——CVE-2026-40197—32.3%
——10——CVE-2023-4893—32.3%
——10——CVE-2025-31487—32.3%
——10——CVE-2023-44077—32.3%
——10——CVE-2024-50826—32.3%
——10——CVE-2024-10126—32.3%
——10——CVE-2024-2608—32.3%
——10——CVE-2024-6540—32.3%
——10——CVE-2026-843757.5 HIG32.3%
——10js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.19dCVE-2024-6012—32.3%
——10——CVE-2025-7904—32.3%
——10——CVE-2025-12576—32.3%
——10——