1,619 totalEPSS avg 51.6%

KEVKnown Exploited Vulnerabilities

CISA’s actively-exploited catalogue · refreshed weekly · authored by Adam Lundqvist

Showing 1,619 of 1,619 · page 8 of 33

CVEVendor / ProductTitleKEV addedEPSS
CVE-2025-24200Apple / iOS and iPadOSApple iOS and iPadOS Incorrect Authorization Vulnerability2025-02-12
4.9%
CVE-2024-40890Zyxel / DSL CPE DevicesZyxel DSL CPE OS Command Injection Vulnerability2025-02-11
19.3%
CVE-2024-40891Zyxel / DSL CPE DevicesZyxel DSL CPE OS Command Injection Vulnerability2025-02-11
20.5%
CVE-2025-21391Microsoft / WindowsMicrosoft Windows Storage Link Following Vulnerability2025-02-11
2.1%
CVE-2025-21418Microsoft / WindowsMicrosoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Ove…2025-02-11
1.5%
CVE-2025-0994Trimble / CityworksTrimble Cityworks Deserialization Vulnerability2025-02-07
27.4%
CVE-2020-15069Sophos / XG FirewallSophos XG Firewall Buffer Overflow Vulnerability2025-02-06
10.7%
CVE-2020-29574Sophos / CyberoamOSCyberoamOS (CROS) SQL Injection Vulnerability2025-02-06
4.7%
CVE-2022-23748Audinate / Dante DiscoveryDante Discovery Process Control Vulnerability2025-02-06
9.1%
CVE-2024-21413Microsoft / Office OutlookMicrosoft Outlook Improper Input Validation Vulnerability2025-02-06
94.7%
CVE-2025-04117-Zip / 7-Zip7-Zip Mark of the Web Bypass Vulnerability2025-02-06
65.9%
CVE-2024-53104Linux / KernelLinux Kernel Out-of-Bounds Write Vulnerability2025-02-05
3.3%
CVE-2018-19410Paessler / PRTG Network MonitorPaessler PRTG Network Monitor Local File Inclusion Vulnerability2025-02-04
85.7%
CVE-2018-9276Paessler / PRTG Network MonitorPaessler PRTG Network Monitor OS Command Injection Vulnerability2025-02-04
86.9%
CVE-2024-29059Microsoft / .NET FrameworkMicrosoft .NET Framework Information Disclosure Vulnerability2025-02-04
98.8%
CVE-2024-45195Apache / OFBizApache OFBiz Forced Browsing Vulnerability2025-02-04
100.0%
CVE-2025-24085Apple / Multiple ProductsApple Multiple Products Use-After-Free Vulnerability2025-01-29
19.7%
CVE-2025-23006SonicWall / SMA1000 AppliancesSonicWall SMA1000 Appliances Deserialization Vulnerability2025-01-24
22.3%
CVE-2020-11023JQuery / JQueryJQuery Cross-Site Scripting (XSS) Vulnerability2025-01-23
83.8%
CVE-2024-50603Aviatrix / ControllersAviatrix Controllers OS Command Injection Vulnerability2025-01-16
98.5%
CVE-2024-55591Fortinet / FortiOS and FortiProxyFortinet FortiOS and FortiProxy Authentication Bypass Vulnerability2025-01-14
98.2%
CVE-2025-21333Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflo…2025-01-14
9.8%
CVE-2025-21334Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability2025-01-14
1.5%
CVE-2025-21335Microsoft / WindowsMicrosoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability2025-01-14
1.4%
CVE-2023-48365Qlik / SenseQlik Sense HTTP Tunneling Vulnerability2025-01-13
24.7%
CVE-2024-12686BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS)BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command…2025-01-13
13.8%
CVE-2025-0282Ivanti / Connect Secure, Policy Secure, and ZTA GatewaysIvanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Ove…2025-01-08
100.0%
CVE-2020-2883Oracle / WebLogic ServerOracle WebLogic Server Unspecified Vulnerability2025-01-07
94.9%
CVE-2024-41713Mitel / MiCollabMitel MiCollab Path Traversal Vulnerability2025-01-07
98.1%
CVE-2024-55550Mitel / MiCollabMitel MiCollab Path Traversal Vulnerability2025-01-07
37.5%
CVE-2024-3393Palo Alto Networks / PAN-OSPalo Alto Networks PAN-OS Malicious DNS Packet Vulnerability2024-12-30
26.6%
CVE-2021-44207Acclaim Systems / USAHERDSAcclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability 2024-12-23
17.6%
CVE-2024-12356BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command In…2024-12-19
88.0%
CVE-2018-14933NUUO / NVRmini DevicesNUUO NVRmini Devices OS Command Injection Vulnerability 2024-12-18
93.7%
CVE-2019-11001Reolink / Multiple IP CamerasReolink Multiple IP Cameras OS Command Injection Vulnerability2024-12-18
38.4%
CVE-2021-40407Reolink / RLC-410W IP CameraReolink RLC-410W IP Camera OS Command Injection Vulnerability 2024-12-18
47.9%
CVE-2022-23227NUUO / NVRmini2 DevicesNUUO NVRmini2 Devices Missing Authentication Vulnerability 2024-12-18
49.4%
CVE-2024-55956Cleo / Multiple ProductsCleo Multiple Products Unauthenticated File Upload Vulnerability2024-12-17
93.8%
CVE-2024-20767Adobe / ColdFusionAdobe ColdFusion Improper Access Control Vulnerability2024-12-16
98.5%
CVE-2024-35250Microsoft / WindowsMicrosoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerabil…2024-12-16
25.2%
CVE-2024-50623Cleo / Multiple ProductsCleo Multiple Products Unrestricted File Upload Vulnerability2024-12-13
98.5%
CVE-2024-49138Microsoft / WindowsMicrosoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Over…2024-12-10
25.4%
CVE-2024-51378CyberPersons / CyberPanelCyberPanel Incorrect Default Permissions Vulnerability2024-12-04
94.9%
CVE-2023-45727North Grid / ProselfNorth Grid Proself Improper Restriction of XML External Entity (XXE) Referenc…2024-12-03
3.5%
CVE-2024-11667Zyxel / Multiple FirewallsZyxel Multiple Firewalls Path Traversal Vulnerability2024-12-03
3.0%
CVE-2024-11680ProjectSend / ProjectSendProjectSend Improper Authentication Vulnerability2024-12-03
91.6%
CVE-2023-28461Array Networks / AG/vxAG ArrayOSArray Networks AG and vxAG ArrayOS Missing Authentication for Critical Functi…2024-11-25
67.6%
CVE-2024-21287Oracle / Agile Product Lifecycle Management (PLM)Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulne…2024-11-21
1.5%
CVE-2024-44308Apple / Multiple ProductsApple Multiple Products Code Execution Vulnerability2024-11-21
9.2%
CVE-2024-44309Apple / Multiple ProductsApple Multiple Products Cross-Site Scripting (XSS) Vulnerability2024-11-21
21.0%
Sourced from CISA Known Exploited Vulnerabilities — current weekly refresh. EPSS scores from FIRST.org via epss.cyentia.com. Curated by Adam Lundqvist, Founder at SQUR.