CYBERSECURITYTRACKER
TRACKING6,767 stories in this site build1,408 vulnerability news stories in this site build

State now. Changed: +4 tier promotions, +1 known-exploited vulnerability addition, 66 leak-site claims, and 6 confirmed breaches since yesterday.

Why today matters · Vulnerability view

Vulnerabilities and patches

Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers. A Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) listing or other confirmed exploitation never ranks below Act. Ransomware association reaches Act now; active exploitation can also rise one tier through either the end-of-life or open-exposure modifier.

Why now: this site build includes 1,691 actively exploited records; the ranked details below show their evidence and actions.

19,076 tracked CVE records in this site build1,710 in CISA KEV1,691 actively exploited records in this site build

Choose your reading level

The page address stays the same, and this choice follows you to other pages.

Analyst view shows the full table.

State now

946 tracked CVEs are in the Act now tier in this site build.

Why these records matter

Details

The legend explains every priority and status label, and the filters sit beside the ranked records below.

Skip to ranked Common Vulnerabilities and Exposures (CVE) table
Deadline quick view

Federal remediation deadline backlog

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.

  1. OverdueCalculating
  2. Due in 0 to 7 daysCalculating
  3. Due in 8 to 14 daysCalculating
  4. Due in 15 to 30 daysCalculating

Counts use this device's current date. Calculating the backlog.

Cloud Vulnerabilities

Cloud provider flaws that never receive a CVE identifier.

From the Open Cloud Vulnerability Database.277 tracked
End of Life

Release cycles past End of Life. No patch is coming.

From endoflife.date.631 past end of life
Malicious Packages

Compromised and typosquatted packages.

From OpenSSF and OSV.3,165 tracked
OT & ICS

Advisories for operational technology and industrial control systems.

From CISA.356 tracked
Patch Day

Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.

Exploits

Public exploit code and proof-of-concepts.

From Exploit-DB and VulnCheck.
108 matches
In this view:Act now6Act55Attend0Track*0Track47

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.

Table legend

What each badge means

Open the full glossary

Tiers ascend Track (watch), Track* (a public exploit or a rising exploitation forecast), Attend (act in the normal cycle),Act (confirmed exploitation somewhere), and Act now(ransomware association, or active exploitation raised by the end-of-life or open-exposure modifier). A lower tier can never outrank a higher one. A Mentions count of 0 is a measured zero: the tracker looked and found no coverage, rather than not having looked.

Changed
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09CitrixNetScalerCRIT9.3v4.06%+2.2pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act now, 69 of 99Act now181st of 944 tracked, non-rejected CVEs in Act now
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-14Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Exploitation status turned active · 2026-09-14News coverage surged · 2026-09-15CiscoSecure Email GatewayCRIT9.8v3.12%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3Act now, 61 of 99Act now491st of 944 tracked, non-rejected CVEs in Act now
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Not applicable outside CISA KEVMicrosoftWindowsHIGH7.5v3.16%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 53 of 99Act now747th of 944 tracked, non-rejected CVEs in Act now
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08MicrosoftWindowsHIGH7.8v3.11%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.7Act now, 53 of 99Act now761st of 944 tracked, non-rejected CVEs in Act now
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08MicrosoftWindowsHIGH7.8v3.11%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act now, 52 of 99Act now781st of 944 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Not applicable outside CISA KEVFortinetFortiOSMED4.8v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 36 of 99Act now933rd of 944 tracked, non-rejected CVEs in Act now
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Exploitation status turned active · 2026-09-09CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCRIT10.0v3.176%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.6Act, 71 of 99Act3rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-15SimpleHelp SimpleHelpCRIT9.5v4.064%+34.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4Act, 71 of 99Act4th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Exploitation status turned active · 2026-09-11A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-12News coverage surged · 2026-09-14GitLabCommunity Edition and Enterprise EditionCRIT10.0v3.1CNA12%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.8Act, 71 of 99Act5th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-15MicrosoftSharePointCRIT9.1v3.151%+10.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.8Act, 69 of 99Act37th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08AdobeCommerce and MagentoCRIT10.0v3.12%+1.5pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act, 68 of 99Act60th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-15Not applicable outside CISA KEVpaperclipaipaperclipCRIT10.0v3.119%+14.2pp vs 7d agoVulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 63 of 99Act604th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08FortinetMultiple ProductsHIGH8.1v3.12%+1.6pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 61 of 99Act838th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-08N-ableN-centralCRIT10.0v4.01%+0.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4Act, 60 of 99Act915th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-10Exploitation status turned active · 2026-09-08MikroTikRouterOSCRIT9.2v4.01%+0.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4Act, 59 of 99Act947th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVsalesagilitysuitecrmCRIT10.0v3.16%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1069th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Not applicable outside CISA KEVJoomla!Joomla!CRIT9.8v3.0100%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1083rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Not applicable outside CISA KEVXWikixwikiCRIT9.9v3.192%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1205th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-15Not applicable outside CISA KEVhoneywellpm43_firmwareCRIT9.9v3.149%+16.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1417th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Exploitation status turned active · 2026-09-10ConnectWiseScreenConnectCRIT9.9v3.11%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 57 of 99Act1454th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVmicrofinance_management_system_projectmicrofinance_management_systemCRIT9.8v3.114%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1612th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVvarktechpricing_deals_for_woocommerceCRIT9.8v3.18%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1718th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-09Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Exploitation status turned active · 2026-09-09GoogleChromium V8HIGH8.8v3.11%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.3Act, 56 of 99Act1961st of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVexrickxmallCRIT9.8v3.13%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1971st of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVkopiakopiaCRIT9.8v3.12%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 54 of 99Act2375th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Not applicable outside CISA KEVJenkinsgitHIGH7.5v3.16%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 53 of 99Act2386th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Not applicable outside CISA KEVKGUARDDVRCRIT10.0v4.01%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 53 of 99Act2458th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-10MikroTikRouterOSHIGH8.8v4.01%+0.4pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3Act, 53 of 99Act2482nd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVmingsoftmcmsCRIT9.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 52 of 99Act2530th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVNagiosNagios XIHIGH7.2v3.043%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 52 of 99Act2603rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVNagiosNagios XIHIGH7.2v3.043%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 52 of 99Act2605th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVokfnckanHIGH8.3v4.02%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 52 of 99Act2639th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Not applicable outside CISA KEVcomsenzduomicmsCRIT9.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 52 of 99Act2644th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-12Not applicable outside CISA KEVThe Events CalendarThe Events Calendar plugin for WordPressCRIT9.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 51 of 99Act2705th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVcar_rental_management_system_projectcar_rental_management_systemHIGH7.2v3.15%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 51 of 99Act2784th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVcar_rental_management_system_projectcar_rental_management_systemHIGH7.2v3.15%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 51 of 99Act2790th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Not applicable outside CISA KEVTendaac15_firmwareMED6.3v3.14%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 51 of 99Act2791st of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVcar_rental_management_system_projectcar_rental_management_systemHIGH7.2v3.15%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 51 of 99Act2819th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVcar_rental_management_system_projectcar_rental_management_systemHIGH7.2v3.15%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 51 of 99Act2820th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVThe Events CalendarThe Events Calendar plugin for WordPressCRIT9.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 50 of 99Act2916th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVsensiolabssymfonyHIGH7.3v3.164%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 50 of 99Act2988th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10JFrogArtifactoryHIGH7.5v3.11%+0.6pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3Act, 49 of 99Act3051st of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-08Not applicable outside CISA KEVIntelatom_cMED5.6v3.194%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 49 of 99Act3103rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVElegant ThemesDivi Ajax FilterCRIT9.8v3.10%0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 48 of 99Act3188th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-15Not applicable outside CISA KEVFlowiseCSV AgentCRIT9.2v4.01%+0.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 48 of 99Act3309th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-11Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10JFrogArtifactoryHIGH8.1v3.11%+0.6pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.4Act, 48 of 99Act3314th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVRed HatRed Hat OpenShift AI (RHOAI)HIGH7.5v3.12%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 47 of 99Act3476th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Not applicable outside CISA KEVNewfoldpluginsHIGH8.8v3.11%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 46 of 99Act3598th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Not applicable outside CISA KEVN-centralN-centralHIGH7.7v4.01%+0.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 45 of 99Act3692nd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVN-ableN-centralMED6.9v4.01%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 40 of 99Act4037th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-09Not applicable outside CISA KEVYITHWooCommerce Waitlist PremiumHIGH8.8v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 40 of 99Act4083rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVWooCommerceLotteryHIGH7.5v3.10%0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 39 of 99Act4114th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not applicable outside CISA KEVTranslatePressTranslatePress - Translate Multilingual sites with AI TranslationHIGH7.2v3.10%0.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 37 of 99Act4217th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not applicable outside CISA KEVpluginushusky_-_products_filter_professional_for_woocommerceMED6.1v3.10%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 35 of 99Act4264th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Not published by source; first tracked Not applicable outside CISA KEVvitejsviteNo CVSS score from tracked sources is available in this site build2%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 35 of 99Act4267th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-11Not published by source; first tracked Not applicable outside CISA KEVvitejsviteNo CVSS score from tracked sources is available in this site build1%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 32 of 99Act4312th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-10Not published by source; first tracked Not applicable outside CISA KEVTencentSogou Input MethodNo CVSS score from tracked sources is available in this site buildNot yet scored by FIRSTVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2Act, 21 of 99Act4333rd of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-14Not published by source; first tracked Not applicable outside CISA KEVFlytoHubflyto-coreNo CVSS score from tracked sources is available in this site buildNot yet scored by FIRSTVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 20 of 99Act4335th of 4,345 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVLinuxkernelHIGH8.8v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 20 of 99Track4908th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-11Not applicable outside CISA KEVNextGen HealthcareMirth ConnectHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.1Track, 20 of 99Track5044th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVIBMLangflow OSSHIGH8.1v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5295th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVIBMAspera Enterprise WebAppsHIGH8.8v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5369th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVPar avisverifiesVerified Reviews (Avis Vérifiés)CRIT9.3v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5462nd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVAdobeAcrobat ReaderHIGH8.8v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5565th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVMicrosoftVisual Studio CodeHIGH8.2v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.1Track, 19 of 99Track5570th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVMicrosoftSkype for Business Server 2019 CU8HIGH8.3v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.1Track, 19 of 99Track5576th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVLinuxkernelHIGH8.8v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5619th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-11Not applicable outside CISA KEVBrainzcompanyZenius EMS 8.0HIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5633rd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-12Not applicable outside CISA KEVvllm-projectvLLMHIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5666th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVSiteSkiteSiteSkiteHIGH8.1v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5810th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-11Not applicable outside CISA KEVWWBNAVideoCRIT9.3v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5811th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-11Not applicable outside CISA KEVWWBNAVideoCRIT9.3v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5812th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-11Not applicable outside CISA KEVKingdom Communication AssociatedSmart Video Intercom SystemHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5845th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVtdunningt-digestHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5870th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVGeoVisionGV-LPC2211HIGH8.8v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5873rd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVbestzipbestzipHIGH8.6v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5885th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVSoftishEarVision Android applicationHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 19 of 99Track5944th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-12Not applicable outside CISA KEVKalkitechASE2000 V2 Communication Test SetCRIT9.1v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6121st of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVWWBNAVideoCRIT9.3v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6214th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVn8nn8nHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6364th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVSoftishEarVision Android applicationHIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6446th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVOpenPanelOpenPanelHIGH8.4v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6542nd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVIBMDataStageHIGH8.5v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6607th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-13Not applicable outside CISA KEVMoritz BunkusMKVToolNixHIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6633rd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-12Not applicable outside CISA KEVfreecivfreecivHIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6667th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVSoftishEarVision Android applicationHIGH8.4v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6685th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVSiYuanSiYuanHIGH8.4v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6688th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVSiYuanSiYuanHIGH8.4v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6689th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVRenovateRenovateHIGH8.3v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6708th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVIBMDataStageHIGH8.5v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 18 of 99Track6714th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVGeoVisionGV-LPC2211CRIT9.4v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track6719th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVOpenPanelopenpanelHIGH8.7v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track6741st of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVInsyde SoftwareInsydeH2OHIGH8.2v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track6796th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVOktaAccess GatewayHIGH8.1v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track6836th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVpassport-saml-encryptedpassport-saml-encryptedCRIT9.3v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track6842nd of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVTP-Link Systems Inc.RE210 AC750HIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track7141st of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-08Not applicable outside CISA KEVMaonoLinkHIGH8.4v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track7254th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVrenovatebotrenovateHIGH8.5v4.0CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track7255th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-09Not applicable outside CISA KEVMageplazaBlog for Magento 2HIGH8.6v3.1ADP0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 17 of 99Track7319th of 10,807 tracked, non-rejected CVEs in Track
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedA vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-09-10Not applicable outside CISA KEVIBMDataStageHIGH8.5v3.1CNA0%no prior readingNo tracked catalog listingTracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.0Track, 16 of 99Track7399th of 10,807 tracked, non-rejected CVEs in Track
How scores and priority work

The effective Common Vulnerability Scoring System (CVSS) score uses NVD's latest version when present, otherwise CNA, ADP, then ENISA EUVD. A non-NVD score is labeled until NVD publishes its analysis. The number is the tier's base (Track 100, Track* 200, Attend 300, Act 400, and Act now 500) plus a 0 to 99 rank inside that tier. A lower-tier CVE can never outrank a higher-tier CVE. A CISA KEV listing or other confirmed exploitation sets an Act floor; ransomware association sets Act now. The Stakeholder-Specific Vulnerability Categorization (SSVC) verdict can set Track through Act. Its automatable and technical-impact foundation is the CISA Vulnrichment judgment where published, with a CVSS fallback; that verdict sets the base tier. Exploitation, open-exposure, and end-of-life modifiers can raise that tier and never lower it. A public exploit or elevated Exploit Prediction Scoring System (EPSS) result can set Track*. Open internet exposure raises an actively exploited or ransomware-associated item one tier and otherwise leaves it unchanged. End of Life raises an actively exploited item by at most one step and has no effect without active exploitation or ransomware association. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. All Tracked filters by published date; recent movement on an older CVE appears in Movers. If no authority published a date, the cell says so, shows first-tracked ingest provenance separately, and sorts below dated rows.

Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. No tracked exploitation signal: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.

Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Detection and validation: Sigma rule, Atomic test, Nuclei template, and Metasploit module badges report mapped metadata availability. They do not change priority.

What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.

Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA, ADP, or ENISA marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, a verified exploit published, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.

How this is computed

Published vulnerability records are ranked by priority tier first and by the documented evidence signals within that tier. The legend above names the source, window, and meaning of each field used by the table.

Method reviewed on .

Glossary