1,619 totalEPSS avg 51.6%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,619 of 1,619 · page 3 of 33

CVEVendor / ProductTitleKEV addedEPSS
CVE-2026-2441Google / ChromiumGoogle Chromium CSS Use-After-Free Vulnerability2026-02-17
22.0%
CVE-2026-1731BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command…2026-02-13
86.1%
CVE-2024-43468Microsoft / Configuration ManagerMicrosoft Configuration Manager SQL Injection Vulnerability2026-02-12
60.7%
CVE-2025-15556Notepad++ / Notepad++Notepad++ Download of Code Without Integrity Check Vulnerability2026-02-12
1.3%
CVE-2025-40536SolarWinds / Web Help DeskSolarWinds Web Help Desk Security Control Bypass Vulnerability2026-02-12
81.6%
CVE-2026-20700Apple / Multiple ProductsApple Multiple Buffer Overflow Vulnerability2026-02-12
1.3%
CVE-2026-21510Microsoft / WindowsMicrosoft Windows Shell Protection Mechanism Failure Vulnerability2026-02-10
25.8%
CVE-2026-21513Microsoft / WindowsMicrosoft MSHTML Framework Protection Mechanism Failure Vulnerability2026-02-10
15.4%
CVE-2026-21514Microsoft / OfficeMicrosoft Office Word Reliance on Untrusted Inputs in a Security Decision Vul…2026-02-10
1.5%
CVE-2026-21519Microsoft / WindowsMicrosoft Windows Type Confusion Vulnerability2026-02-10
2.4%
CVE-2026-21525Microsoft / WindowsMicrosoft Windows NULL Pointer Dereference Vulnerability2026-02-10
5.0%
CVE-2026-21533Microsoft / WindowsMicrosoft Windows Improper Privilege Management Vulnerability2026-02-10
3.8%
CVE-2025-11953React Native Community / CLIReact Native Community CLI OS Command Injection Vulnerability2026-02-05
61.9%
CVE-2026-24423SmarterTools / SmarterMailSmarterTools SmarterMail Missing Authentication for Critical Function Vulnera…2026-02-05
87.7%
CVE-2019-19006sangoma / freepbxCVE-2019-190062026-02-03
35.8%
CVE-2021-39935GitLab / Community and Enterprise EditionsGitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) V…2026-02-03
30.5%
CVE-2025-40551SolarWinds / Web Help DeskSolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability2026-02-03
84.1%
CVE-2025-64328Sangoma / FreePBX Sangoma FreePBX OS Command Injection Vulnerability2026-02-03
84.1%
CVE-2026-1281Ivanti / Endpoint Manager Mobile (EPMM)Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability2026-01-29
81.2%
CVE-2026-24858Fortinet / Multiple ProductsFortinet Multiple Products Authentication Bypass Using an Alternate Path or C…2026-01-27
55.1%
CVE-2018-14634Linux / KernelLinux Kernel Integer Overflow Vulnerability2026-01-26
14.8%
CVE-2025-52691SmarterTools / SmarterMailSmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vuln…2026-01-26
85.5%
CVE-2026-21509Microsoft / OfficeMicrosoft Office Security Feature Bypass Vulnerability2026-01-26
72.2%
CVE-2026-23760SmarterTools / SmarterMailSmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Cha…2026-01-26
96.3%
CVE-2026-24061GNU / InetUtilsGNU InetUtils Argument Injection Vulnerability2026-01-26
98.9%
CVE-2024-37079Broadcom / VMware vCenter ServerBroadcom VMware vCenter Server Out-of-bounds Write Vulnerability2026-01-23
22.4%
CVE-2025-31125Vite / VitejsVite Vitejs Improper Access Control Vulnerability2026-01-22
59.6%
CVE-2025-34026Versa / ConcertoVersa Concerto Improper Authentication Vulnerability2026-01-22
83.4%
CVE-2025-54313Prettier / eslint-config-prettierPrettier eslint-config-prettier Embedded Malicious Code Vulnerability2026-01-22
4.1%
CVE-2025-68645Synacor / Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability2026-01-22
31.8%
CVE-2026-20045Cisco / Unified Communications ManagerCisco Unified Communications Products Code Injection Vulnerability2026-01-21
4.3%
CVE-2026-20805Microsoft / WindowsMicrosoft Windows Information Disclosure Vulnerability2026-01-13
5.0%
CVE-2025-8110Gogs / GogsGogs Path Traversal Vulnerability2026-01-12
76.9%
CVE-2009-0556Microsoft / OfficeMicrosoft Office PowerPoint Code Injection Vulnerability2026-01-07
67.5%
CVE-2025-37164Hewlett Packard Enterprise (HPE) / OneViewHewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability2026-01-07
89.7%
CVE-2025-14847MongoDB / MongoDB and MongoDB ServerMongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistenc…2025-12-29
83.0%
CVE-2023-52163Digiever / DS-2105 ProDigiever DS-2105 Pro Missing Authorization Vulnerability2025-12-22
96.3%
CVE-2025-14733WatchGuard / FireboxWatchGuard Firebox Out of Bounds Write Vulnerability2025-12-19
17.5%
CVE-2025-20393Cisco / Multiple ProductsCisco Multiple Products Improper Input Validation Vulnerability2025-12-17
29.1%
CVE-2025-40602SonicWall / SMA1000 applianceSonicWall SMA1000 Missing Authorization Vulnerability2025-12-17
1.9%
CVE-2025-59374ASUS / Live UpdateASUS Live Update Embedded Malicious Code Vulnerability2025-12-17
1.1%
CVE-2025-59718Fortinet / Multiple ProductsFortinet Multiple Products Improper Verification of Cryptographic Signature V…2025-12-16
63.5%
CVE-2025-14611Gladinet / CentreStack and TriofoxGladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability2025-12-15
50.9%
CVE-2025-43529Apple / Multiple ProductsApple Multiple Products Use-After-Free WebKit Vulnerability2025-12-15
8.0%
CVE-2018-4063Sierra Wireless / AirLink ALEOSSierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type…2025-12-12
28.1%
CVE-2025-14174Google / ChromiumGoogle Chromium Out of Bounds Memory Access Vulnerability2025-12-12
22.2%
CVE-2025-58360OSGeo / GeoServerOSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnera…2025-12-11
66.8%
CVE-2025-6218RARLAB / WinRARRARLAB WinRAR Path Traversal Vulnerability2025-12-09
81.5%
CVE-2025-62221Microsoft / WindowsMicrosoft Windows Use After Free Vulnerability2025-12-09
2.3%
CVE-2022-37055D-Link / RoutersD-Link Routers Buffer Overflow Vulnerability2025-12-08
57.0%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.