Vulnerabilities and patches
Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers that put confirmed exploitation and internet-facing exposure first, then Exploit Prediction Scoring System (EPSS) likelihood, then how much attention it is getting in the news.
Investigating what moved? Filter recent material changesor scan the daily brief.
Skip to ranked Common Vulnerabilities and Exposures (CVE) tableCloud provider flaws that never receive a CVE identifier.
Products past end of support. No patch is coming.
Compromised and typosquatted packages.
Advisories for operational technology and industrial control systems.
Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.
Public exploit code and proof-of-concepts.
An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.
The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.
| Changed | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-12569 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | PTCWindchill and FlexPLM | CRIT9.3v4.0 | 41%+10.4pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 3 | 573.4Act now25th of 815 tracked, non-rejected CVEs in Act now | ||
| CVE-2026-45659PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftSharePoint Server | HIGH8.8v3.1 | 76%+66.2pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 4 | 573.0Act now31st of 815 tracked, non-rejected CVEs in Act now | ||
| CVE-2016-0034 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftSilverlight | HIGH8.8v3.1 | 70%+11.1pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 568.5Act now193rd of 815 tracked, non-rejected CVEs in Act now | ||
| CVE-2021-29441PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | alibabanacos | HIGH8.6v3.1 | 88%+18.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 2 | 566.1Act now273rd of 815 tracked, non-rejected CVEs in Act now | |
| CVE-2026-65400NEWPoC | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-18 | ApplemacOS | HIGH7.1v3.1 | 10%+9.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 4 | 562.6Act now392nd of 815 tracked, non-rejected CVEs in Act now | ||
| CVE-2019-1068PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | MicrosoftSQL Server | HIGH8.8v3.0 | 45%+11.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 559.8Act now479th of 815 tracked, non-rejected CVEs in Act now | |
| CVE-2025-68686 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | FortinetFortiOS | MED5.9v3.1 | 29%+27.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 2 | 558.7Act now508th of 815 tracked, non-rejected CVEs in Act now | ||
| CVE-2015-3105 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | AdobeFlash Player | HIGH10.0v2.0 | 96%+13.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 558.6Act now512th of 815 tracked, non-rejected CVEs in Act now | |
| CVE-2026-72898PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MetabaseMetabase | CRIT10.0v4.0 | 79%+68.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | 472.0Act1st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-63077PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | JetBrainsTeamCity | CRIT9.8v3.1 | 85%+74.0pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 5 | 471.4Act2nd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-16232PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | Check PointSmartConsole | CRIT9.1v3.1 | 89%+15.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 5 | 469.7Act24th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-62593PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | Ray-ProjectRay | CRIT9.4v4.0 | 17%+15.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | 469.3Act28th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-53690PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | SitecoreMultiple Products | CRIT9.0v3.1 | 51%+19.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 469.0Act35th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-59310NEWPoC | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-18Exploit Prediction Scoring System probability jumped · 2026-08-24 | BroadcomVMware vCenter | CRIT9.8v3.1 | 46%+44.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 3 | 468.6Act40th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-9198PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | IBMLangflow | CRIT9.8v3.1 | 37%+20.0pp vs 7d ago | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 468.3Act53rd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-20333PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | CRIT9.9v3.1 | 70%+30.0pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 468.2Act59th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2019-1003030PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | JenkinsMatrix Project Plugin | CRIT9.9v3.1 | 97%+21.3pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 467.8Act70th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-21962NEWPoC | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-24 | OracleHTTP Server and Oracle Weblogic Server Proxy Plug-in | CRIT10.0v3.1 | 43%+0.6pp vs 7d ago | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 467.2Act91st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2024-43468PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftConfiguration Manager | CRIT9.8v3.1 | 82%+21.0pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 467.0Act101st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2021-21551PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | Delldbutil Driver | HIGH8.8v3.1 | 79%+26.1pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | 466.9Act161st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-33824NEW | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-18Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftInternet Key Exchange (IKE) Service Extensions | CRIT9.8v3.1 | 73%+16.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 2 | 466.9Act162nd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-68645PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | Synacor Zimbra Collaboration Suite (ZCS) | HIGH8.8v3.1 | 49%+17.6pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 466.1Act228th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2018-19410PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | PaesslerPRTG Network Monitor | CRIT9.8v3.1 | 98%+11.4pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 466.1Act229th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2021-21224PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | GoogleChromium V8 | HIGH8.8v3.1 | 84%+27.9pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 466.0Act238th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-55040NEWPoC | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-18 | MicrosoftSharePoint | CRIT9.1v3.1 | 6%+1.6pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 7 | 465.9Act244th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2019-13720PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | GoogleChrome WebAudio | HIGH8.8v3.1 | 73%+23.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 465.8Act249th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-23209 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | Craft CMSCraft CMS | HIGH8.0v3.1 | 22%+17.4pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 464.9Act403rd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2012-1856 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftOffice | HIGH8.8v3.1 | 72%+10.4pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 464.7Act426th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2015-2502 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftInternet Explorer | HIGH8.8v3.1 | 51%+12.4pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 464.7Act429th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2020-13671PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | DrupalDrupal core | HIGH8.8v3.1 | 35%+31.0pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 464.6Act441st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2019-2215PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | AndroidAndroid Kernel | HIGH7.8v3.1 | 72%+28.3pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 464.1Act513th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-40536 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | SolarWindsWeb Help Desk | HIGH8.1v3.1 | 82%+10.1pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 463.6Act578th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-6875 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | ServiceNowServiceNow AI Platform | CRIT9.5v4.0 | 78%+50.8pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 3 | 463.0Act633rd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2025-9377 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | TP-LinkMultiple Routers | HIGH8.6v4.0 | 34%+21.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 462.6Act699th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2021-42292 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftOffice | HIGH7.8v3.1 | 43%+11.3pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 462.1Act743rd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-34486PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | ApacheTomcat | HIGH7.5v3.1 | 99%+15.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 3 | 461.5Act802nd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-73570NEW | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-21 | SynacorZimbra Collaboration Suite (ZCS) | HIGH8.9v3.1 | 2%+1.0pp vs 7d ago | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 460.8Act869th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-72530NEW | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-20 | TrueConfServer | CRIT9.5v4.0 | 2%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 460.7Act872nd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-25895PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-18 | — | frangoteamfuxa | CRIT9.5v4.0 | 11%+7.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 460.4Act891st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-16723PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | AlibabaFastjson | CRIT9.0v3.1 | 16%+15.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 2 | 460.3Act902nd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-72529NEW | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-20 | TrueConfServer | CRIT9.3v4.0 | 2%no prior reading | CISA · VulnCheckENISA | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 460.0Act938th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-46442PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | FlowiseAIFlowise | CRIT9.4v4.0 | 36%+32.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 459.8Act951st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2020-36847PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | simplefilelistsimple_file_list | CRIT9.8v3.1 | 32%+14.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 459.6Act959th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-64849NEW | Added to the CISA Known Exploited Vulnerabilities catalog · 2026-08-19Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-18Exploitation status turned active · 2026-08-20Exploit Prediction Scoring System probability jumped · 2026-08-24 | MLflowMLflow | CRIT9.3v3.1 | 16%+16.1pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 459.4Act1011th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2024-21182PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | OracleWebLogic Server | HIGH7.5v3.1 | 74%+24.2pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 459.4Act1021st of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2021-20124PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | DrayTekVigorConnect | HIGH7.5v3.1 | 96%+25.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | 459.3Act1057th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2021-20123PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | DrayTekVigorConnect | HIGH7.5v3.1 | 90%+14.8pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 1 | 458.9Act1102nd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2025-28137PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | totolinka810r_firmware | CRIT9.8v3.1 | 36%+22.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 458.7Act1163rd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-32201PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | MicrosoftSharePoint Server | MED6.5v3.1 | 43%+20.0pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 2 | 458.6Act1193rd of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2026-28318PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | SolarWindsServ-U | HIGH7.5v3.1 | 40%+31.7pp vs 7d ago | CISA · VulnCheckENISA | Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. | 0 | 458.4Act1219th of 4,342 tracked, non-rejected CVEs in Act | ||
| CVE-2018-11714PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | TP-Linktl-wr840n_firmware | CRIT9.8v3.0 | 68%+32.7pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 458.1Act1313th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2022-1281PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | 10Webphoto_gallery | CRIT9.8v3.1 | 43%+19.8pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 458.0Act1337th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2021-27691 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22 | — | Tendag0_firmware | CRIT9.8v3.1 | 25%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 457.8Act1404th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2021-23758 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-20 | — | ajaxpro.2_projectajaxpro.2 | HIGH8.1v3.1 | 89%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 457.7Act1440th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2022-47945PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | thinkphpThinkPHP | CRIT9.8v3.1 | 28%+11.9pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 457.6Act1444th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-53435PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | Jenkinsjenkins | HIGH8.8v3.1 | 38%+18.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 457.3Act1554th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-25253PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | openclawopenclaw | HIGH8.8v3.1 | 24%+15.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 456.4Act1790th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-19478PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-19 | — | GitLabGitLab CE/EE | CRIT9.4v3.1 | 6%+5.3pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 4 | 455.0Act2123rd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2022-41800PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | F5big-ip_access_policy_manager | HIGH8.7v3.1 | 77%+11.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 454.7Act2169th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2018-1000049PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | nanopoolclaymore_dual_miner | HIGH7.5v3.0 | 77%+19.0pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 454.6Act2198th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2022-0995PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-20 | — | LinuxKernel | HIGH7.8v3.1 | 6%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 454.5Act2241st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-73343 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-18 | — | AresITWP Compress | CRIT10.0v3.1 | 1%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 452.5Act2547th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2025-71257PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | BMC Software, Inc.FootPrints | MED6.9v4.0 | 45%+39.4pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 452.5Act2556th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-32475PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-19 | — | ElementorElementor Pro | CRIT9.0v3.1 | 1%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 451.8Act2661st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-77647 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-20 | — | SPIPSPIP | CRIT9.8v3.1 | 1%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 451.1Act2761st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-77806 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-21 | — | SPIPSPIP | CRIT9.8v3.1 | 1%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 449.6Act3027th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-76904PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-21 | — | GeoToolsgeotools | CRIT9.8v3.1 | 1%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 448.2Act3255th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2015-3246PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-20 | — | Red Hatlibuser | HIGH7.2v2.0 | 7%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 447.6Act3358th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2015-5287PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-20 | — | Red Hatautomatic_bug_reporting_tool | MED6.9v2.0 | 3%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 1 | 447.1Act3436th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2011-4106 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | binarymoontimthumb | MED6.8v2.0 | 23%+11.6pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 446.9Act3463rd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-73400 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-18 | — | MotoPressRestaurant Menu | HIGH8.1v3.1 | 0%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 444.3Act3746th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-57739 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22 | — | AcyMailing Newsletter TeamAcyMailing SMTP Newsletter | CRIT9.3v3.1 | 0%+0.1pp vs 7d ago | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 443.0Act3861st of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-66629 | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-18 | — | ThemeumKirki | HIGH7.1v3.1 | 0%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 436.2Act4233rd of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2025-10164PoC | Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-08-22 | — | lmsyssglang | MED5.5v4.0 | 0%no prior reading | VulnCheck | Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. | 0 | 435.2Act4264th of 4,342 tracked, non-rejected CVEs in Act | |
| CVE-2026-61511PoC | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | vBulletinvBulletin | CRIT9.3v4.0 | 34%+32.3pp vs 7d ago | — | Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet. | 0 | 346.7Attend2nd of 226 tracked, non-rejected CVEs in Attend | |
| CVE-2026-66066 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | railsActive Storage | CRIT9.5v4.0 | 19%+17.2pp vs 7d ago | — | Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet. | 3 | 240.1Track*13th of 1,998 tracked, non-rejected CVEs in Track* | |
| CVE-2026-71362 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | AdobeAdobe Commerce | CRIT9.1v3.1 | 25%+24.7pp vs 7d ago | — | Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet. | 3 | 238.1Track*33rd of 1,998 tracked, non-rejected CVEs in Track* | |
| CVE-2026-33112 | Exploit Prediction Scoring System probability jumped · 2026-08-24 | — | MicrosoftMicrosoft SharePoint Enterprise Server 2016 | HIGH8.8v3.1 | 33%+29.6pp vs 7d ago | — | Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet. | 0 | 236.3Track*82nd of 1,998 tracked, non-rejected CVEs in Track* | |
| CVE-2026-54449 | A vendor or Authorized Data Publisher score of 8.0 or higher arrived · 2026-08-20 | — | langbot-appLangBot | HIGH8.8v3.1CNA | 0%no prior reading | — | Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet. | 0 | 222.3Track*1734th of 1,998 tracked, non-rejected CVEs in Track* |
How scores and priority work
The effective Common Vulnerability Scoring System (CVSS) score uses a strict precedence: the National Vulnerability Database (NVD) score when present (latest version, v4.0 then v3.1, v3.0, and v2.0), else the CVE Numbering Authority (CNA) score from the CVE record, else the Authorized Data Publisher (ADP) score. A CNA or ADP score is labeled with a chip beside the version chip; once NVD publishes its analysis the score is replaced and relabeled. Priority is a tier first and a rank within that tier, never a raw sum, so the number is tier major: the five tiers ascend Track, Track*, Attend, Act, and Act now, and any Act now item outranks any Act item, so a quiet high severity CVE can never outrank one that is actively exploited and internet facing. The tier is set by exploitation first, on a single ladder from proof of concept up through active and ransomware use that the tracked exploitation catalogs and the CISA Vulnrichment exploitation signal feed rather than stack, then a Stakeholder Specific Vulnerability Categorization (SSVC) style decision computed by this tracker, whose foundation is the CISA Vulnrichment program's published SSVC judgments wherever they have been ingested for the CVE, with the automatability and technical impact inputs derived here from CVSS only where no CISA judgment is stored (those two inputs are labeled with their source on the CVE panel), then exposure, then Exploit Prediction Scoring System (EPSS) probability. The exploitation ladder, exposure, and End of Life only ever raise the tier above what that SSVC decision implies, never lower it. Exposure counts as open only when the attack vector is Network and the product is a curated internet facing class such as a firewall, a virtual private network gateway, or an edge router, never from Network alone. End of Life raises the tier by at most one step, and only when the product is both internet facing exposed and actively exploited, never on its own. Within a tier, the rank draws on exploitation, EPSS, whether that EPSS score has been rising over the last thirty days, CVSS, technical impact, the weakness class the CWE identifier names, how mature the public exploit is, exposure, CISA KEV due date proximity, news mentions, tracked catalog corroboration, whether the flaw reaches beyond the affected component, and how many privileges an attacker needs, each counted once. Reaching beyond the component means exploiting it affects resources outside its own security authority. CVSS version 3 states that as Scope; version 4 removed Scope and replaced it with three measures of the impact on a system beyond the vulnerable one, so we read whichever the record provides, and both earn the same amount. When the keyed exposure sources are enabled, the within tier rank also reflects observed mass exploitation, the count of threat internet protocol addresses, and the observed internet facing instance count from Shodan, a blast radius signal that never sets the exposure gate, each likewise a small within tier nudge that never changes the tier itself. The All Tracked view filters on a published-date window: a segment shows only CVEs published within it, so the default view shows what is genuinely new rather than years-old maximum-priority entries; Movers is unchanged. The Published column shows only a date an authority stated (NVD or the CVE record); a CVE tracked here without one shows a dash, with the first-tracked date in the dash's tooltip, and sorts below every dated row. The window segments filter on the CVE's published date, whatever its provenance; recent movement on older CVEs, such as a fresh CISA KEV addition to an old CVE, appears in Movers, not in the windows.
Status values. active: Exploitation in the wild is confirmed by a tracked signal: a ransomware-linked catalog entry, or the CISA Vulnrichment SSVC Exploitation decision point reported as Active. That is one CISA decision point, not a full CISA assessment; the SSVC-style verdict on the CVE panel is computed by this tracker, and its automatability and technical impact inputs are labeled with their source. listed by a tracked exploitation catalog: Listed by a tracked exploitation catalog (CISA KEV, VulnCheck KEV, or ENISA EUVD), meaning exploitation has been observed, without a tracked ransomware link or newer active signal. Dash: Tracked from news, advisories, or scoring feeds with no exploitation signal from any tracked catalog yet.
Due: Due dates are CISA Binding Operational Directive remediation deadlines for US federal agencies, and a useful prioritization signal for everyone else. Rows due within the next 14 days carry a subtle accent; past-due rows render plainly, since most of the catalog is long past its federal deadline and the actionable set is what is still upcoming. PoC: a public proof of concept referenced by the CVE record itself, linking to that single reference. EPSS: An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.
What gets tracked. A CVE enters this table when an exploitation catalog lists it (CISA KEV, VulnCheck KEV, or ENISA EU KEV), when GitHub publishes a critical or high severity advisory for it, or when it ships in a Microsoft Patch Tuesday release within the last twelve months. Azure Linux package advisories from those releases are the one documented exception: they stay on the Patch Tuesday page but join this table only when the operator enables them.
Exploitation catalogs: CISA KEV, VulnCheck KEV, and ENISA EU KEV, each with its own badge. Score chips: v-numbers give the CVSS version; CNA or ADP marks a score awaiting NVD analysis. Movers: added to CISA KEV or VulnCheck KEV, turned active, a recent CNA or ADP score at or above 8.0, EPSS up 0.10 or more in about a week (the comparison point is 7 to 14 days old), or 3 or more mentions in 48 hours. Rows added to CISA KEV in the last 7 days are marked NEW.