Vulnerabilities exploitable today
4,338in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,256
- High9,258
- Medium5,266
- Low507
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2017-126158.1 HIG99.9%
KEVR80Apache Tomcat on Windows Remote Code Execution Vulnerability25dCVE-2022-37061—99.9%
——30——CVE-2020-14181—99.9%
——30——CVE-2020-16040—99.9%
——30——CVE-2020-16846—99.9%
KEV—80SaltStack Salt Shell Injection Vulnerability—CVE-2026-80379.6 CRI99.9%
KEV—80Progress LoadMaster Command Injection Vulnerability21dCVE-2023-20198—99.9%
KEV—80Cisco IOS XE Web UI Privilege Escalation Vulnerability—CVE-2022-1471—99.9%
——30——CVE-2021-33045—99.9%
KEV—80Dahua IP Camera Authentication Bypass Vulnerability—CVE-2024-4040—99.9%
KEV—80CrushFTP VFS Sandbox Escape Vulnerability—CVE-2018-20062—99.9%
KEV—80ThinkPHP "noneCms" Remote Code Execution Vulnerability—CVE-2025-1974—99.9%
——30——CVE-2014-0094—99.9%
——30——CVE-2025-3132410.0 CRI99.9%
KEVR80SAP NetWeaver Unrestricted File Upload Vulnerability27dCVE-2020-1472—99.9%
KEVR80Microsoft Netlogon Privilege Escalation Vulnerability—CVE-2024-6387—99.9%
——30——CVE-2018-0171—99.9%
KEV—80Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability—CVE-2017-1000028—99.9%
——30——CVE-2022-42475—99.9%
KEVR80Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability—CVE-2024-236929.8 CRI99.9%
KEVR80Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability20dCVE-2013-0156—99.9%
——30——CVE-2018-2628—99.9%
KEV—80Oracle WebLogic Server Unspecified Vulnerability—CVE-2017-7494—99.9%
KEVR80Samba Remote Code Execution Vulnerability—CVE-2024-32113—99.9%
KEV—80Apache OFBiz Path Traversal Vulnerability—CVE-2023-376799.8 CRI99.9%
——30A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.53dCVE-2023-34048—99.9%
KEV—80VMware vCenter Server Out-of-Bounds Write Vulnerability—CVE-2023-32560—99.9%
——30——CVE-2024-38856—99.9%
KEV—80Apache OFBiz Incorrect Authorization Vulnerability—CVE-2011-0611—99.9%
KEV—80Adobe Flash Player Remote Code Execution Vulnerability—CVE-2017-9805—99.9%
KEV—80Apache Struts Deserialization of Untrusted Data Vulnerability—CVE-2021-32030—99.9%
KEV—80ASUS Routers Improper Authentication Vulnerability—CVE-2017-0148—99.9%
KEVR80Microsoft SMBv1 Server Remote Code Execution Vulnerability—CVE-2022-0543—99.9%
KEV—80Debian-specific Redis Server Lua Sandbox Escape Vulnerability—CVE-2015-5119—99.9%
KEV—80Adobe Flash Player Use-After-Free Vulnerability—CVE-2023-349609.8 CRI99.9%
——30A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.53dCVE-2014-6287—99.9%
KEV—80Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability—CVE-2021-34429—99.9%
——30——CVE-2017-12542—99.9%
——30——CVE-2018-12998—99.9%
——30——CVE-2023-23333—99.9%
——30——