Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-6236—25.7%
——8——CVE-2024-32124—25.7%
——8——CVE-2026-905673.5 LOW25.7%
——8A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.20hCVE-2023-33204—25.7%
——8——CVE-2025-9734—25.7%
——8——CVE-2026-1048—25.7%
——8——CVE-2025-9238—25.7%
——8——CVE-2026-445455.3 MED25.7%
——8daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.55dCVE-2025-27980—25.7%
——8——CVE-2026-73276—25.7%
——8Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.
This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.8dCVE-2021-47700—25.7%
——8——CVE-2010-2380—25.7%
——8——CVE-2025-59837—25.7%
——8——CVE-2026-786845.3 MED25.7%
——8vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.20hCVE-2026-1271—25.7%
——8——CVE-2025-3613—25.7%
——8——CVE-2026-842688.8 HIG25.7%
——8A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.13dCVE-2025-50029—25.7%
——8——CVE-2024-27878—25.7%
——8——CVE-2026-796544.3 MED25.7%
——8A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.18dCVE-2025-56207—25.7%
——8——CVE-2025-7736—25.7%
——8——CVE-2024-2634—25.7%
——8——CVE-2025-11654—25.7%
——8——CVE-2026-4470—25.7%
——8——CVE-2020-4414—25.7%
——8——CVE-2025-10398—25.7%
——8——CVE-2025-3152—25.7%
——8——CVE-2023-25806—25.7%
——8——CVE-2026-32828—25.7%
——8——CVE-2025-7759—25.7%
——8——CVE-2025-10967—25.7%
——8——CVE-2022-34495—25.7%
——8——CVE-2025-26333—25.7%
——8——CVE-2025-15251—25.7%
——8——CVE-2026-46545.3 MED25.7%
——8The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific ticket being requested. This makes it possible for authenticated attackers, with subscriber-level access and above, to access sensitive information from all support tickets in the system by manipulating the ticket_id parameter.52dCVE-2024-8035—25.7%
——8——CVE-2025-24544—25.7%
——8——CVE-2025-20216—25.7%
——8——CVE-2023-31907—25.7%
——8——