Exploited vulnerabilities

The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.

1695
On the catalogue
8
Added in 7 days
7
Due within 7 days
354
Used in ransomware
CVEAffectedCVSSAddedDue
CVE-2020-1938Apache Geode9.8critical2022-03-032022-03-17
CVE-2016-8735Apache Tomcat9.8critical2023-05-122023-06-02
CVE-2017-12617Apache Tomcat8.1high2022-03-252022-04-15
CVE-2023-46604Apache ActiveMQ2023-11-022023-11-23ransomware
CVE-2021-45046Apache Log4j22023-05-012023-05-22ransomware
CVE-2021-42013Apache HTTP Server2021-11-032021-11-17ransomware
CVE-2021-41773Apache HTTP Server2021-11-032021-11-17ransomware
CVE-2021-40438Apache Apache2021-12-012021-12-15ransomware
CVE-2017-5638Apache Struts2021-11-032022-05-03ransomware
CVE-2017-12615Apache Tomcat2022-03-252022-04-15ransomware
CVE-2026-34486Apache Tomcat2026-08-042026-08-07
CVE-2026-34197Apache ActiveMQ2026-04-162026-04-30
CVE-2025-24813Apache Tomcat2025-04-012025-04-22
CVE-2024-45195Apache OFBiz2025-02-042025-02-25
CVE-2024-38856Apache OFBiz2024-08-272024-09-17
CVE-2024-38475Apache HTTP Server2025-05-012025-05-22
CVE-2024-32113Apache OFBiz2024-08-072024-08-28
CVE-2024-27348Apache HugeGraph-Server2024-09-182024-10-09
CVE-2023-33246Apache RocketMQ2023-09-062023-09-27
CVE-2023-27524Apache Superset2024-01-082024-01-29
CVE-2022-33891Apache Spark2023-03-072023-03-28
CVE-2022-24706Apache CouchDB2022-08-252022-09-15
CVE-2022-24112Apache APISIX2022-08-252022-09-15
CVE-2020-1956Apache Kylin2022-03-252022-04-15
CVE-2020-17530Apache Struts2021-11-032022-05-03
Page 1 of 3 · 64 entriesNext