CVE Database
Every vulnerability CISA records as exploited in the wild — 1,715 of them — with severity, exploitation probability, remediation deadlines, and the ransomware groups recorded using each one.
Showing 1–60 of 1,715.
| CVE | Vulnerability | Severity | EPSS | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-84869 |
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect
|
CRITICAL 9.9 | 0.7% | 11 Sep 2026 | — |
| CVE-2026-42016 |
JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory
|
HIGH 8.1 | 0.9% | 11 Sep 2026 | — |
| CVE-2026-42018 |
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory
|
HIGH 7.5 | 0.9% | 11 Sep 2026 | — |
| CVE-2026-85706 |
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition
|
CRITICAL 10 | 1.2% | 11 Sep 2026 | — |
| CVE-2026-86060 |
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS
|
CRITICAL 9.8 | 1% | 10 Sep 2026 | — |
| CVE-2026-67277 |
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS
|
HIGH 8.2 | 0.9% | 10 Sep 2026 | — |
| CVE-2026-19490 |
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler
|
CRITICAL 9.8 | 5.6% | 9 Sep 2026 | — |
| CVE-2025-25249 |
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet Multiple Products
|
HIGH 8.1 | 2.4% | 9 Sep 2026 | — |
| CVE-2026-87491 |
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8
|
HIGH 8.8 | 0.9% | 9 Sep 2026 | — |
| CVE-2026-20079 |
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
|
CRITICAL 10 | 75.8% | 9 Sep 2026 | — |
| CVE-2026-75650 |
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento
|
CRITICAL 10 | 2.1% | 8 Sep 2026 | — |
| CVE-2026-81963 |
Microsoft Windows Link Following Vulnerability
Microsoft Windows
|
HIGH 7.8 | 0.6% | 8 Sep 2026 | — |
| CVE-2026-86218 |
N-able N-central Static Code Injection Vulnerability
N-able N-central
|
CRITICAL 9.8 | 0.7% | 8 Sep 2026 | — |
| CVE-2026-85880 |
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows
|
HIGH 7.8 | 0.6% | 8 Sep 2026 | — |
| CVE-2026-85046 |
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8
|
HIGH 8.8 | 1.3% | 4 Sep 2026 | — |
| CVE-2026-59822 |
BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM
|
HIGH 8.2 | 0.9% | 2 Sep 2026 | — |
| CVE-2026-48710 |
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette
|
MEDIUM 6.5 | 36.3% | 2 Sep 2026 | — |
| CVE-2026-49869 |
Kestra OSS OS Command Injection Vulnerability
Kestra OSS
|
CRITICAL 10 | 1.9% | 2 Sep 2026 | — |
| CVE-2026-82329 |
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory
|
CRITICAL 9.8 | 7.7% | 2 Sep 2026 | — |
| CVE-2026-9586 |
Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox
|
CRITICAL 9.8 | 11.8% | 2 Sep 2026 | — |
| CVE-2026-83548 |
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances
|
CRITICAL 10 | 4.7% | 2 Sep 2026 | — |
| CVE-2026-83549 |
SonicWall SMA1000 Appliances OS Command Injection Vulnerability
SonicWall SMA1000 Appliances
|
HIGH 7.8 | 8.5% | 2 Sep 2026 | — |
| CVE-2026-82078 |
PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut NG/MF
|
CRITICAL 9.1 | 1.7% | 31 Aug 2026 | — |
| CVE-2026-81578 |
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF
|
CRITICAL 9.8 | 1.6% | 31 Aug 2026 | — |
| CVE-2023-49105 |
ownCloud Improper Authentication Vulnerability
ownCloud ownCloud
|
CRITICAL 9.8 | 43.2% | 27 Aug 2026 | — |
| CVE-2026-53362 |
Linux Kernel Unspecified Vulnerability
Linux Kernel
|
HIGH 7.8 | 0.5% | 27 Aug 2026 | — |
| CVE-2026-66384 |
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
JFrog Artifactory
|
MEDIUM 5.3 | 0.6% | 27 Aug 2026 | — |
| CVE-2021-23758 |
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional Ajax.NET Professional
|
HIGH 8.1 | 83.6% | 26 Aug 2026 | — |
| CVE-2015-3246 |
Red Hat Libuser Race Condition Vulnerability
Red Hat Libuser
|
MEDIUM 5.1 | 8.8% | 26 Aug 2026 | — |
| CVE-2015-5287 |
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat Automatic Bug Reporting Tool
|
HIGH 7.8 | 5% | 26 Aug 2026 | — |
| CVE-2022-0995 |
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel
|
HIGH 7.8 | 9.5% | 26 Aug 2026 | — |
| CVE-2026-8452 |
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway
|
CRITICAL 9.8 | 1.6% | 26 Aug 2026 | — |
| CVE-2019-1068 |
Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server
|
HIGH 8.8 | 52.8% | 26 Aug 2026 | — |
| CVE-2026-60004 |
Gitea Code Injection Vulnerability
Gitea Gitea
|
CRITICAL 9.8 | 86.8% | 25 Aug 2026 | — |
| CVE-2026-21962 |
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
|
CRITICAL 10 | 42% | 24 Aug 2026 | — |
| CVE-2026-73570 |
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Synacor Zimbra Collaboration Suite (ZCS)
|
HIGH 8.9 | 32.4% | 21 Aug 2026 | — |
| CVE-2026-72530 |
TrueConf Server Code Injection Vulnerability
TrueConf Server
|
CRITICAL 9 | 1.8% | 20 Aug 2026 | — |
| CVE-2026-72529 |
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server
|
CRITICAL 9.8 | 1.6% | 20 Aug 2026 | — |
| CVE-2026-64849 |
MLflow Server-Side Request Forgery Vulnerability
MLflow MLflow
|
CRITICAL 9.3 | 16.4% | 19 Aug 2026 | — |
| CVE-2026-33824 |
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions
|
CRITICAL 9.8 | 72.7% | 18 Aug 2026 | — |
| CVE-2026-59310 |
Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom VMware vCenter
|
CRITICAL 9.8 | 45.9% | 18 Aug 2026 | CISA: known use |
| CVE-2026-55040 |
Microsoft SharePoint Weak Authentication Vulnerability
Microsoft SharePoint
|
CRITICAL 9.1 | 50.6% | 18 Aug 2026 | — |
| CVE-2026-65400 |
Apple macOS Improper Authentication Vulnerability
Apple macOS
|
CRITICAL 9.8 | 9.9% | 18 Aug 2026 | — |
| CVE-2025-62593 |
Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray
|
HIGH 8.8 | 16.9% | 17 Aug 2026 | — |
| CVE-2026-20349 |
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
|
HIGH 8.6 | 2.2% | 11 Aug 2026 | — |
| CVE-2026-68820 |
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock
|
HIGH 7 | 6.2% | 11 Aug 2026 | — |
| CVE-2026-72898 |
Metabase SQL Injection Vulnerability
Metabase Metabase
|
CRITICAL 10 | 94.2% | 11 Aug 2026 | — |
| CVE-2026-8037 |
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster
|
CRITICAL 9.6 | 99.6% | 7 Aug 2026 | — |
| CVE-2026-63077 |
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains TeamCity
|
CRITICAL 9.8 | 86.5% | 5 Aug 2026 | — |
| CVE-2026-18556 |
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central
|
HIGH 7.4 | 40.2% | 4 Aug 2026 | — |
| CVE-2026-34486 |
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat
|
HIGH 7.5 | 98.6% | 4 Aug 2026 | — |
| CVE-2026-9198 |
IBM Langflow Code Injection Vulnerability
IBM Langflow
|
CRITICAL 9.8 | 60.6% | 4 Aug 2026 | — |
| CVE-2026-18577 |
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central
|
HIGH 8.1 | 54.1% | 3 Aug 2026 | — |
| CVE-2026-20316 |
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC)
|
MEDIUM 5.3 | 11.2% | 29 Jul 2026 | CISA: known use |
| CVE-2025-68686 |
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS
|
MEDIUM 5.9 | 29.6% | 27 Jul 2026 | — |
| CVE-2026-16812 |
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator
|
CRITICAL 10 | 1.6% | 27 Jul 2026 | — |
| CVE-2026-16232 |
Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole
|
CRITICAL 9.1 | 72.1% | 22 Jul 2026 | — |
| CVE-2026-50522 |
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint
|
CRITICAL 9.8 | 85.4% | 22 Jul 2026 | — |
| CVE-2026-60137 |
WordPress Core SQL Injection Vulnerability
WordPress Core
|
MEDIUM 5.9 | 78.3% | 21 Jul 2026 | — |
| CVE-2026-63030 |
WordPress Core Interpretation Conflict Vulnerability
WordPress Core
|
CRITICAL 9.8 | 97.3% | 21 Jul 2026 | — |
Catalogue and remediation deadlines from the CISA Known Exploited Vulnerabilities list; severity from NVD; exploitation probability from FIRST EPSS; ransomware group attribution from ransomware.live. Where a severity or EPSS score is missing, that vulnerability has not been enriched yet — the catalogue entry itself is still authoritative.