Vulnerabilities exploitable today
358,551in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,687
- High11,666
- Medium7,436
- Low688
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2006-2271—90.3%
——27——CVE-2004-0448—90.3%
——27——CVE-2016-4241—90.3%
——27——CVE-2021-344708.0 HIG90.3%
——27Microsoft Exchange Server Elevation of Privilege Vulnerability2dCVE-2021-22922—90.3%
——27——CVE-2019-8028—90.3%
——27——CVE-2011-3623—90.3%
——27——CVE-2020-11655—90.3%
——27——CVE-2022-0750—90.3%
——27——CVE-2017-8223—90.3%
——27——CVE-2017-3243—90.3%
——27——CVE-2011-2368—90.3%
——27——CVE-2006-4917—90.3%
——27——CVE-2006-5340—90.3%
——27——CVE-2001-0931—90.3%
——27——CVE-2018-1212—90.3%
——27——CVE-2017-9377—90.3%
——27——CVE-2009-0496—90.3%
——27——CVE-2013-5755—90.3%
——27——CVE-2007-1794—90.3%
——27——CVE-2000-0509—90.3%
——27——CVE-2013-7025—90.3%
——27——CVE-2020-16608—90.3%
——27——CVE-2023-49314—90.3%
——27——CVE-2016-4219—90.3%
——27——CVE-2016-4220—90.3%
——27——CVE-2018-10257—90.3%
——27——CVE-2008-6822—90.3%
——27——CVE-2009-3739—90.3%
——27——CVE-2019-18830—90.3%
——27——CVE-2025-25034—90.3%
——27——CVE-2019-16693—90.3%
——27——CVE-2021-40521—90.3%
——27——CVE-2019-12324—90.3%
——27——CVE-2026-4766810.0 CRI90.3%
——27DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.19dCVE-2008-4360—90.3%
——27——CVE-2016-9165—90.3%
——27——CVE-2024-0799—90.3%
——27——CVE-2019-1624—90.3%
——27——CVE-2022-24065—90.3%
——27——