Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2026-29785 | Linuxfoundation Nats-Server | 7.5high | — | — | |
| CVE-2026-28356 | Not specified | 7.5high | — | — | |
| CVE-2026-27889 | Linuxfoundation Nats-Server | 7.5high | — | — | |
| CVE-2026-27282 | Adobe Coldfusion | 7.5high | — | — | |
| CVE-2026-26278 | Naturalintelligence Fast-Xml-Parser | 7.5high | — | — | |
| CVE-2026-2614 | Lfprojects Mlflow | 7.5high | — | — | |
| CVE-2026-23490 | Pyasn1 Pyasn1 | 7.5high | — | — | |
| CVE-2026-21728 | Grafana Tempo | 7.5high | — | — | |
| CVE-2026-21309 | Adobe Commerce | 7.5high | — | — | |
| CVE-2026-21289 | Adobe Commerce B2b | 7.5high | — | — | |
| CVE-2026-1605 | Eclipse Jetty | 7.5high | — | — | |
| CVE-2025-61258 | Outsystems Platform Server | 7.5high | — | — | |
| CVE-2025-48431 | Apache Thrift | 7.5high | — | — | |
| CVE-2025-46252 | Kofimokome Message Filter For Contact Form 7 | 7.6high | — | — | |
| CVE-2025-3511 | Not specified | 7.5high | — | — | |
| CVE-2025-2610 | Magnussolution Magnusbilling | 7.6high | — | — | |
| CVE-2024-34046 | Not specified | 7.5high | — | — | |
| CVE-2024-34045 | Not specified | 7.5high | — | — | |
| CVE-2023-43901 | Emudhra Emsigner | 7.5high | — | — | |
| CVE-2023-22460 | Protocol Go-Ipld-Prime | 7.5high | — | — | |
| CVE-2022-37315 | Graphql-Go Project Graphql-Go | 7.5high | — | — | |
| CVE-2022-24030 | Insyde Insydeh2o | 7.5high | — | — | |
| CVE-2021-43522 | Insyde Insydeh2o | 7.5high | — | — | |
| CVE-2021-40690 | Apache Santuario Xml Security For Java | 7.5high | — | — | |
| CVE-2021-38652 | Microsoft Sharepoint Enterprise Server | 7.6high | — | — |