Vulnerabilities exploitable today
4,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,269
- Medium5,273
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-43798—99.8%
KEV—80Grafana Path Traversal Vulnerability—CVE-2021-35590—99.8%
——30——CVE-2021-21699—99.8%
——30——CVE-2021-31643—99.8%
——30——CVE-2020-8193—99.8%
KEV—80Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability—CVE-2020-5398—99.8%
——30——CVE-2020-3243—99.8%
——30——CVE-2023-468478.6 HIG99.8%
——30Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.25dCVE-2024-2961—99.8%
——30——CVE-2025-57819—99.8%
KEV—80Sangoma FreePBX Authentication Bypass Vulnerability—CVE-2024-21683—99.8%
——30——CVE-2010-01887.8 HIG99.8%
KEVR80Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability17dCVE-2026-20127—99.8%
KEV—80Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability—CVE-2024-25600—99.8%
——30——CVE-2012-1454—99.8%
——30——CVE-2023-412659.6 CRI99.8%
KEVR80Qlik Sense HTTP Tunneling Vulnerability26dCVE-2019-7192—99.8%
KEVR80QNAP Photo Station Improper Access Control Vulnerability—CVE-2025-61757—99.8%
KEV—80Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability—CVE-2026-202308.6 HIG99.8%
KEV—80Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability40dCVE-2023-36025—99.8%
KEV—80Microsoft Windows SmartScreen Security Feature Bypass Vulnerability—CVE-2004-2687—99.8%
——30——CVE-2021-20837—99.8%
——30——CVE-2018-1000115—99.8%
——30——CVE-2020-35729—99.8%
——30——CVE-2018-19207—99.8%
——30——CVE-2022-0540—99.8%
——30——CVE-2020-8772—99.8%
——30——CVE-2014-1776—99.8%
KEV—80Microsoft Internet Explorer Memory Corruption Vulnerability—CVE-2024-12356—99.8%
KEV—80BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability —CVE-2017-17411—99.8%
——30——CVE-2003-0085—99.8%
——30——CVE-2022-27593—99.8%
KEVR80QNAP Photo Station Externally Controlled Reference Vulnerability—CVE-2003-0718—99.8%
——30——CVE-2024-26256—99.8%
——30——CVE-2026-90829.8 CRI99.8%
KEV—80Drupal Core SQL Injection Vulnerability39dCVE-2014-0221—99.8%
——30——CVE-2024-36104—99.8%
——30——CVE-2018-7357—99.8%
——30——CVE-2009-0658—99.8%
——30——CVE-2025-29635—99.8%
KEV—80D-Link DIR-823X Command Injection Vulnerability—