Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,282
- High8,400
- Medium6,466
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-368107.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2019-4239—23.5%
——7——CVE-2008-4646—23.5%
——7——CVE-2025-5732—23.5%
——7——CVE-2024-25094—23.5%
——7——CVE-2024-45611—23.5%
——7——CVE-2026-730798.5 HIG23.5%
——7Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*subpath` wildcard routes spliced the client-supplied subpath into the upstream URL with no validation. This lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials via a path traversal. This vulnerability is fixed in 0.1.169.2dCVE-2022-45868—23.5%
——7——CVE-2025-54219—23.5%
——7——CVE-2024-24930—23.5%
——7——CVE-2023-52178—23.5%
——7——CVE-2008-4953—23.5%
——7——CVE-2013-4355—23.5%
——7——CVE-2005-0866—23.5%
——7——CVE-2025-54217—23.5%
——7——CVE-2026-109298.3 HIG23.5%
——7Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)51dCVE-2023-51532—23.5%
——7——CVE-2024-25098—23.5%
——7——CVE-2019-4668—23.5%
——7——CVE-2023-30492—23.5%
——7——CVE-2026-368167.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2025-13333—23.5%
——7——CVE-2023-52197—23.5%
——7——CVE-2023-41687—23.5%
——7——CVE-2020-23139—23.5%
——7——CVE-2026-2146—23.5%
——7——CVE-2026-368157.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2026-4983—23.5%
——7——CVE-2023-45067—23.5%
——7——CVE-2023-46581—23.5%
——7——CVE-2025-1373—23.5%
——7——CVE-2023-51372—23.5%
——7——CVE-2024-45426—23.5%
——7——CVE-2008-1865—23.5%
——7——CVE-2025-10593—23.5%
——7——CVE-2019-11165—23.5%
——7——CVE-2023-47177—23.5%
——7——CVE-2023-45049—23.5%
——7——CVE-2026-368077.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2025-53714—23.5%
——7——