Vulnerabilities exploitable today
378,068in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,716
New KEV · 24H0
Exploit Today ≥ 701,651
Distribution · last window
- Critical2,293
- High8,417
- Medium6,703
- Low757
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-13250—31.8%
——10——CVE-2026-719339.1 CRI31.8%
——10Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.28dCVE-2025-35061—31.8%
——10——CVE-2023-5564—31.8%
——10——CVE-2018-10239—31.8%
——10——CVE-2018-20882—31.8%
——10——CVE-2021-0179—31.8%
——10——CVE-2014-0201—31.8%
——10——CVE-2025-41033—31.8%
——10——CVE-2024-34458—31.8%
——10——CVE-2023-42541—31.8%
——10——CVE-2005-2032—31.8%
——10——CVE-2023-52239—31.8%
——10——CVE-2005-3311—31.8%
——10——CVE-2008-1952—31.8%
——10——CVE-2023-52552—31.7%
——10——CVE-2025-30265—31.7%
——10——CVE-2000-0184—31.7%
——10——CVE-2005-3700—31.7%
——10——CVE-2021-45464—31.7%
——10——CVE-2026-44335—31.7%
——10——CVE-2025-27014—31.7%
——10——CVE-2023-52366—31.7%
——10——CVE-2024-45254—31.7%
——10——CVE-2005-2596—31.7%
——10——CVE-2021-42104—31.7%
——10——CVE-2026-149748.1 HIG31.7%
——10IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.47dCVE-2023-37501—31.7%
——10——CVE-2020-11446—31.7%
——10——CVE-2026-82756—31.7%
——10Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header.
BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a " closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.
This issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.13dCVE-2024-5682—31.7%
——10——CVE-2025-26544—31.7%
——10——CVE-2023-52115—31.7%
——10——CVE-2025-34281—31.7%
——10——CVE-2017-9984—31.7%
——10——CVE-2025-28858—31.7%
——10——CVE-2005-3148—31.7%
——10——CVE-2026-318377.5 HIG31.7%
——10Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable or the fetch fails, exposing hardcoded defaults regardless of use of the RequestAuthentication resource. This vulnerability is fixed in 1.29.1, 1.28.5, and 1.27.8.63dCVE-2023-543944.3 MED31.7%
——10PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication.12dCVE-2023-30308—31.7%
——10——