CYBERSECURITYTRACKER
TRACKING4,114 stories770 vuln stories
Analyst view

Vulnerabilities and patches

Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers that put confirmed exploitation and internet-facing exposure first, then Exploit Prediction Scoring System (EPSS) likelihood, then how much attention it is getting in the news.

13,944 tracked1,665 in CISA KEV366 actively exploited
Skip to ranked Common Vulnerabilities and Exposures (CVE) table
Cloud Vulnerabilities

Cloud provider flaws that never receive a CVE identifier.

From the Open Cloud Vulnerability Database.277 tracked
End of Life

Products past end of support. No patch is coming.

From endoflife.date.632 past end of life
Malicious Packages

Compromised and typosquatted packages.

From OpenSSF and OSV.6,558 tracked
OT & ICS

Advisories for operational technology and industrial control systems.

From CISA.323 tracked
Patch Day

Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.

Exploits

Public exploit code and proof-of-concepts.

From Exploit-DB and VulnCheck.
83 matches

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

ChangedOur evidence
CVE-2026-34908PoCExploit Prediction Scoring System probability jumped · 2026-08-15Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.UbiquitiUniFi OSCRIT10.0v3.185%CISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0470.6Act7th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-48907PoCExploit Prediction Scoring System probability jumped · 2026-08-15Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Widget FactoryJoomla Content Editor CRIT10.0v4.066%CISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2469.7Act26th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-72898NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-11Exploitation status turned active · 2026-08-10Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.MetabaseMetabaseCRIT10.0v4.010%CISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1467.7Act70th of 4,313 tracked, non-rejected CVEs in Act
CVE-2025-49132PoCExploit Prediction Scoring System probability jumped · 2026-08-15Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.pterodactylpanelCRIT10.0v3.153%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1463.7Act546th of 4,313 tracked, non-rejected CVEs in Act
CVE-2024-56064PoCExploit Prediction Scoring System probability jumped · 2026-08-15Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Azzaroco WP SuperBackupAzzaroco WP SuperBackupCRIT10.0v3.130%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0462.4Act704th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-26190PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.milvusmilvusCRIT9.8v3.137%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0458.6Act1182nd of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-55040PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-12Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.MicrosoftOffice SharePointCRIT9.1v3.14%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.7457.9Act1372nd of 4,313 tracked, non-rejected CVEs in Act
CVE-2025-55583PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.D-Linkdir-868l_firmwareCRIT9.8v3.16%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0457.0Act1598th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-55450PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-09Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.langflowlangflowCRIT9.3v3.112%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0454.2Act2252nd of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-20349NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Exploitation status turned active · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.CiscoSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) HIGH8.6v3.11%CISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2453.9Act2327th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-49049PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.joomshaper.comHelix3 extension for JoomlaHIGH7.5v3.118%VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0453.1Act2457th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-59310Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-10Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.VMwareCloud FoundationCRIT9.8v3.11%VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2452.9Act2475th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-58231Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-14Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.SAPCommerce CloudCRIT10.0v3.11%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1452.3Act2551st of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-33497PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.langflowlangflowHIGH8.7v4.020%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0451.5Act2671st of 4,313 tracked, non-rejected CVEs in Act
CVE-2025-10123PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.D-Linkdir-823x_firmwareMED5.5v4.04%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0449.7Act2975th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-59309Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-14Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.VMwarevCenterCRIT9.8v3.11%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2448.7Act3149th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-48294Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-10Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.AdobeAcrobat and ReaderHIGH7.4v3.12%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1448.6Act3171st of 4,313 tracked, non-rejected CVEs in Act
CVE-2019-25765PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.ASP-CMS ProjectASP-CMSHIGH8.7v4.01%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0446.2Act3535th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-68820NEWAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-08-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Exploitation status turned active · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.MicrosoftWindows Ancillary Function Driver for WinSock HIGH7.0v3.10%CISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4445.4Act3615th of 4,313 tracked, non-rejected CVEs in Act
CVE-2016-20097PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Weaver Network Co., Ltd.E-cology 8.0HIGH8.7v4.00%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0444.9Act3658th of 4,313 tracked, non-rejected CVEs in Act
CVE-2008-3873Exploit Prediction Scoring System probability jumped · 2026-08-15Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.AdobeFlash PlayerMED4.3v2.016%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0443.6Act3778th of 4,313 tracked, non-rejected CVEs in Act
CVE-2024-58374PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Hongjing Centurye-HRHIGH8.7v4.00%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0440.8Act3986th of 4,313 tracked, non-rejected CVEs in Act
CVE-2022-50997PoCAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-11Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Weaver Network Co., Ltd.E-cology 9.0HIGH8.7v4.00%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0440.7Act3997th of 4,313 tracked, non-rejected CVEs in Act
CVE-2020-9771Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-13Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.AppleMacOS XHIGH7.1v3.10%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0439.0Act4088th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-66443Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-10Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.Pete NelsonREST API LogHIGH7.5v3.1CNA0%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0437.6Act4153rd of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-66441Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-10Our evidence: strongDocumentation coverage only. This is not a statement of vulnerability risk.MultiVendorXMultiVendorXHIGH7.5v3.1CNA0%VulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0437.2Act4164th of 4,313 tracked, non-rejected CVEs in Act
CVE-2026-72851PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseCRIT9.0v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0331.0Attend156th of 195 tracked, non-rejected CVEs in Attend
CVE-2026-73486PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.FlowiseFlowiseCRIT9.0v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0231.8Track*231st of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73332PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.CamaleonCMScama_contact_formCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0229.9Track*371st of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72789PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.SiYuanSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0228.5Track*509th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72840PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.OpenWrtLuCIHIGH8.7v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0228.5Track*510th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72794PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-notesiyuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0227.5Track*622nd of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73608PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-noteSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0227.3Track*649th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72795PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.SiYuanSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0227.3Track*650th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72793PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.SiYuanSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0227.3Track*651st of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72857PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseHIGH8.3v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0225.3Track*982nd of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72801PoCA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-noteSiYuanHIGH8.7v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0224.2Track*1142nd of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73678A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.MindsDBMinds PlatformCRIT10.0v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0221.3Track*1412th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-72856A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseHIGH8.6v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0220.5Track*1454th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73682A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.semaphoreuiSemaphoreHIGH8.7v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0215.9Track*1490th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73680A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.CockpitCMSHIGH8.7v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0215.9Track*1491st of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-73679A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.ImpressCMSImpressCMSHIGH8.6v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0215.0Track*1496th of 1,498 tracked, non-rejected CVEs in Track*
CVE-2026-8715A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.HashiCorpVault Secrets OperatorCRIT9.6v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0124.1Track1112th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-73485A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.FlowiseAIFlowiseCRIT9.0v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0122.6Track1783rd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-73269A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Red Hatcluster-curator-controllerCRIT9.9v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0122.6Track1804th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72807A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-noteSiYuanHIGH8.8v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0121.6Track2266th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72772A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.n8n-ion8nHIGH8.9v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.9Track2682nd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72853A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseHIGH8.8v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.6Track2798th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-64954A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.VelociraptorVelociraptorHIGH8.2v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.4Track2884th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72534A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Authentik SecurityauthentikHIGH8.8v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.3Track2943rd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-67365A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.icagenda.comiCagenda extension for JoomlaCRIT9.2v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.3Track2944th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66472A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.EverestBackupCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2993rd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-61969A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Webilia Inc.ListdomCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2994th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66659A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.EssekiaTablesome TableCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2995th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66478A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.andy_moyleChurch AdminCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2996th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66458A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.RealPressRealPressCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2997th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66436A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.WooCommerceActive Products Tables for WooCommerceCRIT9.3v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.2Track2998th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72537A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Authentik SecurityauthentikHIGH8.8v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0120.0Track3104th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66154A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.SonicWallGMSHIGH8.3v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0119.7Track3217th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72798A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-noteSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0119.3Track3453rd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72804A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.siyuan-noteSiYuanCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0119.3Track3460th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66658A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.MVPThemesReviewerHIGH8.5v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0119.0Track3601st of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-66430A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.CODEPRESSVisitor Traffic Real Time Statistics ProHIGH8.5v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0119.0Track3602nd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72849A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseHIGH8.7v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.9Track3642nd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72562A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Pimcoreadmin-ui-classic-bundleHIGH8.8v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.8Track3705th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72558A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.CiviCRMCiviCRMHIGH8.8v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.8Track3706th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72561A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Peppermint LabPeppermintHIGH8.8v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.6Track3782nd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72766A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.n8nn8nHIGH8.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.6Track3819th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72555A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Peppermint LabPeppermintHIGH8.1v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.5Track3848th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-67986A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.amazing-printamazing_printHIGH8.4v3.1ADP0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.5Track3854th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72665A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.ElasticKibanaHIGH8.1v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0118.2Track3980th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-73683A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.LaravelSocialiteCRIT9.2v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.8Track4197th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-6484A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Insyde SoftwareUEFIHIGH8.2v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.7Track4215th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72855A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BudibaseBudibaseHIGH8.4v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.5Track4362nd of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-73329A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-12Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.CamaleonCMSCamaleonCMSCRIT9.2v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.4Track4379th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-55402A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Secure AccessSecure AccessHIGH8.7v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.4Track4397th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-73673A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.NetisNC63 router firmwareHIGH8.7v4.0CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.2Track4474th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72595A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BadChoiceHandeskHIGH8.1v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.0Track4508th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72563A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.BadChoiceHandeskHIGH8.1v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0117.0Track4509th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72970A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-14Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.MicrosoftMicrosoft Edge (Chromium-based)HIGH8.3v3.1CNATracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0116.7Track4636th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-63423A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.LenovoAccessories and Display ManagerHIGH8.5v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0116.5Track4701st of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-63425A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-13Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.LenovoDock ManagerHIGH8.5v4.0CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0115.9Track4958th of 7,099 tracked, non-rejected CVEs in Track
CVE-2026-72596A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-11Our evidence: mixedDocumentation coverage only. This is not a statement of vulnerability risk.Ghost FoundationGhostHIGH8.1v3.1CNA0%Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0113.1Track5982nd of 7,099 tracked, non-rejected CVEs in Track
How scores and priority work

The effective Common Vulnerability Scoring System (CVSS) score uses a strict precedence: the National Vulnerability Database (NVD) score when present (latest version, v4.0 then v3.1, v3.0, and v2.0), else the CVE Numbering Authority (CNA) score from the CVE record, else the Authorized Data Publisher (ADP) score. A CNA or ADP score is labeled with a chip beside the version chip; once NVD publishes its analysis the score is replaced and relabeled. Priority is a tier first and a rank within that tier, never a raw sum, so the number is tier major: the five tiers ascend Track, Track*, Attend, Act, and Act now, and any Act now item outranks any Act item, so a quiet high severity CVE can never outrank one that is actively exploited and internet facing. The tier is set by exploitation first, on a single ladder from proof of concept up through active and ransomware use that the tracked exploitation catalogs and the CISA Vulnrichment exploitation signal feed rather than stack, then a Stakeholder Specific Vulnerability Categorization (SSVC) style decision computed by this tracker, whose foundation is the CISA Vulnrichment program's published SSVC judgments wherever they have been ingested for the CVE, with the automatability and technical impact inputs derived here from CVSS only where no CISA judgment is stored (those two inputs are labeled with their source on the CVE panel), then exposure, then Exploit Prediction Scoring System (EPSS) probability. The exploitation ladder, exposure, and End of Life only ever raise the tier above what that SSVC decision implies, never lower it. Exposure counts as open only when the attack vector is Network and the product is a curated internet facing class such as a firewall, a virtual private network gateway, or an edge router, never from Network alone. End of Life raises the tier by at most one step, and only when the product is both internet facing exposed and actively exploited, never on its own. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. The All Tracked view filters on a published-date window: a segment shows only CVEs published within it, so the default view shows what is genuinely new rather than years-old maximum-priority entries; Movers is unchanged. The Published column shows only a date an authority stated (NVD or the CVE record); a CVE tracked here without one shows a dash, with the first-tracked date in the dash's tooltip, and sorts below every dated row. The window segments filter on the CVE's published date, whatever its provenance; recent movement on older CVEs, such as a fresh CISA KEV addition to an old CVE, appears in Movers, not in the windows.

Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. Dash: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.

Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.

Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA or ADP marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.