Vulnerabilities exploitable today
355,082in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,656
New KEV · 24H0
Exploit Today ≥ 701,601
Distribution · last window
- Critical2,577
- High9,224
- Medium7,474
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-8394—93.6%
——28——CVE-2006-2583—93.6%
——28——CVE-2014-8397—93.6%
——28——CVE-2001-0177—93.6%
——28——CVE-1999-0497—93.6%
——28——CVE-2005-2640—93.6%
——28——CVE-2016-3980—93.6%
——28——CVE-2016-0943—93.6%
——28——CVE-2009-1057—93.6%
——28——CVE-2020-1060—93.6%
——28——CVE-2015-3152—93.6%
——28——CVE-2007-1648—93.6%
——28——CVE-2018-8793—93.6%
——28——CVE-2011-3321—93.6%
——28——CVE-2019-8395—93.6%
——28——CVE-2016-9684—93.6%
——28——CVE-2007-2497—93.6%
——28——CVE-2024-8897—93.6%
——28——CVE-2015-0264—93.6%
——28——CVE-2010-2935—93.6%
——28——CVE-2001-0616—93.6%
——28——CVE-2007-6347—93.6%
——28——CVE-2000-0640—93.6%
——28——CVE-2001-0581—93.6%
——28——CVE-2002-1347—93.6%
——28——CVE-2014-0035—93.5%
——28——CVE-2019-17573—93.6%
——28——CVE-2025-32794—93.6%
——28——CVE-2018-8596—93.6%
——28——CVE-2025-10680—93.6%
——28——CVE-2026-479994.8 MED93.6%
——28Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.19dCVE-2014-9471—93.6%
——28——CVE-2020-1577—93.6%
——28——CVE-2008-4926—93.6%
——28——CVE-2024-11392—93.6%
——28——CVE-2001-0298—93.6%
——28——CVE-2017-11228—93.6%
——28——CVE-2020-8115—93.6%
——28——CVE-2016-5397—93.6%
——28——CVE-2007-2401—93.6%
——28——