1,734 totalEPSS avg 50.3%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,734 of 1,734 · page 2 of 35

CVEVendor / ProductTitleKEV addedEPSS
CVE-2026-53362Linux / KernelLinux Kernel Unspecified Vulnerability2026-08-27
0.7%
CVE-2026-66384JFrog / ArtifactoryJFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory…2026-08-27
0.7%
CVE-2015-3246Red Hat / LibuserRed Hat Libuser Race Condition Vulnerability2026-08-26
8.4%
CVE-2015-5287Red Hat / Automatic Bug Reporting ToolRed Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability2026-08-26
5.0%
CVE-2019-1068Microsoft / SQL ServerMicrosoft SQL Server Remote Code Execution Vulnerability2026-08-26
57.0%
CVE-2021-23758Ajax.NET Professional / Ajax.NET ProfessionalAjax.NET Professional Deserialization of Untrusted Data Vulnerability2026-08-26
82.6%
CVE-2022-0995Linux / KernelLinux Kernel Out-of-Bounds Write Vulnerability2026-08-26
8.8%
CVE-2026-8452Citrix / NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations…2026-08-26
1.0%
CVE-2026-60004Gitea / GiteaGitea Code Injection Vulnerability2026-08-25
24.0%
CVE-2026-21962Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-inOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access C…2026-08-24
73.2%
CVE-2026-73570Synacor / Zimbra Collaboration Suite (ZCS)Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability2026-08-21
11.9%
CVE-2026-72529TrueConf / ServerTrueConf Server Missing Authentication for Critical Function Vulnerability2026-08-20
1.5%
CVE-2026-72530TrueConf / ServerTrueConf Server Code Injection Vulnerability2026-08-20
1.7%
CVE-2026-64849lfprojects / mlflowCVE-2026-648492026-08-19
9.8%
CVE-2026-33824Microsoft / Internet Key Exchange (IKE) Service ExtensionsMicrosoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerab…2026-08-18
1.6%
CVE-2026-55040Microsoft / SharePointMicrosoft SharePoint Weak Authentication Vulnerability2026-08-18
69.5%
CVE-2026-59310Broadcom / VMware vCenterBroadcom VMware vCenter Path Traversal Vulnerability2026-08-18
2.6%
CVE-2026-65400Apple / macOSApple macOS Improper Authentication Vulnerability2026-08-18
1.7%
CVE-2025-62593Ray-Project / RayRay-Project Ray Code Injection Vulnerability2026-08-17
62.5%
CVE-2026-20349Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall T…2026-08-11
1.0%
CVE-2026-68820Microsoft / Windows Ancillary Function Driver for WinSock Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulner…2026-08-11
0.3%
CVE-2026-72898Metabase / MetabaseMetabase SQL Injection Vulnerability2026-08-11
19.0%
CVE-2026-8037Progress / LoadMasterProgress LoadMaster Command Injection Vulnerability2026-08-07
77.4%
CVE-2026-63077JetBrains / TeamCityJetBrains TeamCity Deserialization of Untrusted Data Vulnerability2026-08-05
89.6%
CVE-2026-18556N-able / N-centralN-able N-central Authentication Bypass Using an Alternate Path or Channel Vul…2026-08-04
7.9%
CVE-2026-34486Apache / TomcatApache Tomcat Missing Encryption of Sensitive Data Vulnerability2026-08-04
6.6%
CVE-2026-9198IBM / LangflowIBM Langflow Code Injection Vulnerability2026-08-04
28.7%
CVE-2026-18577N-able / N-centralN-able N-central Authentication Bypass Using an Alternate Path or Channel Vul…2026-08-03
14.6%
CVE-2026-20316Cisco / Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability2026-07-29
35.1%
CVE-2025-68686Fortinet / FortiOSFortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor V…2026-07-27
29.6%
CVE-2026-16812Arista / VeloCloud OrchestratorArista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability2026-07-27
1.0%
CVE-2026-16232Check Point / SmartConsoleCheck Point SmartConsole Improper Authentication Vulnerability2026-07-22
78.0%
CVE-2026-50522Microsoft / SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability 2026-07-22
3.0%
CVE-2021-27137DD-WRT / DD-WRTDD-WRT Stack-Based Buffer Overflow Vulnerability2026-07-21
4.0%
CVE-2026-0770Langflow / LangflowLangflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability2026-07-21
63.0%
CVE-2026-60137WordPress / CoreWordPress Core SQL Injection Vulnerability2026-07-21
5.9%
CVE-2026-63030WordPress / CoreWordPress Core Interpretation Conflict Vulnerability2026-07-21
10.1%
CVE-2026-25089Fortinet / FortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability2026-07-16
76.1%
CVE-2026-39808Fortinet / FortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability2026-07-16
47.4%
CVE-2026-58644Microsoft / SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability2026-07-16
15.9%
CVE-2023-4346KNX Association / KNX Protocol Connection Authorization Option 1KNX Association KNX Protocol Connection Authorization Option 1 Overly Restric…2026-07-15
1.3%
CVE-2026-46817Oracle / E-Business SuiteOracle E-Business Suite Improper Privilege Management Vulnerability2026-07-15
0.8%
CVE-2026-15409SonicWall / SMA1000 AppliancesSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability2026-07-14
6.8%
CVE-2026-15410SonicWall / SMA1000 AppliancesSonicWall SMA1000 Appliances Code Injection Vulnerability2026-07-14
11.8%
CVE-2026-56155Microsoft / Active Directory Federation ServicesMicrosoft Active Directory Federation Services Insufficient Granularity of Ac…2026-07-14
0.3%
CVE-2026-56164Microsoft / SharePoint ServerMicrosoft SharePoint Server Missing Authentication for Critical Function Vuln…2026-07-14
1.0%
CVE-2008-4128Cisco / IOSCisco IOS Cross-Site Request Forgery Vulnerability2026-07-13
33.9%
CVE-2026-48939iCagenda / iCagendaiCagenda Unrestricted Upload of File with Dangerous Type Vulnerability2026-07-10
20.1%
CVE-2026-56291Balbooa / FormsBalbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability2026-07-10
14.9%
CVE-2026-48282Adobe / ColdFusionAdobe ColdFusion Path Traversal Vulnerability2026-07-07
42.4%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.