Vulnerabilities exploitable today
352,773in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,598
Distribution · last window
- Critical2,281
- High7,876
- Medium7,168
- Low676
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2020-0687—97.0%
——29——CVE-2010-1495—97.0%
——29——CVE-2014-0263—97.0%
——29——CVE-2022-31656—97.0%
——29——CVE-2006-4018—97.0%
——29——CVE-2022-30425—97.0%
——29——CVE-2003-1028—97.0%
——29——CVE-2023-44974—97.0%
——29——CVE-2015-6053—97.0%
——29——CVE-2005-1215—97.0%
——29——CVE-2026-534358.8 HIG97.0%
——29In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.
This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.11dCVE-2019-1003005—97.0%
——29——CVE-2015-2673—97.0%
——29——CVE-2021-27140—97.0%
——29——CVE-2018-8539—97.0%
——29——CVE-2018-20556—97.0%
——29——CVE-2018-6910—97.0%
——29——CVE-2026-2652—97.0%
——29——CVE-1999-0450—97.0%
——29——CVE-2017-11769—97.0%
——29——CVE-2024-28739—97.0%
——29——CVE-2018-8522—97.0%
——29——CVE-2022-3488—97.0%
——29——CVE-2017-9800—97.0%
——29——CVE-2020-5512—97.0%
——29——CVE-2016-6855—97.0%
——29——CVE-2020-24577—97.0%
——29——CVE-2017-17849—97.0%
——29——CVE-2013-5967—97.0%
——29——CVE-2017-0204—97.0%
——29——CVE-2020-6507—97.0%
——29——CVE-2017-3117—97.0%
——29——CVE-2024-53333—97.0%
——29——CVE-2002-0569—97.0%
——29——CVE-2018-8472—97.0%
——29——CVE-2007-2194—97.0%
——29——CVE-2017-8527—97.0%
——29——CVE-2018-15932—97.0%
——29——CVE-2022-1367—97.0%
——29——CVE-2021-24867—97.0%
——29——