Vulnerabilities exploitable today
364,306in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,674
New KEV · 24H0
Exploit Today ≥ 701,611
Distribution · last window
- Critical2,349
- High9,915
- Medium4,964
- Low466
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-17090—87.7%
——26——CVE-2010-1511—87.7%
——26——CVE-2018-18068—87.7%
——26——CVE-2006-6462—87.7%
——26——CVE-2005-2770—87.7%
——26——CVE-2020-0452—87.7%
——26——CVE-2008-3363—87.7%
——26——CVE-2009-1365—87.7%
——26——CVE-2021-25928—87.7%
——26——CVE-2008-3764—87.7%
——26——CVE-2018-4834—87.7%
——26——CVE-2020-12138—87.7%
——26——CVE-2017-7314—87.7%
——26——CVE-2008-2648—87.7%
——26——CVE-2009-2963—87.7%
——26——CVE-2022-45876—87.7%
——26——CVE-2018-14367—87.7%
——26——CVE-2003-0961—87.7%
——26——CVE-2020-10650—87.7%
——26——CVE-2010-0628—87.7%
——26——CVE-2024-20734—87.6%
——26——CVE-2010-2235—87.7%
——26——CVE-2021-41018—87.7%
——26——CVE-2012-2777—87.7%
——26——CVE-2010-3054—87.7%
——26——CVE-2016-7530—87.7%
——26——CVE-2017-15119—87.7%
——26——CVE-2010-0514—87.6%
——26——CVE-2024-487056.5 MED87.7%
——26Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field50dCVE-2007-5386—87.7%
——26——CVE-2019-13354—87.7%
——26——CVE-2008-7104—87.7%
——26——CVE-2012-1464—87.7%
——26——CVE-2007-1063—87.7%
——26——CVE-2016-7537—87.7%
——26——CVE-2020-12830—87.7%
——26——CVE-2007-5589—87.7%
——26——CVE-2015-5772—87.7%
——26——CVE-2004-2675—87.7%
——26——CVE-2002-1945—87.7%
——26——