Vulnerabilities exploitable today
356,684in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,662
New KEV · 24H0
Exploit Today ≥ 701,605
Distribution · last window
- Critical2,537
- High10,637
- Medium6,742
- Low667
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2011-2148—91.8%
——28——CVE-2016-20012—91.8%
——28——CVE-2013-3331—91.8%
——28——CVE-2018-10969—91.8%
——28——CVE-2019-12190—91.8%
——28——CVE-2015-4704—91.8%
——28——CVE-2019-11869—91.8%
——28——CVE-2017-8602—91.8%
——28——CVE-2019-9740—91.8%
——28——CVE-2013-3335—91.8%
——28——CVE-2018-14469—91.8%
——28——CVE-2022-3140—91.8%
——28——CVE-2019-6804—91.8%
——28——CVE-2026-328547.5 HIG91.8%
——28LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit missing validation of strchr() return values in the CONNECT and GET proxy handling paths to trigger null pointer dereferences and crash the server when httpd and proxy features are enabled.25dCVE-2007-5958—91.8%
——28——CVE-2006-1548—91.8%
——28——CVE-2011-4343—91.8%
——28——CVE-2003-0288—91.8%
——28——CVE-2007-0955—91.8%
——28——CVE-2007-6615—91.8%
——28——CVE-2009-3179—91.8%
——28——CVE-2016-2196—91.8%
——28——CVE-2023-49786—91.8%
——28——CVE-2025-25038—91.8%
——28——CVE-2002-0450—91.8%
——28——CVE-2015-3254—91.8%
——28——CVE-2019-12643—91.8%
——28——CVE-2022-4634—91.8%
——28——CVE-2011-2998—91.8%
——28——CVE-2013-6627—91.8%
——28——CVE-2020-5739—91.8%
——28——CVE-2001-0442—91.8%
——28——CVE-2009-1885—91.8%
——28——CVE-2003-0320—91.8%
——28——CVE-2021-28624—91.8%
——28——CVE-2019-8066—91.8%
——28——CVE-2022-30184—91.8%
——28——CVE-2009-1039—91.8%
——28——CVE-2019-1917—91.8%
——28——CVE-2013-3330—91.8%
——28——