1,734 totalEPSS avg 50.3%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,734 of 1,734 · page 10 of 35

CVEVendor / ProductTitleKEV addedEPSS
CVE-2022-43769Hitachi Vantara / Pentaho Business Analytics (BA) ServerHitachi Vantara Pentaho BA Server Special Element Injection Vulnerability2025-03-03
97.7%
CVE-2022-43939Hitachi Vantara / Pentaho Business Analytics (BA) ServerHitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability2025-03-03
92.3%
CVE-2023-20118Cisco / Small Business RV Series RoutersCisco Small Business RV Series Routers Command Injection Vulnerability2025-03-03
54.1%
CVE-2024-4885Progress / WhatsUp GoldProgress WhatsUp Gold Path Traversal Vulnerability2025-03-03
99.3%
CVE-2023-34192Synacor / Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerabi…2025-02-25
77.3%
CVE-2024-49035Microsoft / Partner CenterMicrosoft Partner Center Improper Access Control Vulnerability2025-02-25
1.3%
CVE-2017-3066Adobe / ColdFusionAdobe ColdFusion Deserialization Vulnerability2025-02-24
90.6%
CVE-2024-20953Oracle / Agile Product Lifecycle Management (PLM)Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability2025-02-24
3.9%
CVE-2025-24989Microsoft / Power PagesMicrosoft Power Pages Improper Access Control Vulnerability2025-02-21
1.6%
CVE-2025-0111Palo Alto Networks / PAN-OSPalo Alto Networks PAN-OS File Read Vulnerability2025-02-20
2.0%
CVE-2025-23209Craft CMS / Craft CMSCraft CMS Code Injection Vulnerability2025-02-20
21.8%
CVE-2024-53704SonicWall / SonicOSSonicWall SonicOS SSLVPN Improper Authentication Vulnerability2025-02-18
95.1%
CVE-2025-0108Palo Alto Networks / PAN-OSPalo Alto Networks PAN-OS Authentication Bypass Vulnerability2025-02-18
98.5%
CVE-2024-57727SimpleHelp / SimpleHelpSimpleHelp Path Traversal Vulnerability2025-02-13
96.6%
CVE-2024-41710Mitel / SIP PhonesMitel SIP Phones Argument Injection Vulnerability2025-02-12
41.6%
CVE-2025-24200Apple / iOS and iPadOSApple iOS and iPadOS Incorrect Authorization Vulnerability2025-02-12
4.4%
CVE-2024-40890Zyxel / DSL CPE DevicesZyxel DSL CPE OS Command Injection Vulnerability2025-02-11
20.7%
CVE-2024-40891Zyxel / DSL CPE DevicesZyxel DSL CPE OS Command Injection Vulnerability2025-02-11
21.5%
CVE-2025-21391Microsoft / WindowsMicrosoft Windows Storage Link Following Vulnerability2025-02-11
2.3%
CVE-2025-21418Microsoft / WindowsMicrosoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Ove…2025-02-11
1.6%
CVE-2025-0994Trimble / CityworksTrimble Cityworks Deserialization Vulnerability2025-02-07
31.1%
CVE-2020-15069Sophos / XG FirewallSophos XG Firewall Buffer Overflow Vulnerability2025-02-06
10.7%
CVE-2020-29574Sophos / CyberoamOSCyberoamOS (CROS) SQL Injection Vulnerability2025-02-06
4.7%
CVE-2022-23748Audinate / Dante DiscoveryDante Discovery Process Control Vulnerability2025-02-06
9.1%
CVE-2024-21413Microsoft / Office OutlookMicrosoft Outlook Improper Input Validation Vulnerability2025-02-06
94.7%
CVE-2025-04117-Zip / 7-Zip7-Zip Mark of the Web Bypass Vulnerability2025-02-06
67.1%
CVE-2024-53104Linux / KernelLinux Kernel Out-of-Bounds Write Vulnerability2025-02-05
3.4%
CVE-2018-19410Paessler / PRTG Network MonitorPaessler PRTG Network Monitor Local File Inclusion Vulnerability2025-02-04
97.9%
CVE-2018-9276Paessler / PRTG Network MonitorPaessler PRTG Network Monitor OS Command Injection Vulnerability2025-02-04
87.0%
CVE-2024-29059Microsoft / .NET FrameworkMicrosoft .NET Framework Information Disclosure Vulnerability2025-02-04
98.6%
CVE-2024-45195Apache / OFBizApache OFBiz Forced Browsing Vulnerability2025-02-04
100.0%
CVE-2025-24085Apple / Multiple ProductsApple Multiple Products Use-After-Free Vulnerability2025-01-29
17.5%
CVE-2025-23006SonicWall / SMA1000 AppliancesSonicWall SMA1000 Appliances Deserialization Vulnerability2025-01-24
23.4%
CVE-2020-11023JQuery / JQueryJQuery Cross-Site Scripting (XSS) Vulnerability2025-01-23
84.9%
CVE-2024-50603Aviatrix / ControllersAviatrix Controllers OS Command Injection Vulnerability2025-01-16
98.5%
CVE-2024-55591Fortinet / FortiOS and FortiProxyFortinet FortiOS and FortiProxy Authentication Bypass Vulnerability2025-01-14
94.1%
CVE-2025-21333Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflo…2025-01-14
10.0%
CVE-2025-21334Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability2025-01-14
1.6%
CVE-2025-21335Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability2025-01-14
1.4%
CVE-2023-48365Qlik / SenseQlik Sense HTTP Tunneling Vulnerability2025-01-13
47.5%
CVE-2024-12686BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS)BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command…2025-01-13
13.7%
CVE-2025-0282Ivanti / Connect Secure, Policy Secure, and ZTA GatewaysIvanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Ove…2025-01-08
100.0%
CVE-2020-2883Oracle / WebLogic ServerOracle WebLogic Server Unspecified Vulnerability2025-01-07
94.9%
CVE-2024-41713Mitel / MiCollabMitel MiCollab Path Traversal Vulnerability2025-01-07
98.1%
CVE-2024-55550Mitel / MiCollabMitel MiCollab Path Traversal Vulnerability2025-01-07
38.2%
CVE-2024-3393Palo Alto Networks / PAN-OSPalo Alto Networks PAN-OS Malicious DNS Packet Vulnerability2024-12-30
29.1%
CVE-2021-44207Acclaim Systems / USAHERDSAcclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability 2024-12-23
17.6%
CVE-2024-12356BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command In…2024-12-19
87.3%
CVE-2018-14933NUUO / NVRmini DevicesNUUO NVRmini Devices OS Command Injection Vulnerability 2024-12-18
94.9%
CVE-2019-11001Reolink / Multiple IP CamerasReolink Multiple IP Cameras OS Command Injection Vulnerability2024-12-18
37.5%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.