Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1699
- On the catalogue
- 5
- Added in 7 days
- 7
- Due within 7 days
- 358
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2018-15756 | Vmware Spring Framework | 7.5high | — | — | |
| CVE-2018-15383 | Cisco Firepower Threat Defense | 7.5high | — | — | |
| CVE-2018-0227 | Cisco Adaptive Security Appliance Software | 7.5high | — | — | |
| CVE-2017-6632 | Cisco Firepower Threat Defense | 7.5high | — | — | |
| CVE-2011-4088 | Redhat Automatic Bug Reporting Tool | 7.5high | — | — | |
| CVE-2026-74984 | Mozilla Firefox | 6.8medium | — | — | |
| CVE-2026-72584 | Not specified | 7.4high | — | — | |
| CVE-2026-70780 | Oracle Hyperion Financial Reporting | 6.8medium | — | — | |
| CVE-2026-70751 | Oracle Hyperion Financial Reporting | 6.8medium | — | — | |
| CVE-2026-70698 | Oracle Agile Engineering Data Management | 6.7medium | — | — | |
| CVE-2026-66016 | Not specified | 6.7medium | — | — | |
| CVE-2026-6374 | Not specified | 7.3high | — | — | |
| CVE-2026-61313 | Oracle Hyperion Calculation Manager | 6.7medium | — | — | |
| CVE-2026-61173 | Oracle Agile Product Lifecycle Management | 7.4high | — | — | |
| CVE-2026-58440 | Not specified | 6.8medium | — | — | |
| CVE-2026-57263 | Not specified | 6.8medium | — | — | |
| CVE-2026-57262 | Not specified | 6.8medium | — | — | |
| CVE-2026-5172 | Not specified | 7.3high | — | — | |
| CVE-2026-48526 | Pyjwt Project Pyjwt | 7.4high | — | — | |
| CVE-2026-48287 | Adobe C2pa | 7.4high | — | — | |
| CVE-2026-47960 | Adobe Coldfusion | 7.4high | — | — | |
| CVE-2026-44393 | Not specified | 7.4high | — | — | |
| CVE-2026-43869 | Apache Thrift | 7.3high | — | — | |
| CVE-2026-42246 | Ruby-Lang Net\ | 7.4high | — | — | |
| CVE-2026-41605 | Apache Thrift | 7.3high | — | — |