Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,690
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2004-1371—95.4%
——29——CVE-2011-2697—95.4%
——29——CVE-2026-95336.3 MED95.4%
——29A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.8dCVE-2007-4478—95.4%
——29——CVE-2021-43734—95.4%
——29——CVE-2026-95326.3 MED95.4%
——29A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.8dCVE-2014-3580—95.4%
——29——CVE-2010-2011—95.4%
——29——CVE-2010-3450—95.4%
——29——CVE-2019-17566—95.4%
——29——CVE-2024-44466—95.4%
——29——CVE-2021-41578—95.4%
——29——CVE-2007-6697—95.4%
——29——CVE-2015-2682—95.4%
——29——CVE-2005-1278—95.4%
——29——CVE-2021-256817.5 HIG95.4%
——29AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.22dCVE-2025-3820—95.4%
——29——CVE-2018-19125—95.4%
——29——CVE-2001-0013—95.4%
——29——CVE-2021-24405—95.4%
——29——CVE-2018-10123—95.4%
——29——CVE-2026-95146.3 MED95.4%
——29A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.8dCVE-2002-0617—95.4%
——29——CVE-2018-8038—95.4%
——29——CVE-2008-2702—95.3%
——29——CVE-2021-20158—95.4%
——29——CVE-2001-0199—95.4%
——29——CVE-2015-4600—95.4%
——29——CVE-2006-5295—95.4%
——29——CVE-2014-9218—95.4%
——29——CVE-2019-1108—95.4%
——29——CVE-2017-0229—95.3%
——29——CVE-2003-0125—95.4%
——29——CVE-2017-8946—95.4%
——29——CVE-2016-7870—95.3%
——29——CVE-2014-5302—95.4%
——29——CVE-2015-4599—95.4%
——29——CVE-2012-3588—95.4%
——29——CVE-2007-3806—95.4%
——29——CVE-2007-3302—95.4%
——29——