Vulnerabilities exploitable today
358,551in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,687
- High11,674
- Medium7,443
- Low689
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-7131—90.3%
——27——CVE-2016-7087—90.3%
——27——CVE-2022-33206—90.3%
——27——CVE-2022-23125—90.3%
——27——CVE-2020-7633—90.3%
——27——CVE-2022-34699—90.3%
——27——CVE-2018-4331—90.3%
——27——CVE-2007-6350—90.3%
——27——CVE-2006-3117—90.3%
——27——CVE-2015-7176—90.3%
——27——CVE-2018-17784—90.3%
——27——CVE-2008-5516—90.3%
——27——CVE-2009-4549—90.3%
——27——CVE-2007-0528—90.3%
——27——CVE-2019-8006—90.3%
——27——CVE-2022-33965—90.3%
——27——CVE-2011-2911—90.3%
——27——CVE-2011-2912—90.3%
——27——CVE-2017-8665—90.3%
——27——CVE-2007-2623—90.3%
——27——CVE-2015-8854—90.3%
——27——CVE-2001-1315—90.3%
——27——CVE-2019-18890—90.3%
——27——CVE-2006-2550—90.3%
——27——CVE-2023-6038—90.3%
——27——CVE-2014-5380—90.3%
——27——CVE-2008-4360—90.3%
——27——CVE-2014-5415—90.3%
——27——CVE-2026-4766810.0 CRI90.3%
——27DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.19dCVE-2021-32465—90.3%
——27——CVE-2024-0799—90.3%
——27——CVE-2022-24065—90.3%
——27——CVE-2009-0663—90.3%
——27——CVE-2016-9165—90.3%
——27——CVE-2019-1624—90.3%
——27——CVE-2017-5693—90.3%
——27——CVE-2007-5111—90.3%
——27——CVE-2004-0448—90.3%
——27——CVE-2012-3954—90.3%
——27——CVE-2012-2002—90.3%
——27——