Vulnerabilities exploitable today
354,689in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,617
- High9,375
- Medium7,592
- Low711
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-1999-0219—94.8%
——28——CVE-2019-7275—94.8%
——28——CVE-2024-5337—94.8%
——28——CVE-2020-11514—94.8%
——28——CVE-2008-0690—94.8%
——28——CVE-2007-5476—94.8%
——28——CVE-2025-52377—94.8%
——28——CVE-2018-19386—94.8%
——28——CVE-2007-1381—94.8%
——28——CVE-2004-1363—94.8%
——28——CVE-2013-4096—94.8%
——28——CVE-2007-1380—94.8%
——28——CVE-2012-2276—94.8%
——28——CVE-2020-12002—94.8%
——28——CVE-2025-2594—94.8%
——28——CVE-2003-1396—94.8%
——28——CVE-2012-5285—94.8%
——28——CVE-2025-606895.4 MED94.8%
——28An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are concatenated into system command strings without proper sanitization and executed via wl_exec_cmd. Successful exploitation allows remote attackers to execute arbitrary commands on the device without authentication.10dCVE-2019-3474—94.7%
——28——CVE-2020-1425—94.7%
——28——CVE-2021-44673—94.7%
——28——CVE-2013-2118—94.7%
——28——CVE-2024-56337—94.7%
——28——CVE-2015-4935—94.7%
——28——CVE-2015-8457—94.7%
——28——CVE-2025-4902—94.7%
——28——CVE-2013-4475—94.7%
——28——CVE-2014-8461—94.7%
——28——CVE-2009-0839—94.7%
——28——CVE-2023-49007—94.7%
——28——CVE-2008-4796—94.7%
——28——CVE-2018-0753—94.7%
——28——CVE-2018-8360—94.7%
——28——CVE-2011-2457—94.7%
——28——CVE-2006-4006—94.7%
——28——CVE-2021-38306—94.7%
——28——CVE-2013-1450—94.7%
——28——CVE-2010-2521—94.7%
——28——CVE-2019-0829—94.7%
——28——CVE-2008-4769—94.7%
——28——