CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build

State now. Changed: +157 tier promotions, 0 known-exploited vulnerability additions, 68 leak-site claims, and 8 confirmed breaches since yesterday.

Why today matters
Vulnerabilities

All CVEs

Browse tracked Common Vulnerabilities and Exposures (CVE) identifiers by priority tier, with confirmed exploitation and ransomware evidence visible.

Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers. A Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) listing or other confirmed exploitation never ranks below Act. Ransomware association reaches Act now; active exploitation can also rise one tier through either the end-of-life or open-exposure modifier.

Why now: this site build includes 1,701 actively exploited records; the ranked details below show their evidence and actions.

77,387 tracked CVE records in this site build1,728 in CISA KEV1,701 actively exploited records in this site build

Choose your reading level

The page address stays the same, and this choice follows you to other pages.

Analyst view shows the full table.

State now

954 tracked CVEs are in the Act now tier in this site build.

Why these records matter

Details

The legend explains every priority and status label, and the filters sit beside the ranked records below.

Skip to ranked Common Vulnerabilities and Exposures (CVE) table
Deadline quick view

Federal remediation deadline backlog

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.

  1. OverdueCalculating
  2. Due in 0 to 7 daysCalculating
  3. Due in 8 to 14 daysCalculating
  4. Due in 15 to 30 daysCalculating

Counts use this device's current date. Calculating the backlog.

Cloud Vulnerabilities

Cloud provider flaws that never receive a CVE identifier.

From the Open Cloud Vulnerability Database.277 tracked
End of Life

Release cycles past End of Life. No patch is coming.

From endoflife.date.632 past end of life
Malicious Packages

Compromised and typosquatted packages.

From OpenSSF and OSV.2,016 tracked
OT & ICS

Advisories for operational technology and industrial control systems.

From CISA.382 tracked
Patch Day

Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.

Exploits

Public exploit code and proof-of-concepts.

From Exploit-DB and VulnCheck.
149 matches
In this view:Act now20Act125Attend0Track*1Track3

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.

Table legend

What each badge means

Open the full glossary

Tiers ascend Track (watch), Track* (a public exploit or a rising exploitation forecast), Attend (act in the normal cycle),Act (confirmed exploitation somewhere), and Act now(ransomware association, or active exploitation raised by the end-of-life or open-exposure modifier). A lower tier can never outrank a higher one. A Mentions count of 0 is a measured zero: the tracker looked and found no coverage, rather than not having looked.

Changed
Permanent recordSigma mappedAtomic mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28QlikSenseCRIT9.6v3.147%+23.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act now, 71 of 99Act now110th of 952 tracked, non-rejected CVEs in Act now
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28CiscoSecure Email GatewayCRIT9.8v3.128%+26.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.5Act now, 67 of 99Act now247th of 952 tracked, non-rejected CVEs in Act now
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28SimpleHelp SimpleHelpHIGH7.2v3.165%+57.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act now, 67 of 99Act now276th of 952 tracked, non-rejected CVEs in Act now
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-22Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-22Exploitation status turned active · 2026-09-22F5BIG-IP APMCRIT9.3v4.02%no prior readingCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.4Act now, 64 of 99Act now350th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVtbkvisiontbk-dvr4216_firmwareCRIT9.8v3.082%+17.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 64 of 99Act now355th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVOracleWebLogic ServerCRIT9.8v3.050%+26.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 64 of 99Act now371st of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVVMwareSpring FrameworkCRIT9.8v3.075%+20.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 64 of 99Act now374th of 952 tracked, non-rejected CVEs in Act now
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28CiscoSecure Firewall Management Center (FMC)MED5.3v3.135%+23.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.6Act now, 62 of 99Act now437th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)CRIT10.0v3.087%+13.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 62 of 99Act now469th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVFortinetFortiOSCRIT9.8v3.050%+13.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 60 of 99Act now523rd of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCitrixSD-WAN and NetScalerCRIT9.8v3.043%+22.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 59 of 99Act now568th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCitrixSD-WAN and NetScalerCRIT9.8v3.043%+22.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 59 of 99Act now569th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCitrixSD-WAN and NetScalerCRIT9.8v3.040%+20.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 59 of 99Act now571st of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCitrixSD-WAN and NetScalerCRIT9.8v3.040%+20.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 59 of 99Act now572nd of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCitrixSD-WAN and NetScalerCRIT9.8v3.039%+21.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 58 of 99Act now598th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVMicrosoftWindowsHIGH7.8v3.043%+14.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 56 of 99Act now671st of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVMicrosoftWindowsHIGH7.8v3.054%+10.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 55 of 99Act now692nd of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVMicrosoftWindowsMED5.3v3.148%+14.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act now, 53 of 99Act now752nd of 952 tracked, non-rejected CVEs in Act now
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-27Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-27Exploitation status turned active · 2026-09-27CitrixNetScalerCRIT9.5v4.0Not yet scored by FIRSTCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2Act now, 50 of 99Act now823rd of 952 tracked, non-rejected CVEs in Act now
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-27Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-27Exploitation status turned active · 2026-09-27CitrixNetScalerCRIT9.5v4.0Not yet scored by FIRSTCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.2Act now, 49 of 99Act now847th of 952 tracked, non-rejected CVEs in Act now
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28GitLabCommunity Edition and Enterprise EditionCRIT10.0v3.191%+76.9pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.7Act, 74 of 99Act1st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28JoomShaperSP Page BuilderCRIT10.0v4.089%+73.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1Act, 73 of 99Act2nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28CiscoSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCRIT10.0v3.188%+12.4pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.5Act, 71 of 99Act3rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28OracleHTTP Server and Oracle Weblogic Server Proxy Plug-inCRIT10.0v3.171%+28.4pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.3Act, 71 of 99Act4th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Ray-ProjectRayCRIT9.4v4.062%+45.6pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.1Act, 71 of 99Act5th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28GoogleChromium V8HIGH8.8v3.149%+47.4pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.10Act, 70 of 99Act14th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-24Exploit Prediction Scoring System probability jumped · 2026-09-28AdobeCommerce and Magento CRIT9.1v3.188%+63.0pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act, 69 of 99Act29th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28CiscoIdentity Services EngineCRIT10.0v3.114%+13.2pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.6Act, 69 of 99Act35th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28RoundcubeRoundcube WebmailCRIT9.8v3.170%+28.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 67 of 99Act96th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28GoogleChromiumHIGH8.8v3.155%+32.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 66 of 99Act231st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-22Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-22Check PointMultiple ProductsCRIT9.8v3.120%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2Act, 66 of 99Act242nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28SangomaFreePBXCRIT9.8v3.156%+19.3pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 66 of 99Act302nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28KenticoXperience CMSCRIT9.8v3.173%+14.0pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 65 of 99Act310th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-25Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-22WordPressCoreHIGH8.1v3.118%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act, 65 of 99Act384th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVShenzhen AitemiM300 Wi-Fi RepeaterCRIT9.4v4.087%+18.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 62 of 99Act705th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28DockerDesktop Community EditionHIGH7.8v3.149%+16.7pp vs 7d agoCISA · VulnCheckENISAExploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source.0Act, 62 of 99Act708th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-21Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-21ZyxelGS1900 Series SwitchesHIGH8.8v3.13%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.2Act, 62 of 99Act715th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVCiscoIdentity Services EngineCRIT10.0v3.139%+11.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 62 of 99Act776th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVgwolle_guestbook_projectgwolle_guestbookCRIT9.0v3.037%+15.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 61 of 99Act819th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVRed Hatdata_gridCRIT9.8v3.086%+15.5pp vs 7d agoVulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 61 of 99Act821st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-22Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-22AristaVeloCloud OrchestratorCRIT9.5v4.01%no prior readingCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 60 of 99Act878th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVApacheSolrCRIT9.8v3.078%+20.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act898th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVjpcertlogontracerCRIT9.8v3.075%+17.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act907th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVD-Linkdir-823_firmwareCRIT9.8v3.080%+14.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act914th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVdellemc_idrac7CRIT9.8v3.090%+12.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act917th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVzeroshellzeroshellCRIT9.8v3.090%+11.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act919th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVbelkincrock-pot_smart_slow_cooker_with_wemo_firmwareCRIT9.8v3.072%+12.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 60 of 99Act921st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVoturiasmart_google_code_inserterCRIT9.8v3.091%+17.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act996th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVasustoradmCRIT9.8v3.044%+20.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1025th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVQNAPQTSCRIT9.8v3.066%+35.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1026th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVOracleWebLogic ServerCRIT9.8v3.071%+28.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1057th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVrevive-sasrevive_adserverCRIT9.8v3.057%+30.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1060th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVLGsupersign_cmsCRIT9.8v3.056%+29.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1063rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVroxyfilemanroxy_filemanCRIT9.8v3.073%+27.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1065th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-22Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-22Check PointMultiple ProductsCRIT9.8v3.11%+0.7pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.5Act, 59 of 99Act1069th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVD-Linkcentral_wifimanagerHIGH8.6v3.044%+15.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1074th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVxiongmaitechuc-httpdCRIT9.8v3.029%+10.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1076th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVflowpaperflexpaperCRIT9.8v3.053%+20.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1127th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVwificamwireless_ip_camera_\(p2p\)_firmwareCRIT9.8v3.035%+21.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1129th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVxiongmaitechuc-httpdCRIT9.8v3.040%+21.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1132nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVaviary_image_editor_add-on_for_gravity_forms_projectaviary_image_editor_add-on_for_gravity_formsCRIT9.8v3.041%+21.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1133rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordNEWSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedAdded to the CISA Known Exploited Vulnerabilities catalog · 2026-09-24WSO2Multiple ProductsCRIT10.0v3.11%+0.3pp vs 7d agoCISA · VulnCheckENISAListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.4Act, 59 of 99Act1142nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVD-Linkdir-818lw_firmwareCRIT9.8v3.042%+19.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1156th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVQNAPQTSCRIT9.8v3.057%+16.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1166th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVvBulletinvBulletinCRIT9.8v3.068%+32.8pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1170th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVElasticKibanaCRIT9.8v3.082%+10.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 59 of 99Act1183rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVJenkinsjenkinsCRIT9.8v3.097%+10.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1187th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVteltonikarut900_firmwareCRIT9.8v3.071%+10.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1188th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVdellemc_avamarCRIT9.8v3.051%+28.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1194th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVhootootripmate_titan_ht-tm05_firmwareCRIT9.8v3.048%+13.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1196th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVRed HatJBoss Application ServerCRIT9.8v3.039%+13.7pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1200th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVgracemedia_media_player_projectgracemedia_media_playerCRIT9.8v3.044%+27.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1221st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVwpenginewpgraphqlCRIT9.8v3.047%+27.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1223rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVcodemenschengift_vouchersCRIT9.8v3.050%+26.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1227th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVTP-Linktl-wr840n_firmwareCRIT9.8v3.068%+36.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1233rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVdreamboxopendreamboxCRIT9.8v3.022%+13.0pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1235th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-24Not applicable outside CISA KEVdompdf_projectdompdfCRIT9.8v3.182%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1255th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVmlwebtechnologiesprayercenterCRIT9.8v3.058%+20.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1271st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVzh_baidumap_projectzh_baidumapCRIT9.8v3.058%+20.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1272nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVdeltekmaconomyCRIT9.8v3.084%+16.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1282nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVjfrogartifactoryCRIT9.8v3.053%+35.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1332nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVGeutebruckip_camera_g-cam_efd-2250_firmwareCRIT9.8v3.052%+12.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1381st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVGitLabGitLab CE/EECRIT9.4v3.160%+54.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.4Act, 58 of 99Act1384th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVseagateblackarmor_nas_220_firmwareCRIT9.8v3.051%+29.6pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1389th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVeatonintelligent_power_managerCRIT9.8v3.020%+13.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1392nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVteclib-editiongestionnaire_libre_de_parc_informatiqueCRIT9.8v3.022%+15.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1408th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVApacheStrutsHIGH8.1v3.093%+10.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 58 of 99Act1410th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEValibabafastjsonCRIT9.8v3.039%+22.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1475th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVeq-3homematic_central_control_unit_ccu2_firmwareCRIT9.8v3.064%+15.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1516th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVbarnimaster_ip_camera01_firmwareCRIT9.8v3.056%+15.9pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1523rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVntpsecntpsecCRIT9.1v3.067%+30.3pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1527th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVcutephpcutenewsHIGH8.8v3.052%+11.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1559th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVcalmar-webmediatotal_donationsCRIT9.8v3.026%+16.4pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1562nd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVWebminWebminHIGH8.8v3.035%+21.5pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 57 of 99Act1673rd of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVsiteeditorsite_editorHIGH7.5v3.062%+20.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1748th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedAdded to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-26Not published by source; first tracked Not applicable outside CISA KEVmesop-devmesopCRIT9.8v3.14%no prior readingVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1751st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei mappedMetasploit mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVsupervisordsupervisorHIGH8.8v3.087%+13.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1840th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVdasanzhoneznid_2426a_firmwareHIGH8.8v3.053%+10.1pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1909th of 4,411 tracked, non-rejected CVEs in Act
Permanent recordPoCSigma not mappedAtomic not mappedNuclei not mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVhuaweihg532_firmwareHIGH8.8v3.078%+11.8pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.1Act, 56 of 99Act1941st of 4,411 tracked, non-rejected CVEs in Act
Permanent recordSigma not mappedAtomic not mappedNuclei mappedMetasploit not mappedExploit Prediction Scoring System probability jumped · 2026-09-28Not applicable outside CISA KEVjolokiawebarchive_agentHIGH8.1v3.074%+27.2pp vs 7d agoVulnCheckListed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal.0Act, 56 of 99Act1958th of 4,411 tracked, non-rejected CVEs in Act
How scores and priority work

The effective Common Vulnerability Scoring System (CVSS) score uses NVD's latest version when present, otherwise CNA, ADP, then ENISA EUVD. A non-NVD score is labeled until NVD publishes its analysis. The number is the tier's base (Track 100, Track* 200, Attend 300, Act 400, and Act now 500) plus a 0 to 99 rank inside that tier. A lower-tier CVE can never outrank a higher-tier CVE. A CISA KEV listing or other confirmed exploitation sets an Act floor; ransomware association sets Act now. The Stakeholder-Specific Vulnerability Categorization (SSVC) verdict can set Track through Act. Its automatable and technical-impact foundation is the CISA Vulnrichment judgment where published, with a CVSS fallback; that verdict sets the base tier. Exploitation, open-exposure, and end-of-life modifiers can raise that tier and never lower it. A public exploit or elevated Exploit Prediction Scoring System (EPSS) result can set Track*. Open internet exposure raises an actively exploited or ransomware-associated item one tier and otherwise leaves it unchanged. End of Life raises an actively exploited item by at most one step and has no effect without active exploitation or ransomware association. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. All Tracked filters by published date; recent movement on an older CVE appears in Movers. If no authority published a date, the cell says so, shows first-tracked ingest provenance separately, and sorts below dated rows.

Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. No tracked exploitation signal: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.

Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Detection and validation: Sigma rule, Atomic test, Nuclei template, and Metasploit module badges report mapped metadata availability. They do not change priority.

What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.

Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA, ADP, or ENISA marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, a verified exploit published, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.

How this is computed

Published vulnerability records are ranked by priority tier first and by the documented evidence signals within that tier. The legend above names the source, window, and meaning of each field used by the table.

Method reviewed on .

Glossary