EPSS
Track exploitation-probability changes and high-likelihood CVEs.
Low-probability majorityScale: all EPSS-active CVEs
Elevated-probability tail · ≥10%4,375 CVEs · 1.6% / Scale: tail maximum
Bar length = count within each labeled scalePercentages = share of all 267K EPSS-active CVEsAverage score = 2.0%Values use last 7 days
Click a bar to inspect matching CVEs
Largest movers
Last 7 days
The largest positive EPSS changes in the selected 7-day time period. Tracks show each previous score and current score.
| # | CVE | Vendor | Date | EPSS movement | Change | CVSS | Signals |
|---|---|---|---|---|---|---|---|
| 1 | CVE-2016-3251 | n/a | 2026-09-01 | 3% 58% | +55 pts | — | |
| 2 | CVE-2017-3191 | D-Link | 2026-09-01 | 14% 63% | +48 pts | — | |
| 3 | CVE-2018-0258 | n/a | 2026-09-01 | 6% 49% | +43 pts | — | |
| 4 | CVE-2017-9829 | n/a | 2026-09-01 | 28% 69% | +41 pts | — | |
| 5 | CVE-2018-3924 | Foxit | 2026-09-01 | 3% 44% | +41 pts | 8.8 | |
| 6 | CVE-2016-3272 | n/a | 2026-09-01 | 3% 43% | +40 pts | — | |
| 7 | CVE-2019-7111 | Adobe | 2026-09-01 | 16% 54% | +39 pts | — | |
| 8 | CVE-2016-6603 | n/a | 2026-09-01 | 49% 87% | +38 pts | — | |
| 9 | CVE-2018-16283 | n/a | 2026-09-01 | 25% 63% | +38 pts | — | |
| 10 | CVE-2015-5259 | n/a | 2026-09-01 | 19% 57% | +38 pts | — |
High EPSS, not yet exploited
Last 7 days
Highest current exploitation probabilities among CVEs updated in the selected 7-day time period without confirmed exploitation.
| # | CVE | Description | CVSS | EPSS | Signals |
|---|---|---|---|---|---|
| 1 | CVE-2023-32560 | An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.
Thanks to a Researcher at Tenable for finding and reporting.
Fixed in version 6.4.1. | 8.8 | 99% | PoC |
| 2 | CVE-2024-29895 | Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc. | 10 | 98% | |
| 3 | CVE-2025-4123 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.
The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive. | 7.6 | 97% | PoC |
| 4 | CVE-2024-10914 | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. | 9.2 | 96% | PoC |
| 5 | CVE-2022-2068 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze). | 9.8 | 96% | |
| 6 | CVE-2019-11478 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e. | 5.3 | 95% | |
| 7 | CVE-2017-5753 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | 5.6 | 94% | PoC |
| 8 | CVE-2021-41349 | Microsoft Exchange Server Spoofing Vulnerability | 6.5 | 93% | Patch |
| 9 | CVE-2024-2389 | In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
| 10 | 93% | |
| 10 | CVE-2023-28302 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 7.5 | 93% | Patch |