CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Analyst view

Vulnerabilities and patches

Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers that put confirmed exploitation and internet-facing exposure first, then Exploit Prediction Scoring System (EPSS) likelihood, then how much attention it is getting in the news.

10,716 tracked1,653 in KEV344 actively exploited
Cloud Vulnerabilities

Cloud provider flaws that never receive a CVE identifier.

From the Open Cloud Vulnerability Database.277 tracked
End of Life

Products past end of support. No patch is coming.

From endoflife.date.615 past end of life
Malicious Packages

Compromised and typosquatted packages.

From OpenSSF and OSV.3,517 tracked
OT & ICS

Advisories for operational technology and industrial control systems.

From CISA.282 tracked
Patch Day

Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.

Exploits

Public exploit code and proof-of-concepts.

From Exploit-DB and VulnCheck.
70 matches
CVEPublishedDueVendor / ProductCVSSEPSSKEVStatusMentionsPriority
CVE-2026-63030NEWPoC2026-07-172026-07-24WordPressCoreHIGH7.5v3.198%CISA · 2026-07-24VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.6477
CVE-2026-16232NEW2026-07-222026-07-25Check PointSmartConsoleCRIT9.1v3.1ADP13%CISA · 2026-07-25VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2477
CVE-2026-50751PoC2026-06-082026-06-11Check PointSecurity GatewayCRIT9.3v3.183%CISA · 2026-06-11VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1583
CVE-2026-50522NEW2026-07-142026-07-25MicrosoftSharePointCRIT9.8v3.157%CISA · 2026-07-25VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3479
CVE-2026-8451PoC2026-06-30CitrixNetScaler ADC and NetScaler GatewayHIGH8.8v4.016%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3573
CVE-2026-60137NEWPoC2026-07-172026-08-04WordPressCoreMED5.9v3.178%CISA · 2026-08-04VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.6470
CVE-2026-48908PoC2026-06-202026-07-10JoomShaperSP Page BuilderCRIT10.0v4.088%CISA · 2026-07-10VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0478
CVE-2026-0770NEWPoC2026-01-232026-07-24LangflowLangflowCRIT9.8v3.053%CISA · 2026-07-24VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1478
CVE-2026-56290PoC2026-06-292026-07-10JoomlackPage BuilderCRIT10.0v4.083%CISA · 2026-07-10VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0478
CVE-2026-15409PoC2026-07-142026-07-17SonicWallSMA1000 AppliancesCRIT10.0v3.178%CISA · 2026-07-17VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4480
CVE-2026-154102026-07-142026-07-17SonicWallSMA1000 AppliancesHIGH7.2v3.176%CISA · 2026-07-17VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4475
CVE-2026-48282PoC2026-06-302026-07-10AdobeColdFusionCRIT10.0v3.199%CISA · 2026-07-10VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2479
CVE-2026-56291PoC2026-07-092026-07-13BalbooaFormsCRIT10.0v4.076%CISA · 2026-07-13VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1478
CVE-2026-34908PoC2026-05-222026-06-26UbiquitiUniFi OSCRIT10.0v3.158%CISA · 2026-06-26VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0478
CVE-2026-34909PoC2026-05-222026-06-26UbiquitiUniFi OSCRIT10.0v3.157%CISA · 2026-06-26VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0478
CVE-2021-27137NEWPoC2026-07-162026-07-24DD-WRTDD-WRTHIGH8.1v3.116%CISA · 2026-07-24VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1475
CVE-2026-20230PoC2026-06-032026-06-28CiscoUnified Communications ManagerHIGH8.6v3.181%CISA · 2026-06-28VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0476
CVE-2026-250892026-06-092026-07-19FortinetFortiSandboxCRIT9.8v3.170%CISA · 2026-07-19VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0478
CVE-2026-20127PoC2026-02-252026-02-27CiscoCatalyst SD-WAN Controller and ManagerCRIT10.0v3.188%CISA · 2026-02-27VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1478
CVE-2013-33072025-07-11x3000_firmwareLinksysHIGH8.3v3.153%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0461
CVE-2026-8037PoC2026-06-04ProgressloadmasterCRIT9.6v3.185%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2466
CVE-2026-55255PoC2026-06-232026-07-10LangflowLangflowHIGH8.4v3.129%CISA · 2026-07-10VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1476
CVE-2021-226812021-03-032026-03-26RockwellMultiple ProductsCRIT9.8v3.151%CISA · 2026-03-26VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0477
CVE-2025-30066PoC2025-03-152025-04-08tj-actionschanged-files GitHub ActionHIGH8.6v3.172%CISA · 2025-04-08VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0471
CVE-2026-48939PoC2026-06-202026-07-13iCagendaiCagendaCRIT10.0v4.024%CISA · 2026-07-13VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2478
CVE-2026-20896PoC2026-07-03GiteaGitea Open Source Git ServerCRIT9.8v3.132%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2469
CVE-2025-21042PoC2025-09-122025-12-01SamsungMobile DevicesHIGH8.8v3.133%CISA · 2025-12-01VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0476
CVE-2026-68752026-07-13ServiceNowServiceNow AI PlatformCRIT9.5v4.024%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2469
CVE-2025-670382026-03-112026-06-26LantronixEDS5000CRIT9.8v3.114%CISA · 2026-06-26VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0477
CVE-2026-468172026-05-282026-07-18OracleE-Business SuiteCRIT9.8v3.113%CISA · 2026-07-18VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3478
CVE-2026-201332026-02-252026-04-23CiscoCatalyst SD-WAN ManagerMED6.5v3.131%CISA · 2026-04-23VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2026-20122PoC2026-02-252026-04-23CiscoCatalyst SD-WAN MangerMED5.4v3.125%CISA · 2026-04-23VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0471
CVE-2026-202622026-06-152026-06-29CiscoCatalyst SD-WAN ManagerMED6.5v3.128%CISA · 2026-06-29VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2026-48558PoC2026-06-122026-07-02SimpleHelp SimpleHelpCRIT9.5v4.011%CISA · 2026-07-02VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2477
CVE-2025-8088PoC2025-08-082025-09-02RARLABWinRARHIGH8.4v4.095%CISA · 2025-09-02VulnCheckENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0473
CVE-2026-28496PoC2026-06-23fossbillingfossbillingCRIT9.4v4.018%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2026-561642026-07-142026-07-17MicrosoftSharePoint ServerMED5.3v3.118%CISA · 2026-07-17VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.7468
CVE-2026-21445PoC2026-01-02langflowlangflowHIGH8.8v4.034%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2019-112482019-08-29kuberneteskubernetesHIGH8.2v3.175%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0466
CVE-2025-34509PoC2025-06-17SitecoreExperience Manager (XM)/Experience Platform (XP)HIGH7.5v3.153%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0465
CVE-2026-490492026-06-29joomshaper.comHelix3 extension for JoomlaHIGH7.5v3.118%ENISAIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0460
CVE-2026-584552026-07-02NotifiarrDockwatchCRIT9.2v4.05%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0466
CVE-2016-48002017-04-13eclipsejettyCRIT9.8v3.06%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2026-4480PoC2026-05-26Red Hatopenshift_container_platformCRIT9.0v3.114%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0467
CVE-2026-48611PoC2026-06-12phpbbphpbbCRIT9.8v3.04%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0466
CVE-2016-3081PoC2016-04-26ApacheStrutsHIGH8.1v3.093%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0466
CVE-2025-684932026-01-11ApacheStrutsHIGH8.1v3.123%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0461
CVE-2026-167232026-07-23AlibabaFastjsonCRIT9.0v3.10%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1453
CVE-2005-08692005-05-02phpsysinfophpsysinfoMED5.0v2.05%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0455
CVE-2007-66722008-01-08mortbay_jettyjettyMED5.0v2.04%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454
CVE-2026-44825PoC2026-06-01ApacheSolrHIGH8.1v3.11%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454
CVE-2025-4283PoC2025-05-05oretnom23stock_management_systemMED6.9v4.01%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0447
CVE-2026-84962026-05-13Alinto SOGoSOGoMED6.1v3.10%VulnCheckIn an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0443
CVE-2026-483192026-07-14AdobeColdFusionCRIT9.1v3.127%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0243
CVE-2026-454842026-06-09MicrosoftMicrosoft SharePoint Enterprise Server 2016HIGH8.8v3.127%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0243
CVE-2026-482842026-07-14AdobeColdFusionCRIT9.6v3.128%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0241
CVE-2026-483182026-07-14AdobeColdFusionCRIT9.9v3.123%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0244
CVE-2026-483562026-07-14AdobeCommerceCRIT9.6v3.128%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0244
CVE-2026-455022026-06-09MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 14MED5.0v3.120%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0232
CVE-2026-571062026-07-24MicrosoftMicrosoft Purview Data GovernanceCRIT10.0v3.1CNA1%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0235
CVE-2026-561632026-07-24MicrosoftAzure Kubernetes ServiceCRIT10.0v3.1CNA1%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0235
CVE-2026-586302026-07-24MicrosoftAzure App Service for LinuxCRIT10.0v3.1CNA1%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0235
CVE-2026-628352026-07-24MicrosoftOnline ServicesCRIT9.3v3.1CNA1%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0130
CVE-2026-164202026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.8v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0128
CVE-2026-164212026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.8v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0127
CVE-2026-164182026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.8v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0125
CVE-2026-164192026-07-21MicrosoftMicrosoft Edge (Chromium-based)CRIT9.6v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0125
CVE-2026-164132026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.3v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0123
CVE-2026-164162026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.3v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0118
CVE-2026-164142026-07-21MicrosoftMicrosoft Edge (Chromium-based)HIGH8.3v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.0118
How scores and priority work

The effective Common Vulnerability Scoring System (CVSS) score uses a strict precedence: the National Vulnerability Database (NVD) score when present (latest version, v4.0 then v3.1, v3.0, and v2.0), else the CVE Numbering Authority (CNA) score from the CVE record, else the Authorized Data Publisher (ADP) score. A CNA or ADP score is labeled with a chip beside the version chip; once NVD publishes its analysis the score is replaced and relabeled. Priority is a tier first and a rank within that tier, never a raw sum, so the number is tier major: the five tiers ascend Track, Track*, Attend, Act, and Act now, and any Act now item outranks any Act item, so a quiet high severity CVE can never outrank one that is actively exploited and internet facing. The tier is set by exploitation first, on a single ladder from proof of concept up through active and ransomware use that the Known Exploited Vulnerabilities (KEV) catalogs and the CISA Vulnrichment exploitation signal feed rather than stack, then a Stakeholder Specific Vulnerability Categorization (SSVC) style decision computed by this tracker, whose foundation is the CISA Vulnrichment program's published SSVC judgments wherever they have been ingested for the CVE, with the automatability and technical impact inputs derived here from CVSS only where no CISA judgment is stored (those two inputs are labeled with their source on the CVE panel), then exposure, then Exploit Prediction Scoring System (EPSS) probability. The exploitation ladder, exposure, and End of Life only ever raise the tier above what that SSVC decision implies, never lower it. Exposure counts as open only when the attack vector is Network and the product is a curated internet facing class such as a firewall, a virtual private network gateway, or an edge router, never from Network alone. End of Life raises the tier by at most one step, and only when the product is both internet facing exposed and actively exploited, never on its own. Within a tier, the rank draws on exploitation, EPSS, CVSS, exposure, KEV due date proximity, news mentions, and KEV corroboration, each counted once. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. The All Tracked view filters on a published-date window: a segment shows only CVEs published within it, so the default view shows what is genuinely new rather than years-old maximum-priority entries; Movers is unchanged. The Published column shows only a date an authority stated (NVD or the CVE record); a CVE tracked here without one shows a dash, with the first-tracked date in the dash's tooltip, and sorts below every dated row. The window segments filter on the CVE's published date, whatever its provenance; recent movement on older CVEs, such as a fresh KEV addition to an old CVE, appears in Movers, not in the windows.

Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked KEV entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. kev-listed: In an exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. Dash: Tracked from news, advisories, or scoring feeds with no exploitation signal from any catalog yet.

Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: EPSS (Exploit Prediction Scoring System) is the probability that a vulnerability will be exploited in the wild within the next 30 days, shown here as a percentage.

What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.

Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA or ADP marks a score awaiting NVD analysis. Movers: added to KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to KEV in the last 7 days are marked NEW.