Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-78072—25.2%
——8Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.118dCVE-2021-43575—25.2%
——8——CVE-2026-22005—25.2%
——8——CVE-2025-13847—25.2%
——8——CVE-2026-43570—25.2%
——8——CVE-2023-41781—25.2%
——8——CVE-2012-3737—25.2%
——8——CVE-2025-62946—25.1%
——8——CVE-2020-5978—25.1%
——8——CVE-2022-35894—25.1%
——8——CVE-2022-35896—25.1%
——8——CVE-2024-1804—25.1%
——8——CVE-2024-32566—25.1%
——8——CVE-2025-69771—25.1%
——8——CVE-2020-0510—25.1%
——8——CVE-2023-42559—25.1%
——8——CVE-2026-59729—25.1%
——8Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "' >/= or whitespace are dropped. A second attribute-rendering path, renderHTMLElement() in packages/astro/src/runtime/server/render/dom.ts, has its own inline attribute loop that does not go through addAttribute() and was not updated. It interpolates the attribute name unescaped and only escapes the value, so untrusted prop keys spread onto a native-HTMLElement-subclass component can still break out of the attribute context. This issue has been fixed in version 7.0.6.49dCVE-2025-1084—25.1%
——8——CVE-2016-8981—25.1%
——8——CVE-2025-11445—25.1%
——8——CVE-2026-30974—25.1%
——8——CVE-2024-9067—25.1%
——8——CVE-2017-2328—25.1%
——8——CVE-2021-40367—25.1%
——8——CVE-2024-6836—25.1%
——8——CVE-2024-9685—25.1%
——8——CVE-2024-46362—25.1%
——8——CVE-2024-50337—25.1%
——8——CVE-2025-13234—25.1%
——8——CVE-2020-12329—25.1%
——8——CVE-2024-47441—25.1%
——8——CVE-2025-22633—25.1%
——8——CVE-2026-749418.8 HIG25.1%
——8Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.25dCVE-2026-369577.5 HIG25.1%
——8Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.72dCVE-2024-11401—25.1%
——8——CVE-2025-48735—25.1%
——8——CVE-2020-5987—25.1%
——8——CVE-2024-23902—25.1%
——8——CVE-2025-13236—25.1%
——8——CVE-2022-36448—25.1%
——8——