Vulnerabilities exploitable today
363,765in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,673
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,923
- High12,261
- Medium7,481
- Low679
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-2892—87.9%
——26——CVE-2011-1785—87.9%
——26——CVE-2007-1503—87.9%
——26——CVE-2010-0451—87.9%
——26——CVE-2017-5429—87.9%
——26——CVE-2012-1785—87.9%
——26——CVE-2020-16928—87.9%
——26——CVE-2014-5109—87.9%
——26——CVE-2004-1194—87.9%
——26——CVE-2014-9673—87.9%
——26——CVE-2012-6614—87.9%
——26——CVE-2017-7507—87.9%
——26——CVE-2017-12138—87.9%
——26——CVE-2020-13091—87.9%
——26——CVE-2022-4953—87.9%
——26——CVE-2021-44159—87.9%
——26——CVE-2026-2961—87.9%
——26——CVE-2017-15878—87.9%
——26——CVE-2026-137736.0 MED87.9%
——26IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.50dCVE-2018-7845—87.9%
——26——CVE-2015-0340—87.9%
——26——CVE-2020-3227—87.9%
——26——CVE-2023-38177—87.9%
——26——CVE-2015-1885—87.9%
——26——CVE-2019-13584—87.9%
——26——CVE-2017-1002004—87.9%
——26——CVE-2006-6102—87.9%
——26——CVE-2019-11472—87.9%
——26——CVE-2017-10804—87.9%
——26——CVE-2002-2149—87.9%
——26——CVE-2007-0358—87.9%
——26——CVE-2014-3311—87.9%
——26——CVE-2018-18773—87.9%
——26——CVE-2018-1999019—87.9%
——26——CVE-2019-16776—87.9%
——26——CVE-2018-8015—87.9%
——26——CVE-2019-1000019—87.9%
——26——CVE-2016-0089—87.9%
——26——CVE-2006-6924—87.9%
——26——CVE-2016-1405—87.9%
——26——