Vulnerabilities exploitable today
373,979in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,709
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,324
- High8,430
- Medium6,377
- Low704
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-50337—25.1%
——8——CVE-2022-35894—25.1%
——8——CVE-2025-13234—25.1%
——8——CVE-2024-46362—25.1%
——8——CVE-2024-6836—25.1%
——8——CVE-2022-35896—25.1%
——8——CVE-2021-41278—25.1%
——8——CVE-2020-26132—25.1%
——8——CVE-2021-42028—25.1%
——8——CVE-2023-23144—25.1%
——8——CVE-2024-9361—25.1%
——8——CVE-2024-9653—25.1%
——8——CVE-2019-12611—25.1%
——8——CVE-2024-1804—25.1%
——8——CVE-2020-0510—25.1%
——8——CVE-2025-62946—25.1%
——8——CVE-2020-5978—25.1%
——8——CVE-2026-118755.3 MED25.1%
——8The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.68dCVE-2025-59426—25.1%
——8——CVE-2025-712547.5 HIG25.1%
——8In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.57dCVE-2026-6315—25.1%
——8——CVE-2021-45465—25.1%
——8——CVE-2024-23902—25.1%
——8——CVE-2022-36448—25.1%
——8——CVE-2024-11401—25.1%
——8——CVE-2020-5987—25.1%
——8——CVE-2026-369577.5 HIG25.1%
——8Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent URIs, an attacker can exhaust critical system resources, including file descriptors and memory buffers. This results in a kernel deadlock or system hang that disables the web management portal and all routing capabilities.72dCVE-2025-48735—25.1%
——8——CVE-2026-749418.8 HIG25.1%
——8Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.25dCVE-2025-1445—25.1%
——8——CVE-2026-739947.5 HIG25.1%
——8Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.26dCVE-2020-5979—25.1%
——8——CVE-2025-23036—25.1%
——8——CVE-2020-8687—25.1%
——8——CVE-2026-347406.5 MED25.1%
——8WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FILTER_VALIDATE_URL, which accepts internal network addresses. Although AVideo has a dedicated isSSRFSafeURL() function for preventing SSRF, it is not called in this code path. This results in a stored server-side request forgery vulnerability that can be used to scan internal networks, access cloud metadata services, and interact with internal services. At time of publication, there are no publicly available patches.53dCVE-2025-67994—25.1%
——8——CVE-2026-135979.1 CRI25.1%
——8The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password.50dCVE-2024-33564—25.1%
——8——CVE-2020-12325—25.1%
——8——CVE-2023-47650—25.1%
——8——