Vulnerabilities exploitable today
378,755in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,721
New KEV · 24H0
Exploit Today ≥ 701,652
Distribution · last window
- Critical2,413
- High8,699
- Medium6,979
- Low789
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2015-3777—33.9%
——10——CVE-2025-25150—33.9%
——10——CVE-2023-27631—33.9%
——10——CVE-2018-6629—33.9%
——10——CVE-2018-6626—33.9%
——10——CVE-2018-6779—33.9%
——10——CVE-2018-8992—33.9%
——10——CVE-2026-578597.5 HIG33.9%
——10e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the stored value to eval(), causing automatic PHP execution whenever the affected user's preferences are materialized through e_user_pref::load().54dCVE-2018-6780—33.9%
——10——CVE-2018-6770—33.9%
——10——CVE-2026-32132—33.9%
——10——CVE-2018-8994—33.9%
——10——CVE-2008-5984—33.9%
——10——CVE-2000-1011—33.9%
——10——CVE-2018-8904—33.9%
——10——CVE-2000-0294—33.9%
——10——CVE-2019-25402—33.9%
——10——CVE-2002-0349—33.9%
——10——CVE-1999-0245—33.9%
——10——CVE-2018-8993—33.9%
——10——CVE-2018-6778—33.9%
——10——CVE-2018-8997—33.9%
——10——CVE-2020-13646—33.9%
——10——CVE-2018-6783—33.9%
——10——CVE-2021-37725—33.9%
——10——CVE-2018-5081—33.9%
——10——CVE-2018-5079—33.9%
——10——CVE-2025-4643—33.9%
——10——CVE-2018-8896—33.9%
——10——CVE-2024-32681—33.9%
——10——CVE-2025-30657—33.9%
——10——CVE-2018-5080—33.9%
——10——CVE-2018-6774—33.9%
——10——CVE-2025-63408—33.9%
——10——CVE-2018-5086—33.9%
——10——CVE-2024-45509—33.9%
——10——CVE-2018-6625—33.9%
——10——CVE-2018-6207—33.9%
——10——CVE-2018-6776—33.9%
——10——CVE-2018-6781—33.9%
——10——