Vulnerabilities exploitable today
354,449in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,641
- High9,461
- Medium7,690
- Low693
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2001-0199—95.4%
——29——CVE-2021-24320—95.4%
——29——CVE-2021-44704—95.4%
——29——CVE-2026-95346.3 MED95.4%
——29A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.8dCVE-2024-27612—95.4%
——29——CVE-2021-256817.5 HIG95.4%
——29AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.22dCVE-2026-95326.3 MED95.4%
——29A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.8dCVE-2015-2489—95.4%
——29——CVE-2017-0899—95.4%
——29——CVE-2015-4600—95.4%
——29——CVE-2015-4599—95.4%
——29——CVE-2010-1299—95.4%
——29——CVE-2019-14540—95.4%
——29——CVE-2026-95336.3 MED95.4%
——29A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.8dCVE-2022-1118—95.4%
——29——CVE-2018-8206—95.4%
——29——CVE-2026-483327.7 HIG95.4%
——29ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.15dCVE-2002-0617—95.4%
——29——CVE-2017-8749—95.4%
——29——CVE-2007-4990—95.4%
——29——CVE-2010-4267—95.4%
——29——CVE-2014-3583—95.4%
——29——CVE-2026-21249—95.4%
——29——CVE-2026-95146.3 MED95.4%
——29A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.8dCVE-2005-0500—95.4%
——29——CVE-2015-2213—95.4%
——29——CVE-2006-1770—95.4%
——29——CVE-2016-7870—95.3%
——29——CVE-2026-95316.3 MED95.4%
——29A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.8dCVE-2001-0432—95.4%
——29——CVE-2014-3580—95.4%
——29——CVE-2018-19125—95.4%
——29——CVE-2019-7824—95.4%
——29——CVE-2006-5295—95.4%
——29——CVE-2011-3495—95.4%
——29——CVE-2014-9218—95.4%
——29——CVE-2019-6753—95.4%
——29——CVE-2012-3236—95.4%
——29——CVE-2025-3820—95.4%
——29——CVE-2010-1932—95.4%
——29——