Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1703
- On the catalogue
- 8
- Added in 7 days
- 8
- Due within 7 days
- 359
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2025-13601 | Redhat Codeready Linux Builder | 7.7high | — | — | |
| CVE-2025-11234 | Not specified | 7.5high | — | — | |
| CVE-2025-0624 | Not specified | 7.6high | — | — | |
| CVE-2024-7409 | Not specified | 7.5high | — | — | |
| CVE-2024-5971 | Not specified | 7.5high | — | — | |
| CVE-2024-4027 | Not specified | 7.5high | — | — | |
| CVE-2024-3884 | Not specified | 7.5high | — | — | |
| CVE-2024-34046 | Not specified | 7.5high | — | — | |
| CVE-2024-34045 | Not specified | 7.5high | — | — | |
| CVE-2024-12085 | Samba Rsync | 7.5high | — | — | |
| CVE-2023-7260 | Opentext Cx-E Voice | 7.5high | — | — | |
| CVE-2023-43901 | Emudhra Emsigner | 7.5high | — | — | |
| CVE-2023-39533 | Libp2p Go-Libp2p | 7.5high | — | — | |
| CVE-2023-34062 | Broadcom Reactor Netty | 7.5high | — | — | |
| CVE-2023-22460 | Protocol Go-Ipld-Prime | 7.5high | — | — | |
| CVE-2022-38178 | Isc Bind | 7.5high | — | — | |
| CVE-2022-38177 | Isc Bind | 7.5high | — | — | |
| CVE-2022-37315 | Graphql-Go Project Graphql-Go | 7.5high | — | — | |
| CVE-2022-34821 | Siemens Simatic Cp 1242-7 V2 Firmware | 7.6high | — | — | |
| CVE-2022-24030 | Insyde Insydeh2o | 7.5high | — | — | |
| CVE-2021-43522 | Insyde Insydeh2o | 7.5high | — | — | |
| CVE-2021-40690 | Apache Santuario Xml Security For Java | 7.5high | — | — | |
| CVE-2021-38652 | Microsoft Sharepoint Enterprise Server | 7.6high | — | — | |
| CVE-2021-38651 | Microsoft Sharepoint Enterprise Server | 7.6high | — | — | |
| CVE-2021-38650 | Microsoft 365 Apps | 7.6high | — | — |