Every vulnerability CISA says is exploited in the wild, joined with what the internet can reach and how likely exploitation is this month. 2026-09-26.
The short list
49 vulnerabilities added in the last 90 days, reachable from the internet without credentials, and in the top 10% by near-term exploitation probability.
That is the list to work through. It is 9% of the catalog, which is the point: most known-exploited vulnerabilities are not urgent, and a flat list sorted by severity cannot tell you which ones are.
Added to KEV in the last 90 days, AV:N with PR:N - so no credentials - and an EPSS percentile at or above 0.9.
| CVE | CVSS | EPSS | Exploited |
|---|---|---|---|
| CVE-2026-85706GitLab / Community Edition and Enterprise Edition | 10.0 | 0.9143top 1% | 16d |
| CVE-2026-48908JoomShaper / SP Page Builder | 10.0 | 0.8851top 1% | 82d |
| CVE-2026-20079Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 10.0 | 0.8818top 1% | 18d |
| CVE-2026-71362Adobe / Commerce and Magento | 9.1 | 0.8751top 1% | 3d |
| CVE-2021-23758Ajax.NET Professional / Ajax.NET Professional | 8.1 | 0.8258top 1% | 32d |
| CVE-2026-16232Check Point / SmartConsole | 9.3 | 0.7797top 1% | 67d |
| CVE-2026-25089Fortinet / FortiSandbox | 9.8 | 0.7611top 1% | 73d |
| CVE-2026-21962Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in | 10.0 | 0.7091top 1% | 34d |
| CVE-2026-0770Langflow / Langflow | 9.8 | 0.6384top 1% | 68d |
| CVE-2025-62593Ray-Project / Ray | 9.4 | 0.6246top 1% | 41d |
| CVE-2026-85046Google / Chromium V8 | 8.8 | 0.4888top 5% | 23d |
| CVE-2026-39808Fortinet / FortiSandbox | 9.8 | 0.4736top 5% | 73d |
| CVE-2023-49105ownCloud / ownCloud | 9.8 | 0.4292top 5% | 31d |
| CVE-2026-48282Adobe / ColdFusion | 10.0 | 0.4239top 5% | 82d |
| CVE-2026-20316Cisco / Secure Firewall Management Center (FMC) | 5.3 | 0.3510top 5% | 60d ransomware |
| CVE-2008-4128Cisco / IOS | 8.1 | 0.3387top 5% | 76d |
| CVE-2026-56290Joomlack / Page Builder | 10.0 | 0.3087top 5% | 82d |
| CVE-2025-68686Fortinet / FortiOS | 5.9 | 0.2960top 5% | 62d |
| CVE-2026-9198IBM / Langflow | 9.8 | 0.2866top 5% | 54d |
| CVE-2026-76461Cisco / Secure Email Gateway | 9.8 | 0.2827top 5% | 13d |
| CVE-2026-60004Gitea / Gitea | 9.8 | 0.2399top 5% | 33d |
| CVE-2026-48939iCagenda / iCagenda | 10.0 | 0.2007top 5% | 79d |
| CVE-2026-93616Check Point / Multiple Products | 9.8 | 0.1965top 5% | 5d |
| CVE-2026-72898Metabase / Metabase | 10.0 | 0.1905top 5% | 47d |
| CVE-2026-9586Sangoma / Switchvox | 9.3 | 0.1898top 5% | 25d |
| CVE-2026-87902WordPress / Core | 8.1 | 0.1817top 5% | 2d |
| CVE-2026-55040Microsoft / SharePoint | 9.1 | 0.1754top 5% | 40d |
| CVE-2026-58644Microsoft / SharePoint | 9.8 | 0.1587top 5% | 73d |
| CVE-2026-56291Balbooa / Forms | 10.0 | 0.1485top 5% | 79d |
| CVE-2026-18577N-able / N-central | 8.2 | 0.1462top 5% | 55d |
| CVE-2026-82329JFrog / Artifactory | 9.8 | 0.1412top 5% | 25d |
| CVE-2026-76460Cisco / Identity Services Engine | 10.0 | 0.1403top 5% | 11d |
| CVE-2026-86218N-able / N-central | 10.0 | 0.1293top 5% | 19d |
| CVE-2026-73570Synacor / Zimbra Collaboration Suite (ZCS) | 8.9 | 0.1174top 5% | 37d |
| CVE-2026-63030WordPress / Core | 9.8 | 0.1012top 5% | 68d |
| CVE-2026-64849MLflow / MLflow | 9.3 | 0.0984top 5% | 39d |
| CVE-2026-42018JFrog / Artifactory | 7.5 | 0.0980top 5% | 16d |
| CVE-2026-63077JetBrains / TeamCity | 9.8 | 0.0976top 5% | 53d ransomware |
| CVE-2026-83548SonicWall / SMA1000 Appliances | 10.0 | 0.0876top 10% | 25d |
| CVE-2026-18556N-able / N-central | 8.2 | 0.0788top 10% | 54d |
| CVE-2026-48710Kludex / Starlette | 6.5 | 0.0706top 10% | 25d |
| CVE-2026-19490Citrix / NetScaler | 9.3 | 0.0701top 10% | 18d |
| CVE-2026-15409SonicWall / SMA1000 Appliances | 10.0 | 0.0679top 10% | 75d ransomware |
| CVE-2026-34486Apache / Tomcat | 7.5 | 0.0656top 10% | 54d |
| CVE-2026-60137WordPress / Core | 5.9 | 0.0591top 10% | 68d |
| CVE-2026-48558SimpleHelp / SimpleHelp | 9.5 | 0.0572top 10% | 90d |
| CVE-2026-81578PaperCut / NG/MF | 8.8 | 0.0448top 10% | 27d |
| CVE-2021-27137DD-WRT / DD-WRT | 8.1 | 0.0399top 10% | 68d |
| CVE-2026-75650Adobe / Commerce and Magento | 10.0 | 0.0395top 10% | 19d |
A list sorted by CVSS score puts a vulnerability exploited for six years above one found last week. For someone deciding what to do on a Monday, that is backwards.
| 0-30 days exploited | 41 CVEs |
|---|---|
| 31-90 days exploited | 56 CVEs |
| 91-180 days exploited | 74 CVEs |
| 181-365 days exploited | 138 CVEs |
| 366-730 days exploited | 236 CVEs |
| 730+ days exploited | 1181 CVEs |
1181 of these have been exploited for more than two years. If that number is uncomfortable, it is a fair reading: most of the catalog is not new, it is a debt that was never paid.
| CVE | CVSS | EPSS | Exploited |
|---|---|---|---|
| CVE-2026-87902WordPress / Core | 8.1 | 0.1817top 5% | 2d |
| CVE-2026-71362Adobe / Commerce and Magento | 9.1 | 0.8751top 1% | 3d |
| CVE-2026-93616Check Point / Multiple Products | 9.8 | 0.1965top 5% | 5d |
| CVE-2026-76460Cisco / Identity Services Engine | 10.0 | 0.1403top 5% | 11d |
| CVE-2026-76461Cisco / Secure Email Gateway | 9.8 | 0.2827top 5% | 13d |
| CVE-2026-85706GitLab / Community Edition and Enterprise Edition | 10.0 | 0.9143top 1% | 16d |
| CVE-2026-42018JFrog / Artifactory | 7.5 | 0.0980top 5% | 16d |
| CVE-2026-20079Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | 10.0 | 0.8818top 1% | 18d |
| CVE-2026-19490Citrix / NetScaler | 9.3 | 0.0701top 10% | 18d |
| CVE-2026-86218N-able / N-central | 10.0 | 0.1293top 5% | 19d |
| CVE-2026-75650Adobe / Commerce and Magento | 10.0 | 0.0395top 10% | 19d |
| CVE-2026-85046Google / Chromium V8 | 8.8 | 0.4888top 5% | 23d |
| CVE-2026-9586Sangoma / Switchvox | 9.3 | 0.1898top 5% | 25d |
| CVE-2026-82329JFrog / Artifactory | 9.8 | 0.1412top 5% | 25d |
| CVE-2026-83548SonicWall / SMA1000 Appliances | 10.0 | 0.0876top 10% | 25d |
| CVE-2026-48710Kludex / Starlette | 6.5 | 0.0706top 10% | 25d |
| CVE-2026-81578PaperCut / NG/MF | 8.8 | 0.0448top 10% | 27d |
| CVE-2023-49105ownCloud / ownCloud | 9.8 | 0.4292top 5% | 31d |
| CVE-2021-23758Ajax.NET Professional / Ajax.NET Professional | 8.1 | 0.8258top 1% | 32d |
| CVE-2026-60004Gitea / Gitea | 9.8 | 0.2399top 5% | 33d |
| CVE-2026-21962Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-in | 10.0 | 0.7091top 1% | 34d |
| CVE-2026-73570Synacor / Zimbra Collaboration Suite (ZCS) | 8.9 | 0.1174top 5% | 37d |
| CVE-2026-64849MLflow / MLflow | 9.3 | 0.0984top 5% | 39d |
| CVE-2026-55040Microsoft / SharePoint | 9.1 | 0.1754top 5% | 40d |
| CVE-2025-62593Ray-Project / Ray | 9.4 | 0.6246top 1% | 41d |
| CVE-2026-72898Metabase / Metabase | 10.0 | 0.1905top 5% | 47d |
| CVE-2026-63077JetBrains / TeamCity | 9.8 | 0.0976top 5% | 53d ransomware |
| CVE-2026-9198IBM / Langflow | 9.8 | 0.2866top 5% | 54d |
| CVE-2026-18556N-able / N-central | 8.2 | 0.0788top 10% | 54d |
| CVE-2026-34486Apache / Tomcat | 7.5 | 0.0656top 10% | 54d |
| CVE-2026-18577N-able / N-central | 8.2 | 0.1462top 5% | 55d |
| CVE-2026-20316Cisco / Secure Firewall Management Center (FMC) | 5.3 | 0.3510top 5% | 60d ransomware |
| CVE-2025-68686Fortinet / FortiOS | 5.9 | 0.2960top 5% | 62d |
| CVE-2026-16232Check Point / SmartConsole | 9.3 | 0.7797top 1% | 67d |
| CVE-2026-0770Langflow / Langflow | 9.8 | 0.6384top 1% | 68d |
| CVE-2026-63030WordPress / Core | 9.8 | 0.1012top 5% | 68d |
| CVE-2026-60137WordPress / Core | 5.9 | 0.0591top 10% | 68d |
| CVE-2021-27137DD-WRT / DD-WRT | 8.1 | 0.0399top 10% | 68d |
| CVE-2026-25089Fortinet / FortiSandbox | 9.8 | 0.7611top 1% | 73d |
| CVE-2026-39808Fortinet / FortiSandbox | 9.8 | 0.4736top 5% | 73d |
| CVE-2026-58644Microsoft / SharePoint | 9.8 | 0.1587top 5% | 73d |
| CVE-2026-15409SonicWall / SMA1000 Appliances | 10.0 | 0.0679top 10% | 75d ransomware |
| CVE-2008-4128Cisco / IOS | 8.1 | 0.3387top 5% | 76d |
| CVE-2026-48939iCagenda / iCagenda | 10.0 | 0.2007top 5% | 79d |
| CVE-2026-56291Balbooa / Forms | 10.0 | 0.1485top 5% | 79d |
| CVE-2026-48908JoomShaper / SP Page Builder | 10.0 | 0.8851top 1% | 82d |
| CVE-2026-48282Adobe / ColdFusion | 10.0 | 0.4239top 5% | 82d |
| CVE-2026-56290Joomlack / Page Builder | 10.0 | 0.3087top 5% | 82d |
| CVE-2026-48558SimpleHelp / SimpleHelp | 9.5 | 0.0572top 10% | 90d |
| CVE-2026-20230Cisco / Unified Communications Manager | 8.6 | 0.8820top 1% | 94d |
| CVE-2026-12569PTC / Windchill and FlexPLM | 9.3 | 0.4605top 5% | 94d ransomware |
| CVE-2026-34910Ubiquiti / UniFi OS | 10.0 | 0.4577top 5% | 96d |
| CVE-2025-67038Lantronix / EDS5000 | 9.3 | 0.1926top 5% | 96d |
| CVE-2026-34908Ubiquiti / UniFi OS | 10.0 | 0.1521top 5% | 96d |
| CVE-2026-20253Splunk / Enterprise | 9.8 | 0.9694top 1% | 101d |
| CVE-2026-48907Widget Factory / Joomla Content Editor | 10.0 | 0.1619top 5% | 103d |
| CVE-2026-35273Oracle / PeopleSoft Enterprise PeopleTools | 9.8 | 0.0944top 5% | 107d ransomware |
| CVE-2026-10520Ivanti / Sentry | 10.0 | 0.9991top 1% | 108d |
| CVE-2026-50751Check Point / Security Gateway | 9.3 | 0.0630top 10% | 111d ransomware |
| CVE-2024-21182Oracle / WebLogic Server | 7.5 | 0.7416top 1% | 118d |
| CVE-2026-0257Palo Alto Networks / PAN-OS | 7.8 | 0.9638top 1% | 121d ransomware |
| CVE-2026-9082Drupal / Core | 9.8 | 0.1570top 5% | 128d |
| CVE-2025-34291Langflow / Langflow | 9.4 | 0.9281top 1% | 129d |
| CVE-2008-4250Microsoft / Windows | 9.8 | 0.9875top 1% | 130d |
| CVE-2010-0249Microsoft / Internet Explorer | 8.8 | 0.9194top 1% | 130d |
| CVE-2009-3459Adobe / Acrobat and Reader | 8.8 | 0.8658top 1% | 130d |
| CVE-2010-0806Microsoft / Internet Explorer | 8.8 | 0.8217top 1% | 130d |
| CVE-2009-1537Microsoft / DirectX | 8.8 | 0.5121top 5% | 130d |
| CVE-2026-20182Cisco / Catalyst SD-WAN | 10.0 | 0.9152top 1% | 136d |
| CVE-2026-42208BerriAI / LiteLLM | 9.3 | 0.0577top 10% | 142d |
| CVE-2026-0300Palo Alto Networks / PAN-OS | 9.3 | 0.3172top 5% | 144d |
| CVE-2026-41940WebPros / cPanel & WHM and WP2 (WordPress Squared) | 9.3 | 0.9853top 1% | 150d ransomware |
| CVE-2026-32202Microsoft / Windows | 4.3 | 0.0490top 10% | 152d |
| CVE-2026-39987Marimo / Marimo | 9.3 | 0.3786top 5% | 157d |
| CVE-2024-27199JetBrains / TeamCity | 7.3 | 0.9999top 1% | 160d ransomware |
| CVE-2023-27351PaperCut / NG/MF | 7.5 | 0.7805top 1% | 160d ransomware |
| CVE-2009-0238Microsoft / Office | 8.8 | 0.4321top 5% | 166d |
| CVE-2026-21643Fortinet / FortiClient EMS | 9.8 | 0.9372top 1% | 167d |
| CVE-2026-1340Ivanti / Endpoint Manager Mobile (EPMM) | 9.8 | 0.9864top 1% | 172d |
| CVE-2026-35616Fortinet / FortiClient EMS | 9.8 | 0.0910top 5% | 174d |
| CVE-2026-3055Citrix / NetScaler | 9.3 | 0.0404top 10% | 181d |
| CVE-2026-33017Langflow / Langflow | 9.3 | 0.2475top 5% | 186d |
| CVE-2025-32432Craft CMS / Craft CMS | 10.0 | 0.9979top 1% | 191d |
| CVE-2025-54068Laravel / Livewire | 9.2 | 0.9707top 1% | 191d |
| CVE-2026-20131Cisco / Secure Firewall Management Center (FMC) | 10.0 | 0.4266top 5% | 192d ransomware |
| CVE-2026-20963Microsoft / SharePoint | 9.8 | 0.2958top 5% | 193d |
| CVE-2025-66376Synacor / Zimbra Collaboration Suite (ZCS) | 7.2 | 0.1956top 5% | 193d |
| CVE-2021-22054Omnissa / Workspace One UEM | 7.5 | 0.9968top 1% | 202d |
| CVE-2025-26399SolarWinds / Web Help Desk | 9.8 | 0.8950top 1% | 202d ransomware |
| CVE-2026-1603Ivanti / Endpoint Manager (EPM) | 8.6 | 0.8764top 1% | 202d |
| CVE-2017-7921Hikvision / Multiple Products | 9.8 | 1.0000top 1% | 206d |
| CVE-2021-22681Rockwell / Multiple Products | 9.8 | 0.6363top 1% | 206d |
| CVE-2026-22719Broadcom / VMware Aria Operations | 8.1 | 0.1771top 5% | 208d |
| CVE-2026-20127Cisco / Catalyst SD-WAN Controller and Manager | 10.0 | 0.8848top 1% | 214d |
| CVE-2025-68461Roundcube / Webmail | 7.2 | 0.2684top 5% | 219d |
| CVE-2021-22175GitLab / GitLab | 6.8 | 0.5337top 5% | 221d |
| CVE-2026-22769Dell / RecoverPoint for Virtual Machines (RP4VMs) | 10.0 | 0.1335top 5% | 221d |
| CVE-2020-7796Synacor / Zimbra Collaboration Suite | 9.8 | 0.8442top 1% | 222d |
| CVE-2008-0015Microsoft / Windows | 8.8 | 0.7673top 1% | 222d |
| CVE-2026-2441Google / Chromium | 8.8 | 0.5510top 5% | 222d |
| CVE-2026-1731BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA) | 9.9 | 0.9096top 1% | 226d ransomware |
| CVE-2024-43468Microsoft / Configuration Manager | 9.8 | 0.8091top 1% | 227d |
| CVE-2025-40536SolarWinds / Web Help Desk | 8.1 | 0.7356top 1% | 227d |
| CVE-2026-21510Microsoft / Windows | 8.8 | 0.2423top 5% | 229d |
| CVE-2026-21513Microsoft / Windows | 8.8 | 0.1564top 5% | 229d |
| CVE-2025-11953React Native Community / CLI | 9.8 | 0.9398top 1% | 234d |
| CVE-2026-24423SmarterTools / SmarterMail | 9.3 | 0.8818top 1% | 234d ransomware |
| CVE-2025-40551SolarWinds / Web Help Desk | 9.8 | 0.8418top 1% | 236d |
| CVE-2019-19006Sangoma / FreePBX | 9.8 | 0.5595top 1% | 236d |
| CVE-2021-39935GitLab / Community and Enterprise Editions | 6.8 | 0.3565top 5% | 236d |
| CVE-2026-1281Ivanti / Endpoint Manager Mobile (EPMM) | 9.8 | 0.9869top 1% | 241d |
| CVE-2026-24858Fortinet / Multiple Products | 9.8 | 0.8580top 1% | 243d |
| CVE-2026-24061GNU / InetUtils | 9.8 | 0.9898top 1% | 244d |
| CVE-2026-23760SmarterTools / SmarterMail | 9.3 | 0.9654top 1% | 244d ransomware |
| CVE-2025-52691SmarterTools / SmarterMail | 10.0 | 0.8566top 1% | 244d ransomware |
| CVE-2024-37079Broadcom / VMware vCenter Server | 9.8 | 0.2238top 5% | 247d |
| CVE-2025-34026Versa / Concerto | 9.2 | 0.8194top 1% | 248d |
| CVE-2025-31125Vite / Vitejs | 5.3 | 0.6469top 1% | 248d |
| CVE-2025-68645Synacor / Zimbra Collaboration Suite (ZCS) | 8.8 | 0.4887top 5% | 248d |
| CVE-2025-54313Prettier / eslint-config-prettier | 7.5 | 0.0452top 10% | 248d |
| CVE-2026-20045Cisco / Unified Communications Manager | 8.2 | 0.0454top 10% | 249d |
| CVE-2025-37164Hewlett Packard Enterprise (HPE) / OneView | 10.0 | 0.9019top 1% | 263d |
| CVE-2009-0556Microsoft / Office | 8.8 | 0.6731top 1% | 263d |
| CVE-2025-14847MongoDB / MongoDB and MongoDB Server | 8.7 | 0.8322top 1% | 272d |
| CVE-2025-14733WatchGuard / Firebox | 9.3 | 0.2651top 5% | 282d ransomware |
| CVE-2025-20393Cisco / Multiple Products | 10.0 | 0.3239top 5% | 284d |
| CVE-2025-59718Fortinet / Multiple Products | 9.8 | 0.6829top 1% | 285d |
| CVE-2025-14611Gladinet / CentreStack and Triofox | 7.1 | 0.5330top 5% | 286d |
| CVE-2025-43529Apple / Multiple Products | 8.8 | 0.0876top 10% | 286d |
| CVE-2025-14174Google / Chromium | 8.8 | 0.2233top 5% | 289d |
| CVE-2025-58360OSGeo / GeoServer | 8.2 | 0.6052top 1% | 290d |
| CVE-2022-37055D-Link / Routers | 9.8 | 0.5553top 1% | 293d |
| CVE-2025-55182Meta / React Server Components | 10.0 | 0.9980top 1% | 296d ransomware |
| CVE-2025-61757Oracle / Fusion Middleware | 9.8 | 0.8865top 1% | 310d |
| CVE-2025-13223Google / Chromium V8 | 8.8 | 0.0503top 10% | 312d |
| CVE-2025-64446Fortinet / FortiWeb | 9.8 | 0.9184top 1% | 317d |
| CVE-2025-12480Gladinet / Triofox | 9.1 | 0.9543top 1% | 319d |
| CVE-2025-9242WatchGuard / Firebox | 9.3 | 0.9130top 1% | 319d |
| CVE-2025-21042Samsung / Mobile Devices | 8.8 | 0.3317top 5% | 321d |
| CVE-2025-48703CWP / Control Web Panel | 9.0 | 0.9966top 1% | 327d |
| CVE-2025-11371Gladinet / CentreStack and Triofox | 7.5 | 0.9214top 1% | 327d |
| CVE-2025-24893XWiki / Platform | 9.8 | 0.9986top 1% | 332d |
| CVE-2025-6205Dassault Systèmes / DELMIA Apriso | 9.1 | 0.7331top 1% | 334d |
| CVE-2025-59287Microsoft / Windows | 9.8 | 0.9998top 1% | 338d |
| CVE-2025-54236Adobe / Commerce and Magento | 9.1 | 0.9453top 1% | 338d |
| CVE-2025-2747Kentico / Xperience CMS | 9.8 | 0.9717top 1% | 342d |
| CVE-2025-61884Oracle / E-Business Suite | 7.5 | 0.9589top 1% | 342d ransomware |
| CVE-2025-2746Kentico / Xperience CMS | 9.8 | 0.7304top 1% | 342d |
| CVE-2025-54253Adobe / Experience Manager (AEM) Forms | 10.0 | 0.8799top 1% | 347d |
| CVE-2016-7836SKYSEA / Client View | 9.8 | 0.1923top 5% | 348d |
| CVE-2021-43798Grafana Labs / Grafana | 7.5 | 0.8850top 1% | 353d |
| CVE-2025-61882Oracle / E-Business Suite | 9.8 | 0.9973top 1% | 356d ransomware |
| CVE-2010-3962Microsoft / Internet Explorer | 8.1 | 0.9683top 1% | 356d |
| CVE-2010-3765Mozilla / Multiple Products | 9.8 | 0.8316top 1% | 356d |
| CVE-2011-3402Microsoft / Windows | 8.8 | 0.7814top 1% | 356d |
| CVE-2013-3918Microsoft / Windows | 8.8 | 0.7369top 1% | 356d |
| CVE-2017-1000353Jenkins / Jenkins | 9.8 | 0.9968top 1% | 360d |
| CVE-2014-6278GNU / GNU Bash | 8.8 | 0.9960top 1% | 360d |
| CVE-2015-7755Juniper / ScreenOS | 9.8 | 0.6114top 1% | 360d |
| CVE-2025-10035Fortra / GoAnywhere MFT | 10.0 | 0.9980top 1% | 363d ransomware |
| CVE-2021-21311Adminer / Adminer | 7.2 | 0.9846top 1% | 363d |
| CVE-2025-20362Cisco / Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 6.5 | 0.8709top 1% | 367d |
| CVE-2025-10585Google / Chromium V8 | 9.8 | 0.0539top 10% | 369d |
| CVE-2025-5086Dassault Systèmes / DELMIA Apriso | 9.0 | 0.9691top 1% | 381d |
| CVE-2025-53690Sitecore / Multiple Products | 9.0 | 0.5109top 5% | 388d |
| CVE-2025-57819Sangoma / FreePBX | 10.0 | 0.8546top 1% | 394d |
| CVE-2025-7775Citrix / NetScaler | 9.2 | 0.1963top 5% | 397d |
| CVE-2025-43300Apple / iOS, iPadOS, and macOS | 10.0 | 0.2199top 5% | 402d |
| CVE-2025-54948Trend Micro / Apex One | 9.4 | 0.2204top 5% | 405d |
| CVE-2013-3893Microsoft / Internet Explorer | 8.8 | 0.8753top 1% | 411d |
| CVE-2007-0671Microsoft / Office | 8.8 | 0.4324top 5% | 411d |
| CVE-2020-25078D-Link / DCS-2530L and DCS-2670L Devices | 7.5 | 0.9751top 1% | 418d |
| CVE-2025-20281Cisco / Identity Services Engine | 10.0 | 0.9760top 1% | 426d |
| CVE-2025-20337Cisco / Identity Services Engine | 10.0 | 0.6783top 1% | 426d |
| CVE-2025-49706Microsoft / SharePoint | 6.5 | 0.9906top 1% | 432d ransomware |
| CVE-2025-54309CrushFTP / CrushFTP | 9.0 | 0.9490top 1% | 432d |
| CVE-2025-2776SysAid / SysAid On-Prem | 9.3 | 0.6440top 1% | 432d |
| CVE-2025-2775SysAid / SysAid On-Prem | 9.3 | 0.4295top 5% | 432d |
| CVE-2025-6558Google / Chromium | 8.8 | 0.0959top 5% | 432d |
| CVE-2025-53770Microsoft / SharePoint | 9.8 | 1.0000top 1% | 434d ransomware |
| CVE-2025-25257Fortinet / FortiWeb | 9.8 | 0.9978top 1% | 436d |
| CVE-2025-47812Wing FTP Server / Wing FTP Server | 10.0 | 0.9286top 1% | 440d |
| CVE-2025-5777Citrix / NetScaler ADC and Gateway | 9.3 | 0.9997top 1% | 444d ransomware |
| CVE-2016-10033PHP / PHPMailer | 9.8 | 0.9971top 1% | 447d |
| CVE-2019-5418Rails / Ruby on Rails | 7.5 | 0.9851top 1% | 447d |
| CVE-2019-9621Synacor / Zimbra Collaboration Suite (ZCS) | 7.5 | 0.8104top 1% | 447d |
| CVE-2014-3931Looking Glass / Multi-Router Looking Glass (MRLG) | 9.8 | 0.2898top 5% | 447d |
| CVE-2025-6554Google / Chromium V8 | 8.1 | 0.1256top 5% | 452d |
| CVE-2025-48927TeleMessage / TM SGNL | 5.3 | 0.1110top 5% | 453d |
| CVE-2025-6543Citrix / NetScaler ADC and Gateway | 9.2 | 0.1056top 5% | 454d |
| CVE-2024-0769D-Link / DIR-859 Router | 5.3 | 0.8271top 1% | 459d |
| CVE-2024-54085AMI / MegaRAC SPx | 10.0 | 0.6075top 1% | 459d |
| CVE-2025-33053Microsoft / Windows | 8.8 | 0.8701top 1% | 474d |
| CVE-2025-32433Erlang / Erlang/OTP | 10.0 | 0.9879top 1% | 475d |
| CVE-2024-42009Roundcube / Webmail | 9.3 | 0.8288top 1% | 475d |
| CVE-2025-5419Google / Chromium V8 | 8.8 | 0.0782top 10% | 479d |
| CVE-2021-32030ASUS / Routers | 9.8 | 0.9939top 1% | 482d |
| CVE-2024-56145Craft CMS / Craft CMS | 9.3 | 0.9740top 1% | 482d |
| CVE-2025-4632Samsung / MagicINFO 9 Server | 9.8 | 0.2429top 5% | 493d |
| CVE-2025-4427Ivanti / Endpoint Manager Mobile (EPMM) | 5.3 | 0.9993top 1% | 496d |
| CVE-2023-38950ZKTeco / BioTime | 7.5 | 0.9247top 1% | 496d |
| CVE-2024-27443Synacor / Zimbra Collaboration Suite (ZCS) | 6.1 | 0.2363top 5% | 496d |
| CVE-2024-11182MDaemon / Email Server | 5.3 | 0.1771top 5% | 496d |
| CVE-2024-12987DrayTek / Vigor Routers | 6.9 | 0.9808top 1% | 500d |
| CVE-2025-32756Fortinet / Multiple Products | 9.8 | 0.2981top 5% | 501d |
| CVE-2025-30397Microsoft / Windows | 7.5 | 0.2683top 5% | 502d |
| CVE-2024-11120GeoVision / Multiple Devices | 9.8 | 0.2839top 5% | 508d |
| CVE-2024-6047GeoVision / Multiple Devices | 9.8 | 0.1007top 5% | 508d |
| CVE-2025-27363FreeType / FreeType | 8.1 | 0.2777top 5% | 509d |
| CVE-2025-3248Langflow / Langflow | 9.8 | 0.9999top 1% | 510d ransomware |
| CVE-2025-34028Commvault / Command Center | 9.3 | 0.9755top 1% | 513d |
| CVE-2024-58136Yiiframework / Yii | 9.0 | 0.8776top 1% | 513d |
| CVE-2024-38475Apache / HTTP Server | 9.1 | 0.9996top 1% | 514d |
| CVE-2025-31324SAP / NetWeaver | 10.0 | 0.9947top 1% | 516d ransomware |
| CVE-2025-24054Microsoft / Windows | 6.5 | 0.5891top 1% | 528d |
| CVE-2025-31200Apple / Multiple Products | 9.8 | 0.1875top 5% | 528d |
| CVE-2025-31201Apple / Multiple Products | 9.8 | 0.1397top 5% | 528d |
| CVE-2025-30406Gladinet / CentreStack | 9.0 | 0.9434top 1% | 537d |
| CVE-2025-31161CrushFTP / CrushFTP | 9.8 | 0.9998top 1% | 538d ransomware |
| CVE-2025-22457Ivanti / Connect Secure, Policy Secure, and ZTA Gateways | 9.0 | 0.9998top 1% | 541d ransomware |
| CVE-2025-24813Apache / Tomcat | 9.8 | 0.9993top 1% | 544d |
| CVE-2024-20439Cisco / Smart Licensing Utility | 9.8 | 0.9709top 1% | 545d |
| CVE-2025-2783Google / Chromium Mojo | 8.3 | 0.0924top 5% | 549d |
| CVE-2019-9874Sitecore / CMS and Experience Platform (XP) | 9.8 | 0.8374top 1% | 550d |
| CVE-2017-12637SAP / NetWeaver | 7.5 | 0.9511top 1% | 557d |
| CVE-2024-48248NAKIVO / Backup and Replication | 8.6 | 0.9436top 1% | 557d |
| CVE-2025-1316Edimax / IC-7100 IP Camera | 9.3 | 0.7448top 1% | 557d |
| CVE-2025-30066tj-actions / changed-files GitHub Action | 8.6 | 0.7209top 1% | 558d |
| CVE-2025-24472Fortinet / FortiOS and FortiProxy | 8.1 | 0.0723top 10% | 558d ransomware |
| CVE-2024-13159Ivanti / Endpoint Manager (EPM) | 9.8 | 0.9999top 1% | 566d |
| CVE-2024-13160Ivanti / Endpoint Manager (EPM) | 9.8 | 0.9125top 1% | 566d |
| CVE-2024-13161Ivanti / Endpoint Manager (EPM) | 9.8 | 0.9008top 1% | 566d |
| CVE-2025-25181Advantive / VeraCore | 5.8 | 0.5730top 1% | 566d |
| CVE-2024-4885Progress / WhatsUp Gold | 9.8 | 0.9929top 1% | 573d |
| CVE-2022-43939Hitachi Vantara / Pentaho Business Analytics (BA) Server | 8.6 | 0.9227top 1% | 573d |
| CVE-2017-3066Adobe / ColdFusion | 9.8 | 0.9060top 1% | 580d |
| CVE-2025-0108Palo Alto Networks / PAN-OS | 8.8 | 0.9846top 1% | 586d |
| CVE-2024-53704SonicWall / SonicOS | 9.8 | 0.9513top 1% | 586d ransomware |
| CVE-2024-57727SimpleHelp / SimpleHelp | 7.5 | 0.9658top 1% | 591d ransomware |
| CVE-2024-21413Microsoft / Office Outlook | 9.8 | 0.9466top 1% | 598d |
| CVE-2020-15069Sophos / XG Firewall | 9.8 | 0.1067top 5% | 598d |
| CVE-2020-29574Sophos / CyberoamOS | 9.8 | 0.0466top 10% | 598d ransomware |
| CVE-2024-45195Apache / OFBiz | 7.5 | 0.9998top 1% | 600d |
| CVE-2024-29059Microsoft / .NET Framework | 7.5 | 0.9862top 1% | 600d |
| CVE-2018-19410Paessler / PRTG Network Monitor | 9.8 | 0.9794top 1% | 600d |
| CVE-2025-24085Apple / Multiple Products | 10.0 | 0.1751top 5% | 606d |
| CVE-2025-23006SonicWall / SMA1000 Appliances | 9.8 | 0.2343top 5% | 611d ransomware |
| CVE-2020-11023JQuery / JQuery | 6.9 | 0.8489top 1% | 612d |
| CVE-2024-50603Aviatrix / Controllers | 10.0 | 0.9855top 1% | 619d |
| CVE-2024-55591Fortinet / FortiOS and FortiProxy | 9.8 | 0.9415top 1% | 621d ransomware |
| CVE-2025-0282Ivanti / Connect Secure, Policy Secure, and ZTA Gateways | 9.0 | 0.9998top 1% | 627d ransomware |
| CVE-2024-41713Mitel / MiCollab | 9.1 | 0.9811top 1% | 628d ransomware |
| CVE-2020-2883Oracle / WebLogic Server | 9.8 | 0.9493top 1% | 628d |
| CVE-2024-3393Palo Alto Networks / PAN-OS | 8.7 | 0.2841top 5% | 636d |
| CVE-2021-44207Acclaim Systems / USAHERDS | 8.1 | 0.1758top 5% | 643d |
| CVE-2024-12356BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS) | 9.8 | 0.8726top 1% | 647d |
| CVE-2018-14933NUUO / NVRmini Devices | 9.8 | 0.9488top 1% | 648d |
| CVE-2022-23227NUUO / NVRmini2 Devices | 9.8 | 0.4850top 5% | 648d |
| CVE-2024-55956Cleo / Multiple Products | 9.8 | 0.9397top 1% | 649d ransomware |
| CVE-2024-20767Adobe / ColdFusion | 7.4 | 0.9851top 1% | 650d |
| CVE-2024-50623Cleo / Multiple Products | 9.8 | 0.9861top 1% | 653d ransomware |
| CVE-2024-51378CyberPersons / CyberPanel | 10.0 | 0.9467top 1% | 662d ransomware |
| CVE-2024-11680ProjectSend / ProjectSend | 9.8 | 0.9170top 1% | 663d |
| CVE-2023-28461Array Networks / AG/vxAG ArrayOS | 9.8 | 0.6808top 1% | 671d ransomware |
| CVE-2024-44309Apple / Multiple Products | 6.3 | 0.2259top 5% | 675d |
| CVE-2024-44308Apple / Multiple Products | 8.8 | 0.1008top 5% | 675d |
| CVE-2024-38812VMware / vCenter Server | 9.8 | 0.5457top 5% | 676d |
| CVE-2024-0012Palo Alto Networks / PAN-OS | 9.3 | 0.9985top 1% | 678d ransomware |
| CVE-2024-1212Progress / Kemp LoadMaster | 10.0 | 0.9539top 1% | 678d |
| CVE-2024-9465Palo Alto Networks / Expedition | 9.2 | 0.9963top 1% | 682d |
| CVE-2024-9463Palo Alto Networks / Expedition | 9.9 | 0.9855top 1% | 682d |
| CVE-2021-26086Atlassian / Jira Server and Data Center | 5.3 | 1.0000top 1% | 684d |
| CVE-2021-41277Metabase / Metabase | 10.0 | 0.9718top 1% | 684d |
| CVE-2024-43451Microsoft / Windows | 6.5 | 0.8411top 1% | 684d |
| CVE-2014-2120Cisco / Adaptive Security Appliance (ASA) | 6.1 | 0.1877top 5% | 684d |
| CVE-2019-16278Nostromo / nhttpd | 9.8 | 0.9903top 1% | 689d |
| CVE-2024-5910Palo Alto Networks / Expedition | 9.3 | 0.9178top 1% | 689d |
| CVE-2024-51567CyberPersons / CyberPanel | 10.0 | 0.8663top 1% | 689d ransomware |
| CVE-2024-8956PTZOptics / PT30X-SDI/NDI Cameras | 9.1 | 0.5879top 1% | 692d |
| CVE-2024-37383Roundcube / Webmail | 6.1 | 0.7330top 1% | 703d |
| CVE-2024-20481Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 5.8 | 0.1575top 5% | 703d |
| CVE-2024-47575Fortinet / FortiManager | 9.8 | 0.9477top 1% | 704d |
| CVE-2024-40711Veeam / Backup & Replication | 9.8 | 0.9037top 1% | 710d ransomware |
| CVE-2024-28987SolarWinds / Web Help Desk | 9.1 | 0.9330top 1% | 712d |
| CVE-2024-9680Mozilla / Firefox | 9.8 | 0.2318top 5% | 712d ransomware |
| CVE-2024-23113Fortinet / Multiple Products | 9.8 | 0.6172top 1% | 718d |
| CVE-2024-43573Microsoft / Windows | 6.5 | 0.4611top 5% | 719d |
| CVE-2024-45519Synacor / Zimbra Collaboration Suite (ZCS) | 10.0 | 0.9991top 1% | 724d |
| CVE-2023-25280D-Link / DIR-820 Router | 9.8 | 0.9786top 1% | 727d |
| CVE-2020-15415DrayTek / Multiple Vigor Routers | 9.8 | 0.8448top 1% | 727d |
| CVE-2019-0344SAP / Commerce Cloud | 9.8 | 0.0708top 10% | 727d |
| CVE-2026-67279MikroTik / RouterOS | 6.9 | 0.0103top half | 2d |
| CVE-2026-5430WSO2 / Multiple Products | 10.0 | 0.0059upper half | 3d |
| CVE-2026-94127F5 / BIG-IP APM | 9.3 | 0.0223top 25% | 5d |
| CVE-2026-85102Check Point / Multiple Products | 9.8 | 0.0099top half | 5d |
| CVE-2026-93952Arista / VeloCloud Orchestrator | 9.5 | 0.0089top half | 5d |
| CVE-2025-39682Linux / Kernel | 9.8 | 0.0288top 25% | 9d |
| CVE-2026-86060MikroTik / RouterOS | 9.2 | 0.0185top 25% | 17d |
| CVE-2026-67277MikroTik / RouterOS | 8.8 | 0.0156top half | 17d |
| CVE-2025-25249Fortinet / Multiple Products | 8.1 | 0.0386top 25% | 18d |
| CVE-2026-87491Google / Chromium V8 | 8.8 | 0.0314top 25% | 18d |
| CVE-2026-83549SonicWall / SMA1000 Appliances | 7.8 | 0.1076top 5% | 25d |
| CVE-2026-49869Kestra / Kestra OSS | 10.0 | 0.0209top 25% | 25d |
| CVE-2026-59822BerriAI / LiteLLM | 8.8 | 0.0084top half | 25d |
| CVE-2019-1068Microsoft / SQL Server | 8.8 | 0.5791top 1% | 32d |
| CVE-2015-3246Red Hat / Libuser | 5.1 | 0.0880top 5% | 32d |
| CVE-2022-0995Linux / Kernel | 7.8 | 0.0879top 5% | 32d |
| CVE-2026-8452Citrix / NetScaler ADC and NetScaler Gateway | 8.8 | 0.0101top half | 32d |
| CVE-2026-72530TrueConf / Server | 9.5 | 0.0169top 25% | 38d |
| CVE-2026-72529TrueConf / Server | 9.3 | 0.0146top half | 38d |
| CVE-2026-59310Broadcom / VMware vCenter | 9.8 | 0.0256top 25% | 40d ransomware |
| CVE-2026-33824Microsoft / Internet Key Exchange (IKE) Service Extensions | 9.8 | 0.0162top 25% | 40d |
| CVE-2026-65400Apple / macOS | 9.8 | 0.0122top half | 40d |
| CVE-2026-20349Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | 8.6 | 0.0101top half | 47d |
| CVE-2026-8037Progress / LoadMaster | 9.6 | 0.7736top 1% | 51d |
| CVE-2026-16812Arista / VeloCloud Orchestrator | 10.0 | 0.0100top half | 62d |
| CVE-2026-50522Microsoft / SharePoint | 9.8 | 0.0304top 25% | 67d |
| CVE-2023-4346KNX Association / KNX Protocol Connection Authorization Option 1 | 7.5 | 0.0129top half | 74d |
| CVE-2026-46817Oracle / E-Business Suite | 9.8 | 0.0081top half | 74d |
| CVE-2026-15410SonicWall / SMA1000 Appliances | 7.2 | 0.1179top 5% | 75d ransomware |
| CVE-2026-56164Microsoft / SharePoint Server | 5.3 | 0.0101top half | 75d |
| CVE-2026-34909Ubiquiti / UniFi OS | 10.0 | 0.0179top 25% | 96d |
| CVE-2026-20262Cisco / Catalyst SD-WAN Manager | 6.5 | 0.2817top 5% | 104d |
| CVE-2026-20245Cisco / Catalyst SD-WAN Manager | 7.8 | 0.2532top 5% | 110d |
| CVE-2026-11645Google / Chromium V8 | 8.8 | 0.0219top 25% | 110d |
| CVE-2026-7473Arista / Extensible Operating System | 6.9 | 0.0065upper half | 110d |
| CVE-2026-42271BerriAI / LiteLLM | 8.7 | 0.1275top 5% | 111d |
| CVE-2026-28318SolarWinds / Serv-U | 7.5 | 0.0194top 25% | 114d |
| CVE-2026-45247Mirasvit / Mirasvit Full Page Cache Warmer | 9.3 | 0.0209top 25% | 116d |
| CVE-2026-48027Nx / Nx Console | 9.3 | 0.0134top half | 123d ransomware |
| CVE-2026-45321TanStack / TanStack | 9.6 | 0.0105top half | 123d ransomware |
| CVE-2026-8398Daemon / Daemon Tools Lite | 9.3 | 0.0096top half | 123d |
| CVE-2026-48172LiteSpeed / cPanel Plugin | 10.0 | 0.0101top half | 124d |
| CVE-2026-42897Microsoft / Microsoft | 8.1 | 0.0052upper half | 135d |
| CVE-2024-1708ConnectWise / ScreenConnect | 8.4 | 0.9544top 1% | 152d ransomware |
| CVE-2024-7399Samsung / MagicINFO 9 Server | 8.8 | 0.9194top 1% | 156d |
| CVE-2025-29635D-Link / DIR-823X | 7.2 | 0.8794top 1% | 156d |
| CVE-2024-57726SimpleHelp / SimpleHelp | 9.9 | 0.6660top 1% | 156d ransomware |
| CVE-2024-57728SimpleHelp / SimpleHelp | 7.2 | 0.6466top 1% | 156d ransomware |
| CVE-2026-20133Cisco / Catalyst SD-WAN Manager | 6.5 | 0.3183top 5% | 160d |
| CVE-2026-20122Cisco / Catalyst SD-WAN Manger | 5.4 | 0.2498top 5% | 160d |
| CVE-2025-32975Quest / KACE Systems Management Appliance (SMA) | 10.0 | 0.0249top 25% | 160d |
| CVE-2025-48700Synacor / Zimbra Collaboration Suite (ZCS) | 6.1 | 0.0171top 25% | 160d |
| CVE-2026-34197Apache / ActiveMQ | 8.8 | 0.1549top 5% | 164d |
| CVE-2026-32201Microsoft / SharePoint Server | 6.5 | 0.0098top half | 166d |
| CVE-2023-21529Microsoft / Exchange Server | 8.8 | 0.5929top 1% | 167d ransomware |
| CVE-2020-9715Adobe / Acrobat | 7.8 | 0.4859top 5% | 167d |
| CVE-2012-1854Microsoft / Visual Basic for Applications (VBA) | 7.8 | 0.2103top 5% | 167d |
| CVE-2023-36424Microsoft / Windows | 7.8 | 0.1218top 5% | 167d |
| CVE-2026-5281Google / Dawn | 8.8 | 0.0070top half | 179d |
| CVE-2025-53521F5 / BIG-IP | 9.3 | 0.0230top 25% | 184d |
| CVE-2025-31277Apple / Multiple Products | 8.8 | 0.0163top 25% | 191d |
| CVE-2025-47813Wing FTP Server / Wing FTP Server | 4.3 | 0.6297top 1% | 195d |
| CVE-2026-3910Google / Chromium V8 | 8.8 | 0.0103top half | 198d |
| CVE-2026-3909Google / Skia | 8.8 | 0.0070top half | 198d |
| CVE-2025-68613n8n / n8n | 9.9 | 0.9899top 1% | 200d |
| CVE-2023-43000Apple / Multiple Products | 8.8 | 0.0390top 25% | 206d |
| CVE-2022-20775Cisco / SD-WAN | 7.8 | 0.1247top 5% | 214d |
| CVE-2025-49113Roundcube / Webmail | 9.9 | 0.9890top 1% | 219d |
| CVE-2025-15556Notepad++ / Notepad++ | 7.7 | 0.0175top 25% | 227d |
| CVE-2025-64328Sangoma / FreePBX | 8.6 | 0.8462top 1% | 236d |
| CVE-2026-21509Microsoft / Office | 7.8 | 0.7287top 1% | 244d |
| CVE-2018-14634Linux / Kernel | 7.8 | 0.1469top 5% | 244d |
| CVE-2025-8110Gogs / Gogs | 8.7 | 0.8520top 1% | 258d |
| CVE-2023-52163Digiever / DS-2105 Pro | 8.8 | 0.9692top 1% | 279d |
| CVE-2025-59374ASUS / Live Update | 9.3 | 0.0120top half | 284d |
| CVE-2018-4063Sierra Wireless / AirLink ALEOS | 8.8 | 0.2706top 5% | 289d |
| CVE-2025-6218RARLAB / WinRAR | 7.8 | 0.9048top 1% | 292d |
| CVE-2021-26828OpenPLC / ScadaBR | 8.8 | 0.3936top 5% | 298d |
| CVE-2021-26829OpenPLC / ScadaBR | 5.4 | 0.4805top 5% | 303d |
| CVE-2025-58034Fortinet / FortiWeb | 7.2 | 0.5558top 1% | 313d |
| CVE-2025-6204Dassault Systèmes / DELMIA Apriso | 8.0 | 0.7796top 1% | 334d |
| CVE-2025-61932Motex / LANSCOPE Endpoint Manager | 9.3 | 0.0277top 25% | 340d |
| CVE-2025-33073Microsoft / Windows | 8.8 | 0.8270top 1% | 342d |
| CVE-2022-48503Apple / Multiple Products | 8.8 | 0.0321top 25% | 342d |
| CVE-2021-22555Linux / Kernel | 8.3 | 0.7868top 1% | 356d |
| CVE-2025-4008Smartbedded / Meteobridge | 8.7 | 0.9367top 1% | 360d |
| CVE-2025-21043Samsung / Mobile Devices | 8.8 | 0.0214top 25% | 360d |
| CVE-2025-32463Sudo / Sudo | 9.3 | 0.6104top 1% | 363d |
| CVE-2025-20352Cisco / IOS and IOS XE | 7.7 | 0.3945top 5% | 363d |
| CVE-2025-59689Libraesva / Email Security Gateway | 6.1 | 0.0186top 25% | 363d |
| CVE-2025-20333Cisco / Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 9.9 | 0.7065top 1% | 367d |
| CVE-2025-9377TP-Link / Multiple Routers | 8.6 | 0.3352top 5% | 389d |
| CVE-2023-50224TP-Link / TL-WR841N | 6.5 | 0.1556top 5% | 389d |
| CVE-2020-24363TP-Link / TL-WA855RE | 8.8 | 0.2069top 5% | 390d |
| CVE-2024-8069Citrix / Session Recording | 5.1 | 0.1464top 5% | 398d |
| CVE-2025-8088RARLAB / WinRAR | 8.4 | 0.9405top 1% | 411d ransomware |
| CVE-2020-25079D-Link / DCS-2530L and DCS-2670L Devices | 8.8 | 0.5401top 5% | 418d |
| CVE-2022-40799D-Link / DNR-322L | 8.8 | 0.3365top 5% | 418d |
| CVE-2023-2533PaperCut / NG/MF | 8.4 | 0.2925top 5% | 426d |
| CVE-2025-49704Microsoft / SharePoint | 8.8 | 1.0000top 1% | 432d ransomware |
| CVE-2023-33538TP-Link / Multiple Routers | 8.8 | 0.4161top 5% | 468d |
| CVE-2025-43200Apple / Multiple Products | 4.2 | 0.0119top half | 468d |
| CVE-2025-24016Wazuh / Wazuh Server | 9.9 | 0.9384top 1% | 474d |
| CVE-2025-27038Qualcomm / Multiple Chipsets | 7.5 | 0.0102top half | 481d |
| CVE-2023-39780ASUS / RT-AX55 Routers | 8.8 | 0.4019top 5% | 482d |
| CVE-2025-3935ConnectWise / ScreenConnect | 8.1 | 0.0351top 25% | 482d |
| CVE-2025-35939Craft CMS / Craft CMS | 6.9 | 0.0132top half | 482d |
| CVE-2025-4428Ivanti / Endpoint Manager Mobile (EPMM) | 7.2 | 0.8652top 1% | 496d |
| CVE-2025-27920Srimax / Output Messenger | 7.2 | 0.0186top 25% | 496d |
| CVE-2025-42999SAP / NetWeaver | 9.1 | 0.1387top 5% | 500d ransomware |
| CVE-2023-44221SonicWall / SMA100 Appliances | 7.2 | 0.7625top 1% | 514d |
| CVE-2025-42599Qualitia / Active! Mail | 9.8 | 0.0330top 25% | 517d |
| CVE-2025-29824Microsoft / Windows | 7.8 | 0.1390top 5% | 537d ransomware |
| CVE-2019-9875Sitecore / CMS and Experience Platform (XP) | 8.8 | 0.1379top 5% | 550d |
| CVE-2025-30154reviewdog / action-setup GitHub Action | 8.6 | 0.0244top 25% | 552d |
| CVE-2025-24201Apple / Multiple Products | 10.0 | 0.0377top 25% | 563d |
| CVE-2025-26633Microsoft / Windows | 7.0 | 0.3039top 5% | 565d ransomware |
| CVE-2024-57968Advantive / VeraCore | 9.9 | 0.3228top 5% | 566d |
| CVE-2022-43769Hitachi Vantara / Pentaho Business Analytics (BA) Server | 8.8 | 0.9767top 1% | 573d |
| CVE-2023-20118Cisco / Small Business RV Series Routers | 6.5 | 0.5411top 5% | 573d |
| CVE-2018-8639Microsoft / Windows | 7.8 | 0.2218top 5% | 573d ransomware |
| CVE-2023-34192Synacor / Zimbra Collaboration Suite (ZCS) | 9.0 | 0.7727top 1% | 579d |
| CVE-2025-24989Microsoft / Power Pages | 8.2 | 0.0162top 25% | 583d |
| CVE-2025-23209Craft CMS / Craft CMS | 8.0 | 0.2178top 5% | 584d |
| CVE-2024-41710Mitel / SIP Phones | 7.2 | 0.4165top 5% | 592d |
| CVE-2024-40891Zyxel / DSL CPE Devices | 8.8 | 0.2154top 5% | 593d |
| CVE-2024-40890Zyxel / DSL CPE Devices | 8.8 | 0.2070top 5% | 593d |
| CVE-2025-0994Trimble / Cityworks | 8.6 | 0.3131top 5% | 597d |
| CVE-2025-04117-Zip / 7-Zip | 7.0 | 0.6707top 1% | 598d |
| CVE-2022-23748Audinate / Dante Discovery | 7.8 | 0.0909top 5% | 598d |
| CVE-2018-9276Paessler / PRTG Network Monitor | 7.2 | 0.8700top 1% | 600d |
| CVE-2025-21333Microsoft / Windows | 7.8 | 0.0999top 5% | 621d |
| CVE-2023-48365Qlik / Sense | 9.6 | 0.4745top 5% | 622d ransomware |
| CVE-2024-12686BeyondTrust / Privileged Remote Access (PRA) and Remote Support (RS) | 6.6 | 0.1370top 5% | 622d |
| CVE-2024-55550Mitel / MiCollab | 2.7 | 0.3790top 5% | 628d ransomware |
| CVE-2021-40407Reolink / RLC-410W IP Camera | 7.2 | 0.4763top 5% | 648d |
| CVE-2019-11001Reolink / Multiple IP Cameras | 7.2 | 0.3754top 5% | 648d |
| CVE-2024-35250Microsoft / Windows | 7.8 | 0.2503top 5% | 650d |
| CVE-2024-49138Microsoft / Windows | 7.8 | 0.2621top 5% | 656d |
| CVE-2023-45727North Grid / Proself | 7.5 | 0.0354top 25% | 663d |
| CVE-2024-11667Zyxel / Multiple Firewalls | 7.5 | 0.0293top 25% | 663d ransomware |
| CVE-2024-21287Oracle / Agile Product Lifecycle Management (PLM) | 7.5 | 0.0172top 25% | 675d |
| CVE-2024-38813VMware / vCenter Server | 7.5 | 0.1736top 5% | 676d |
| CVE-2024-9474Palo Alto Networks / PAN-OS | 6.9 | 0.9470top 1% | 678d ransomware |
| CVE-2024-49039Microsoft / Windows | 8.8 | 0.1418top 5% | 684d ransomware |
| CVE-2024-8957PTZOptics / PT30X-SDI/NDI Cameras | 7.2 | 0.7970top 1% | 692d |
| CVE-2024-38094Microsoft / SharePoint | 7.2 | 0.5089top 5% | 705d ransomware |
| CVE-2024-9537ScienceLogic / SL1 | 9.3 | 0.0383top 25% | 706d |
| CVE-2024-30088Microsoft / Windows | 7.0 | 0.6820top 1% | 712d ransomware |
| CVE-2024-9380Ivanti / Cloud Services Appliance (CSA) | 7.2 | 0.5965top 1% | 718d |
| CVE-2024-9379Ivanti / Cloud Services Appliance (CSA) | 6.5 | 0.4378top 5% | 718d |
| CVE-2024-43572Microsoft / Windows | 7.8 | 0.6670top 1% | 719d |
| CVE-2024-29824Ivanti / Endpoint Manager (EPM) | 8.8 | 0.9994top 1% | 725d |
| CVE-2026-65660Microsoft / SharePoint | 8.8 | 0.0210top 25% | 2d |
| CVE-2026-7273Zyxel / GS1900 Series Switches | 8.8 | 0.0250top 25% | 6d |
| CVE-2025-39964Linux / Kernel | 7.8 | 0.0100top half | 9d |
| CVE-2026-53266Linux / Kernel | 8.8 | 0.0065upper half | 9d |
| CVE-2026-58704Google / Pixel | 8.8 | 0.0059upper half | 11d |
| CVE-2026-87886Acronis / Backup | 7.8 | 0.0023upper half | 11d |
| CVE-2026-42016JFrog / Artifactory | 8.1 | 0.0864top 10% | 16d |
| CVE-2026-84869ConnectWise / ScreenConnect | 9.9 | 0.0092top half | 16d |
| CVE-2026-85880Microsoft / Windows | 7.8 | 0.0362top 25% | 19d |
| CVE-2026-81963Microsoft / Windows | 7.8 | 0.0039upper half | 19d |
| CVE-2026-82078PaperCut / NG/MF | 9.4 | 0.0384top 25% | 27d |
| CVE-2026-53362Linux / Kernel | 7.8 | 0.0071top half | 31d |
| CVE-2026-66384JFrog / Artifactory | 5.3 | 0.0066upper half | 31d |
| CVE-2015-5287Red Hat / Automatic Bug Reporting Tool | 7.8 | 0.0496top 10% | 32d |
| CVE-2026-68820Microsoft / Windows Ancillary Function Driver for WinSock | 7.0 | 0.0033upper half | 47d |
| CVE-2026-56155Microsoft / Active Directory Federation Services | 7.8 | 0.0035upper half | 75d |
| CVE-2026-55255Langflow / Langflow | 8.4 | 0.0089top half | 82d |
| CVE-2026-45659Microsoft / SharePoint Server | 8.8 | 0.0270top 25% | 88d ransomware |
| CVE-2026-54420LiteSpeed / cPanel Plugin | 8.5 | 0.0081top half | 104d |
| CVE-2022-0492Linux / Kernel | 7.8 | 0.0553top 10% | 117d |
| CVE-2025-48595Android / Framework | 8.4 | 0.0171top 25% | 117d |
| CVE-2026-34926Trend Micro / Apex One | 6.7 | 0.0054upper half | 129d |
| CVE-2026-45498Microsoft / Defender | 4.0 | 0.0127top half | 130d |
| CVE-2026-41091Microsoft / Defender | 7.8 | 0.0044upper half | 130d |
| CVE-2026-6973Ivanti / Endpoint Manager Mobile (EPMM) | 7.2 | 0.0254top 25% | 143d |
| CVE-2026-31431Linux / Kernel | 7.8 | 0.0344top 25% | 149d |
| CVE-2026-33825Microsoft / Defender | 7.8 | 0.0040upper half | 158d ransomware |
| CVE-2026-20128Cisco / Catalyst SD-WAN Manager | 7.5 | 0.0780top 10% | 160d |
| CVE-2025-2749Kentico / Kentico Xperience | 7.2 | 0.0405top 10% | 160d |
| CVE-2025-60710Microsoft / Windows | 7.8 | 0.0460top 10% | 167d ransomware |
| CVE-2026-34621Adobe / Acrobat and Reader | 8.6 | 0.0218top 25% | 167d |
| CVE-2026-3502TrueConf / Client | 7.8 | 0.0033upper half | 178d |
| CVE-2026-33634Aquasecurity / Trivy | 9.4 | 0.0168top 25% | 185d |
| CVE-2025-43520Apple / Multiple Products | 5.5 | 0.0043upper half | 191d |
| CVE-2025-43510Apple / Multiple Products | 7.8 | 0.0036upper half | 191d |
| CVE-2021-30952Apple / Multiple Products | 7.8 | 0.0696top 10% | 206d |
| CVE-2023-41974Apple / iOS and iPadOS | 7.8 | 0.0140top half | 206d |
| CVE-2026-21385Qualcomm / Multiple Chipsets | 7.8 | 0.0124top half | 208d |
| CVE-2026-25108Soliton Systems K.K / FileZen | 8.7 | 0.0507top 10% | 215d |
| CVE-2024-7694TeamT5 / ThreatSonar Anti-Ransomware | 7.2 | 0.0181top 25% | 222d |
| CVE-2026-20700Apple / Multiple Products | 7.8 | 0.0134top half | 227d |
| CVE-2026-21525Microsoft / Windows | 6.2 | 0.0480top 10% | 229d |
| CVE-2026-21533Microsoft / Windows | 7.8 | 0.0413top 10% | 229d |
| CVE-2026-21519Microsoft / Windows | 7.8 | 0.0246top 25% | 229d |
| CVE-2026-21514Microsoft / Office | 7.8 | 0.0154top half | 229d |
| CVE-2026-20805Microsoft / Windows | 5.5 | 0.0720top 10% | 257d |
| CVE-2025-40602SonicWall / SMA1000 appliance | 6.6 | 0.0276top 25% | 284d |
| CVE-2025-62221Microsoft / Windows | 7.8 | 0.0250top 25% | 292d |
| CVE-2025-66644Array Networks / ArrayOS AG | 7.2 | 0.0341top 25% | 293d |
| CVE-2025-48633Android / Framework | 5.5 | 0.0026upper half | 299d |
| CVE-2025-48572Android / Framework | 7.8 | 0.0026upper half | 299d |
| CVE-2025-62215Microsoft / Windows | 7.0 | 0.0599top 10% | 319d |
| CVE-2025-41244Broadcom / VMware Aria Operations and VMware Tools | 7.8 | 0.0844top 10% | 332d |
| CVE-2025-24990Microsoft / Windows | 7.8 | 0.0637top 10% | 348d |
| CVE-2025-47827IGEL / IGEL OS | 4.6 | 0.0493top 10% | 348d |
| CVE-2025-59230Microsoft / Windows | 7.8 | 0.0266top 25% | 348d |
| CVE-2025-27915Synacor / Zimbra Collaboration Suite (ZCS) | 5.4 | 0.0399top 10% | 355d |
| CVE-2021-43226Microsoft / Windows | 7.8 | 0.0307top 25% | 356d ransomware |
| CVE-2025-38352Linux / Kernel | 7.8 | 0.0130top half | 388d |
| CVE-2025-48543Android / Runtime | 8.8 | 0.0054upper half | 388d |
| CVE-2025-55177Meta Platforms / WhatsApp | 5.4 | 0.0430top 10% | 390d |
| CVE-2025-48384Git / Git | 8.0 | 0.0411top 10% | 398d |
| CVE-2024-8068Citrix / Session Recording | 5.1 | 0.0348top 25% | 398d |
| CVE-2025-8876N-able / N-Central | 9.4 | 0.0345top 25% | 410d |
| CVE-2025-8875N-able / N-Central | 9.4 | 0.0190top 25% | 410d |
| CVE-2025-48928TeleMessage / TM SGNL | 4.0 | 0.0055upper half | 453d |
| CVE-2019-6693Fortinet / FortiOS | 6.5 | 0.0583top 10% | 459d ransomware |
| CVE-2023-0386Linux / Kernel | 7.8 | 0.0788top 10% | 467d |
| CVE-2025-21479Qualcomm / Multiple Chipsets | 8.6 | 0.0084top half | 481d |
| CVE-2025-21480Qualcomm / Multiple Chipsets | 8.6 | 0.0046upper half | 481d |
| CVE-2025-32706Microsoft / Windows | 7.8 | 0.0229top 25% | 502d |
| CVE-2025-32709Microsoft / Windows | 7.8 | 0.0214top 25% | 502d |
| CVE-2025-30400Microsoft / Windows | 7.8 | 0.0190top 25% | 502d |
| CVE-2025-32701Microsoft / Windows | 7.8 | 0.0139top half | 502d |
| CVE-2025-47729TeleMessage / TM SGNL | 1.9 | 0.0043upper half | 503d |
| CVE-2025-3928Commvault / Web Server | 8.7 | 0.0230top 25% | 517d |
| CVE-2025-1976Broadcom / Brocade Fabric OS | 8.6 | 0.0069top half | 517d |
| CVE-2021-20035SonicWall / SMA100 Appliances | 6.5 | 0.0418top 10% | 529d |
| CVE-2024-53197Linux / Kernel | 7.8 | 0.0356top 25% | 536d |
| CVE-2024-53150Linux / Kernel | 7.1 | 0.0135top half | 536d |
| CVE-2025-21590Juniper / Junos OS | 6.7 | 0.0171top 25% | 563d |
| CVE-2025-24985Microsoft / Windows | 7.8 | 0.0385top 25% | 565d |
| CVE-2025-24993Microsoft / Windows | 7.8 | 0.0217top 25% | 565d |
| CVE-2025-24991Microsoft / Windows | 5.5 | 0.0198top 25% | 565d |
| CVE-2025-24984Microsoft / Windows | 4.6 | 0.0196top 25% | 565d |
| CVE-2025-24983Microsoft / Windows | 7.0 | 0.0135top half | 565d |
| CVE-2025-22226VMware / ESXi, Workstation, and Fusion | 7.1 | 0.0174top 25% | 572d |
| CVE-2025-22224VMware / ESXi and Workstation | 9.3 | 0.0156top half | 572d |
| CVE-2025-22225VMware / ESXi | 8.2 | 0.0100top half | 572d ransomware |
| CVE-2024-50302Linux / Kernel | 5.5 | 0.0081top half | 572d |
| CVE-2024-49035Microsoft / Partner Center | 8.7 | 0.0130top half | 579d |
| CVE-2024-20953Oracle / Agile Product Lifecycle Management (PLM) | 8.8 | 0.0393top 10% | 580d |
| CVE-2025-0111Palo Alto Networks / PAN-OS | 7.1 | 0.0200top 25% | 584d |
| CVE-2025-24200Apple / iOS and iPadOS | 6.1 | 0.0446top 10% | 592d |
| CVE-2025-21391Microsoft / Windows | 7.1 | 0.0230top 25% | 593d |
| CVE-2025-21418Microsoft / Windows | 7.8 | 0.0157top half | 593d |
| CVE-2024-53104Linux / Kernel | 7.8 | 0.0340top 25% | 599d |
| CVE-2025-21334Microsoft / Windows | 7.8 | 0.0156top half | 621d |
| CVE-2025-21335Microsoft / Windows | 7.8 | 0.0139top half | 621d |
| CVE-2024-43093Android / Framework | 7.3 | 0.0072top half | 689d |
| CVE-2024-43047Qualcomm / Multiple Chipsets | 7.8 | 0.0067top half | 719d |
1181 further entries have been in the catalog for over two years and are reported by aggregate rather than paged one by one. A vulnerability exploited for six years is not what is going to cost you, and the pages exist for the ones that are.
Three public sources, no vendor marketing, joined per vulnerability: CISA KEV for exploited status and dates, NVD for the CVSS vector, and EPSS for probability. Every derived field is spelled out, along with what it does not mean.