Vulnerabilities exploitable today
4,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,263
- High9,268
- Medium5,273
- Low508
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2005-4360—99.7%
——30——CVE-2015-8103—99.7%
——30——CVE-2020-25687—99.7%
——30——CVE-2015-2426—99.7%
KEV—80Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability—CVE-2020-8644—99.7%
KEV—80PlaySMS Server-Side Template Injection Vulnerability—CVE-2023-35813—99.7%
——30——CVE-2003-0132—99.7%
——30——CVE-2021-40655—99.7%
KEV—80D-Link DIR-605 Router Information Disclosure Vulnerability—CVE-2015-2996—99.7%
——30——CVE-2018-1999002—99.7%
——30——CVE-2020-10915—99.7%
——30——CVE-2020-139357.5 HIG99.7%
——30The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.6dCVE-2023-36035—99.7%
——30——CVE-2018-17153—99.7%
——30——CVE-2009-3459—99.7%
KEV—80Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability—CVE-2011-2462—99.7%
KEV—80Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability—CVE-2018-1160—99.7%
——30——CVE-2024-5156710.0 CRI99.7%
KEVR80CyberPanel Incorrect Default Permissions Vulnerability27dCVE-2023-28121—99.7%
——30——CVE-2018-10661—99.7%
——30——CVE-2024-3721—99.7%
——30——CVE-2023-34127—99.7%
——30——CVE-2019-4716—99.7%
KEV—80IBM Planning Analytics Remote Code Execution Vulnerability—CVE-2011-2110—99.7%
——30——CVE-2021-27907—99.7%
——30——CVE-2010-0483—99.7%
——30——CVE-2005-0773—99.7%
——30——CVE-2025-24799—99.7%
——30——CVE-2020-14295—99.7%
——30——CVE-2022-3265—99.7%
——30——CVE-2021-21017—99.7%
KEV—80Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability—CVE-2013-7091—99.7%
——30——CVE-2024-25641—99.7%
——30——CVE-2012-0152—99.7%
——30——CVE-2018-6961—99.7%
KEV—80VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability—CVE-2018-15379—99.7%
——30——CVE-2017-5816—99.7%
——30——CVE-2026-1340—99.7%
KEV—80Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability—CVE-2022-2992—99.7%
——30——CVE-2016-20016—99.7%
——30——