Vulnerabilities exploitable today
4,338in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,685
New KEV · 24H0
Exploit Today ≥ 701,629
Distribution · last window
- Critical2,256
- High9,258
- Medium5,266
- Low507
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2023-35082—100.0%
KEVR80Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability—CVE-2020-5902—100.0%
KEVR80F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability—CVE-2024-218938.2 HIG100.0%
KEVR80Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability27dCVE-2021-26084—100.0%
KEVR80Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability—CVE-2019-0708—100.0%
KEVR80Microsoft Remote Desktop Services Remote Code Execution Vulnerability—CVE-2024-23897—100.0%
KEVR80Jenkins Command Line Interface (CLI) Path Traversal Vulnerability—CVE-2023-444877.5 HIG100.0%
KEV—80HTTP/2 Rapid Reset Attack Vulnerability20dCVE-2021-451055.9 MED100.0%
——30Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.6dCVE-2023-06697.2 HIG100.0%
KEVR80Fortra GoAnywhere MFT Remote Code Execution Vulnerability25dCVE-2023-32315—100.0%
KEV—80Ignite Realtime Openfire Path Traversal Vulnerability—CVE-2017-9841—100.0%
KEV—80PHPUnit Command Injection Vulnerability—CVE-2019-197819.8 CRI100.0%
KEVR80Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability19dCVE-2021-404389.0 CRI100.0%
KEVR80Apache HTTP Server-Side Request Forgery (SSRF)25dCVE-2023-1671—100.0%
KEV—80Sophos Web Appliance Command Injection Vulnerability—CVE-2021-1498—100.0%
KEV—80Cisco HyperFlex HX Data Platform Command Injection Vulnerability—CVE-2021-219859.8 CRI100.0%
KEVR80VMware vCenter Server Improper Input Validation Vulnerability19dCVE-2024-3400—100.0%
KEVR80Palo Alto Networks PAN-OS Command Injection Vulnerability—CVE-2019-11510—100.0%
KEVR80Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability—CVE-2023-22518—100.0%
KEVR80Atlassian Confluence Data Center and Server Improper Authorization Vulnerability—CVE-2022-29464—100.0%
KEVR80WSO2 Multiple Products Unrestrictive Upload of File Vulnerability—CVE-2023-350789.8 CRI100.0%
KEVR80Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability26dCVE-2021-22005—100.0%
KEVR80VMware vCenter Server File Upload Vulnerability—CVE-2017-5638—100.0%
KEVR80Apache Struts Remote Code Execution Vulnerability—CVE-2021-4422810.0 CRI100.0%
KEVR80Apache Log4j2 Remote Code Execution Vulnerability20dCVE-2015-1635—100.0%
KEV—80Microsoft HTTP.sys Remote Code Execution Vulnerability—CVE-2024-218879.1 CRI100.0%
KEVR80Ivanti Connect Secure and Policy Secure Command Injection Vulnerability27dCVE-2021-26086—100.0%
KEV—80Atlassian Jira Server and Data Center Path Traversal Vulnerability—CVE-2023-27350—100.0%
KEVR80PaperCut MF/NG Improper Access Control Vulnerability—CVE-2014-6271—100.0%
KEV—80GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability—CVE-2022-26134—100.0%
KEVR80Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability—CVE-2014-3566—100.0%
——30——CVE-2018-13379—100.0%
KEVR80Fortinet FortiOS SSL VPN Path Traversal Vulnerability—CVE-2014-0160—100.0%
KEV—80OpenSSL Information Disclosure Vulnerability—CVE-2023-1389—100.0%
KEV—80TP-Link Archer AX-21 Command Injection Vulnerability—CVE-2021-344739.1 CRI100.0%
KEVR80Microsoft Exchange Server Remote Code Execution Vulnerability21dCVE-2021-35464—100.0%
KEVR80ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability—CVE-2023-49669.4 CRI100.0%
KEVR80Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability31dCVE-2013-2251—100.0%
KEV—80Apache Struts Improper Input Validation Vulnerability—CVE-2012-1823—100.0%
KEV—80PHP-CGI Query String Parameter Vulnerability—CVE-2017-7921—100.0%
KEV—80Hikvision Multiple Products Improper Authentication Vulnerability—