Vulnerabilities exploitable today
372,403in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,705
New KEV · 24H0
Exploit Today ≥ 701,644
Distribution · last window
- Critical2,282
- High8,401
- Medium6,467
- Low636
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-45049—23.5%
——7——CVE-2025-53714—23.5%
——7——CVE-2026-368077.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2008-4646—23.5%
——7——CVE-2024-22297—23.5%
——7——CVE-2026-368107.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2024-9919—23.5%
——7——CVE-2023-46783—23.5%
——7——CVE-2020-36429—23.5%
——7——CVE-2025-5732—23.5%
——7——CVE-2026-368057.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer overflows in the Saveqqlist function via the qqStr and markStr parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.53dCVE-2024-24713—23.5%
——7——CVE-2026-368187.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2026-568586.1 MED23.5%
——7Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.8dCVE-2020-5962—23.5%
——7——CVE-2026-53531—23.5%
——7RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximum depth limit. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = "abort"` (`Cargo.toml:48`), and because a Rust stack overflow is always a fatal `SIGABRT` regardless of panic strategy this is an unrecoverable, whole-process denial of service reachable from a single untrusted LaTeX string. Version 0.1.11 fixes the issue.2dCVE-2026-368227.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.50dCVE-2024-24931—23.5%
——7——CVE-2024-30250—23.5%
——7——CVE-2026-368207.5 HIG23.5%
——7Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.53dCVE-2025-54220—23.5%
——7——CVE-2022-48077—23.5%
——7——CVE-2005-0866—23.5%
——7——CVE-2024-24803—23.5%
——7——CVE-2026-82868.1 HIG23.5%
——7A vulnerability exists where a new transfer that uses STARTTLS to upgrade the
connection might reuse an existing live connection even though the TLS
configuration mismatches so it should not.66dCVE-2023-41666—23.5%
——7——CVE-2025-54217—23.5%
——7——CVE-2008-4953—23.5%
——7——CVE-2013-4355—23.5%
——7——CVE-2019-4239—23.5%
——7——CVE-2024-24930—23.5%
——7——CVE-2023-52178—23.5%
——7——CVE-2021-30680—23.5%
——7——CVE-2023-50824—23.5%
——7——CVE-2025-62459—23.5%
——7——CVE-2023-51749—23.5%
——7——CVE-2025-2245—23.5%
——7——CVE-2021-3960—23.5%
——7——CVE-2023-45110—23.5%
——7——CVE-2026-148617.5 HIG23.5%
——7The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to act on the supplied user, nor bind the protecting token to that user, allowing unauthenticated attackers to reset arbitrary users' email-verification status and lock them, including administrators, out of their accounts.23d