Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1703
- On the catalogue
- 8
- Added in 7 days
- 8
- Due within 7 days
- 359
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-13753 | Not specified | 7.5high | — | — | |
| CVE-2026-13586 | Bouncycastle Bc-Java | 7.5high | — | — | |
| CVE-2026-13506 | Bouncycastle Bc-Java | 7.5high | — | — | |
| CVE-2026-13399 | Not specified | 7.5high | — | — | |
| CVE-2026-13154 | Not specified | 7.5high | — | — | |
| CVE-2026-13153 | Not specified | 7.5high | — | — | |
| CVE-2026-13084 | Watchguard Fireware | 7.5high | — | — | |
| CVE-2026-12852 | Bouncycastle Bc-Java | 7.5high | — | — | |
| CVE-2026-12720 | Not specified | 7.5high | — | — | |
| CVE-2026-12584 | Not specified | 7.5high | — | — | |
| CVE-2026-11404 | Not specified | 7.5high | — | — | |
| CVE-2026-10599 | Not specified | 7.5high | — | — | |
| CVE-2026-10524 | Not specified | 7.5high | — | — | |
| CVE-2026-0994 | Google Protobuf | 7.5high | — | — | |
| CVE-2025-9784 | Redhat Build Of Apache Camel For Spring Boot | 7.5high | — | — | |
| CVE-2025-7424 | Xmlsoft Libxslt | 7.5high | — | — | |
| CVE-2025-61258 | Outsystems Platform Server | 7.5high | — | — | |
| CVE-2025-6021 | Xmlsoft Libxml2 | 7.5high | — | — | |
| CVE-2025-48431 | Apache Thrift | 7.5high | — | — | |
| CVE-2025-46252 | Kofimokome Message Filter For Contact Form 7 | 7.6high | — | — | |
| CVE-2025-3511 | Not specified | 7.5high | — | — | |
| CVE-2025-30706 | Oracle Mysql Connector\/J | 7.5high | — | — | |
| CVE-2025-2610 | Magnussolution Magnusbilling | 7.6high | — | — | |
| CVE-2025-13878 | Not specified | 7.5high | — | — | |
| CVE-2025-13836 | Python Python | 7.5high | — | — |