Vulnerabilities exploitable today
355,262in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,657
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,740
- High11,055
- Medium7,344
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2018-8794—93.2%
——28——CVE-2007-3338—93.2%
——28——CVE-2022-20472—93.2%
——28——CVE-2018-13140—93.2%
——28——CVE-2019-7779—93.2%
——28——CVE-2007-0980—93.2%
——28——CVE-2021-46398—93.2%
——28——CVE-2018-1040—93.2%
——28——CVE-2007-0451—93.2%
——28——CVE-2016-6432—93.2%
——28——CVE-2008-6071—93.2%
——28——CVE-2008-7086—93.2%
——28——CVE-2008-3252—93.2%
——28——CVE-2026-3288—93.2%
——28——CVE-2024-26170—93.2%
——28——CVE-2024-30280—93.2%
——28——CVE-2025-47959—93.2%
——28——CVE-2021-23132—93.2%
——28——CVE-2016-2242—93.2%
——28——CVE-2025-606876.5 MED93.2%
——28An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is then directly inserted into a system command using sprintf() and executed with system(). Maliciously crafted IMEI input can execute arbitrary commands on the router without authentication.31dCVE-2007-1916—93.2%
——28——CVE-2015-4695—93.2%
——28——CVE-2008-7006—93.2%
——28——CVE-2006-6445—93.2%
——28——CVE-2008-2419—93.2%
——28——CVE-2016-7130—93.2%
——28——CVE-2007-1917—93.2%
——28——CVE-2015-0225—93.2%
——28——CVE-2004-0164—93.2%
——28——CVE-2006-1159—93.2%
——28——CVE-2015-8309—93.2%
——28——CVE-2011-3187—93.2%
——28——CVE-2009-1690—93.2%
——28——CVE-2013-1821—93.2%
——28——CVE-2012-3961—93.2%
——28——CVE-2014-0063—93.2%
——28——CVE-2006-3223—93.2%
——28——CVE-2023-20569—93.2%
——28——CVE-2016-5767—93.2%
——28——CVE-2011-0226—93.2%
——28——