Vulnerabilities exploitable today
352,969in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,600
Distribution · last window
- Critical2,334
- High8,050
- Medium7,230
- Low682
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2001-0815—96.2%
——29——CVE-2020-7473—96.2%
——29——CVE-2013-2558—96.2%
——29——CVE-2001-0245—96.2%
——29——CVE-2021-28359—96.2%
——29——CVE-2002-0372—96.2%
——29——CVE-2014-6357—96.2%
——29——CVE-1999-1052—96.2%
——29——CVE-2013-0083—96.2%
——29——CVE-2024-57684—96.2%
——29——CVE-2021-45901—96.2%
——29——CVE-2007-2434—96.2%
——29——CVE-2011-0917—96.2%
——29——CVE-2011-3496—96.2%
——29——CVE-2015-7246—96.2%
——29——CVE-2023-22513—96.2%
——29——CVE-2021-1388—96.2%
——29——CVE-2002-1718—96.2%
——29——CVE-2018-8588—96.2%
——29——CVE-2019-13383—96.2%
——29——CVE-2005-2126—96.2%
——29——CVE-2005-445910.0 NO 96.2%
——29Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.20dCVE-2020-1062—96.2%
——29——CVE-2010-1175—96.2%
——29——CVE-2015-2481—96.2%
——29——CVE-2018-17442—96.2%
——29——CVE-2005-2970—96.2%
——29——CVE-2018-8557—96.2%
——29——CVE-2018-8555—96.2%
——29——CVE-2013-0233—96.2%
——29——CVE-2015-1880—96.2%
——29——CVE-2016-4463—96.2%
——29——CVE-2001-0658—96.2%
——29——CVE-2017-8529—96.2%
——29——CVE-2015-1765—96.2%
——29——CVE-2026-5852—96.2%
——29——CVE-2026-46319.8 CRI96.2%
——29Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.13dCVE-2010-2642—96.2%
——29——CVE-2009-0086—96.2%
——29——CVE-2022-31788—96.2%
——29——