Vulnerabilities exploitable today
358,987in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,665
New KEV · 24H0
Exploit Today ≥ 701,607
Distribution · last window
- Critical2,477
- High11,067
- Medium7,028
- Low654
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2014-2855—89.9%
——27——CVE-2019-15528—89.9%
——27——CVE-2007-6545—89.9%
——27——CVE-2016-9303—89.9%
——27——CVE-2017-16606—89.9%
——27——CVE-2018-17198—89.9%
——27——CVE-2019-1051—89.9%
——27——CVE-2014-7840—89.9%
——27——CVE-2019-159927.2 HIG89.9%
——27A vulnerability in the implementation of the Lua interpreter integrated in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying Linux operating system of an affected device. The vulnerability is due to insufficient restrictions on the allowed Lua function calls within the context of user-supplied Lua scripts. A successful exploit could allow the attacker to trigger a heap overflow condition and execute arbitrary code with root privileges on the underlying Linux operating system of an affected device.3dCVE-2020-9463—89.9%
——27——CVE-2016-4861—89.9%
——27——CVE-2016-3554—89.9%
——27——CVE-2016-4965—89.9%
——27——CVE-2013-4531—89.9%
——27——CVE-2020-7624—89.9%
——27——CVE-2017-11525—89.9%
——27——CVE-2006-6976—89.9%
——27——CVE-2017-5396—89.9%
——27——CVE-2012-2379—89.9%
——27——CVE-2018-0410—89.9%
——27——CVE-2009-4587—89.9%
——27——CVE-2015-7984—89.9%
——27——CVE-2006-4450—89.9%
——27——CVE-2002-2011—89.9%
——27——CVE-2008-5345—89.9%
——27——CVE-2020-7625—89.9%
——27——CVE-2018-7105—89.9%
——27——CVE-2007-5391—89.9%
——27——CVE-2026-53526.3 MED89.9%
——27A security vulnerability has been detected in Trendnet TEW-657BRM 1.00.1. This impacts the function Edit of the file /setup.cgi. Such manipulation of the argument pcdb_list leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.21dCVE-2007-5048—89.9%
——27——CVE-2016-7980—89.9%
——27——CVE-2013-4267—89.9%
——27——CVE-2020-11969—89.9%
——27——CVE-2016-5983—89.9%
——27——CVE-2010-3031—89.9%
——27——CVE-2002-0525—89.9%
——27——CVE-2019-14418—89.9%
——27——CVE-2020-7627—89.9%
——27——CVE-2000-0827—89.9%
——27——CVE-2012-5674—89.9%
——27——