Top KEV by EPSS percentile

EPSS 0.744 • 99th pct

No description.

WatchGuard
Firebox
EPSS 0.174 • 95th pct

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) o...

Citrix
NetScaler
EPSS 0.146 • 94th pct

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9.This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/N...

TP-Link
Multiple Routers
EPSS 0.139 • 94th pct

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

N-able
N-Central
EPSS 0.051 • 89th pct

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

N-able
N-Central
EPSS 0.032 • 86th pct

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovere...

RARLAB
WinRAR
EPSS 0.000 • 0th pct

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a...

Microsoft
Windows
EPSS 0.000 • 0th pct

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

Microsoft
Windows
EPSS 0.000 • 0th pct

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

Cisco
IOS
EPSS 0.000 • 0th pct

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl...

Hewlett Packard (HP)
OpenView Network Node Manager
EPSS 0.000 • 0th pct

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references t...

Apache
Struts 1
EPSS 0.000 • 0th pct

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object po...

Microsoft
Word
EPSS 0.000 • 0th pct

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonst...

Microsoft
Office
EPSS 0.000 • 0th pct

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during...

Alcatel
OmniPCX Enterprise
EPSS 0.000 • 0th pct

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be...

Adobe
Acrobat and Reader

High EPSS not in KEV

EPSS 0.658 • 98th pct

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks ro...

Trending PoCs

StarsUpdatedNameDescription
1241 2 hours ago CVE-2025-55182 Explanation and full RCE PoC for CVE-2025-55182
775 3 hours ago CVE-2025-55182-research CVE-2025-55182 POC
495 8 days ago CVE-2018-20250 exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
607 20 hours ago CVE-2025-33073 PoC Exploit for the NTLM reflection SMB flaw.
496 4 days ago CVE-2025-32463_chwoot Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
419 5 hours ago CVE-2025-32463 Local Privilege Escalation to Root via Sudo chroot in Linux
305 1 day ago CVE-2025-53770-Exploit SharePoint WebPart Injection Exploit Tool
289 4 hours ago CVE-2025-55182 RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478
901 1 hour ago React2Shell-CVE-2025-55182-original-poc Original Proof-of-Concepts for React2Shell CVE-2025-55182
386 4 days ago CVE-2025-24071_PoC CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
207 1 day ago CVE-2025-32023 PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
396 6 days ago ColorOS-CVE-2025-10184 ColorOS短信漏洞,以及用户自救方案
180 6 days ago POC-CVE-2025-24813 his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
256 15 minutes ago CVE-2025-55182-advanced-scanner-
357 1 hour ago Next.js-RSC-RCE-Scanner-CVE-2025-66478 A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
198 4 days ago CVE-2025-30208-EXP CVE-2025-30208-EXP
73 6 days ago cve-2025-8088 Path traversal tool based on cve-2025-8088
163 1 day ago CVE-2025-26125 ( 0day ) Local Privilege Escalation in IObit Malware Fighter
153 8 days ago CVE-2025-21756 Exploit for CVE-2025-21756 for Linux kernel 6.6.75. My first linux kernel exploit!
136 27 days ago CVE-2025-32433 CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

Changes since yesterday

TypeCountExamples
New KEV entries 75 CVE-2025-9242, CVE-2025-7775, CVE-2025-9377, CVE-2025-8876, CVE-2025-8875
New high EPSS 2 CVE-2025-9316, CVE-2025-8943
Top EPSS movers 0 None