Vulnerabilities exploitable today
4,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,274
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-116809.8 CRI99.8%
KEV—80ProjectSend Improper Authentication Vulnerability48dCVE-2016-3510—99.8%
——30——CVE-2017-0004—99.8%
——30——CVE-2023-36844—99.8%
KEV—80Juniper Junos OS EX Series PHP External Variable Modification Vulnerability—CVE-2014-0054—99.8%
——30——CVE-2020-1350—99.8%
KEV—80Microsoft Windows DNS Server Remote Code Execution Vulnerability—CVE-2024-27316—99.8%
——30——CVE-2010-2568—99.8%
KEV—80Microsoft Windows Remote Code Execution Vulnerability—CVE-2020-27988—99.8%
——30——CVE-2010-4221—99.8%
——30——CVE-2025-92429.8 CRI99.8%
KEV—80WatchGuard Firebox Out-of-Bounds Write Vulnerability21dCVE-2015-5477—99.8%
——30——CVE-2024-13160—99.8%
KEV—80Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability—CVE-2020-8654—99.8%
——30——CVE-2021-35211—99.8%
KEVR80SolarWinds Serv-U Remote Code Execution Vulnerability—CVE-2018-3810—99.8%
——30——CVE-2021-25921—99.8%
——30——CVE-2020-13851—99.8%
——30——CVE-2015-7547—99.8%
——30——CVE-2024-11320—99.8%
——30——CVE-2012-5076—99.8%
KEV—80Oracle Java SE Sandbox Bypass Vulnerability—CVE-2021-22962—99.8%
——30——CVE-2022-26809—99.8%
——30——CVE-2009-3023—99.8%
——30——CVE-2022-36553—99.8%
——30——CVE-2018-1000600—99.8%
——30——CVE-2025-34037—99.8%
——30An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the ttcp_ip parameter without sanitization, allowing unauthenticated attackers to inject shell commands. This vulnerability was reported to be exploited in the wild by the "TheMoon" worm in 2014 to deploy a MIPS ELF payload, enabling arbitrary code execution on the router. Additionally, this vulnerability may affect other Linksys products to include, but not limited to, WAG/WAP/WES/WET/WRT-series router models and Wireless-N access points and routers. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.40dCVE-2017-7615—99.8%
——30——CVE-2001-0333—99.8%
——30——CVE-2022-3602—99.8%
——30——CVE-2007-0450—99.8%
——30——CVE-2020-8243—99.8%
KEV—80Ivanti Pulse Connect Secure Code Execution Vulnerability—CVE-2026-356169.8 CRI99.8%
KEV—80Fortinet FortiClient EMS Improper Access Control Vulnerability38dCVE-2011-3368—99.8%
——30——CVE-2017-121499.8 CRI99.8%
KEVR80Red Hat JBoss Application Server Remote Code Execution Vulnerability18dCVE-2021-21315—99.8%
KEV—80System Information Library for Node.JS Command Injection—CVE-2018-11759—99.8%
——30——CVE-2000-0402—99.8%
——30——CVE-2017-3066—99.8%
KEV—80Adobe ColdFusion Deserialization Vulnerability—CVE-2013-6429—99.8%
——30——