Vulnerabilities exploitable today
354,170in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,468
- High8,365
- Medium7,494
- Low681
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-25830—95.6%
——29——CVE-2021-22654—95.6%
——29——CVE-2016-3353—95.6%
——29——CVE-2021-39841—95.6%
——29——CVE-2007-1863—95.6%
——29——CVE-2015-6912—95.6%
——29——CVE-2011-2543—95.6%
——29——CVE-2019-12854—95.6%
——29——CVE-2018-0930—95.6%
——29——CVE-2021-25151—95.6%
——29——CVE-2017-6506—95.6%
——29——CVE-2020-1286—95.6%
——29——CVE-2018-4872—95.6%
——29——CVE-2024-39360—95.6%
——29——CVE-2019-147506.1 MED95.6%
——29An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.20dCVE-2011-3160—95.6%
——29——CVE-2009-2168—95.6%
——29——CVE-2020-13938—95.6%
——29——CVE-2019-17132—95.6%
——29——CVE-2007-2285—95.6%
——29——CVE-2006-4304—95.6%
——29——CVE-2014-8731—95.6%
——29——CVE-2006-5822—95.6%
——29——CVE-2015-1632—95.6%
——29——CVE-2018-4961—95.6%
——29——CVE-2007-0455—95.6%
——29——CVE-2002-0696—95.6%
——29——CVE-2011-3157—95.6%
——29——CVE-2014-7279—95.6%
——29——CVE-2018-8468—95.6%
——29——CVE-2011-3162—95.6%
——29——CVE-1999-1397—95.6%
——29——CVE-2011-3158—95.6%
——29——CVE-2011-3159—95.6%
——29——CVE-2024-55544—95.6%
——29——CVE-2009-3302—95.6%
——29——CVE-2005-4573—95.6%
——29——CVE-2011-3161—95.6%
——29——CVE-2001-1342—95.6%
——29——CVE-2018-0925—95.6%
——29——