Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2021-41839 | Insyde Insydeh2o | 8.2high | — | — | |
| CVE-2021-41838 | Insyde Insydeh2o | 8.2high | — | — | |
| CVE-2021-41837 | Insyde Insydeh2o | 8.2high | — | — | |
| CVE-2021-41164 | Ckeditor Ckeditor | 8.2high | — | — | |
| CVE-2021-34469 | Microsoft 365 Apps | 8.2high | — | — | |
| CVE-2021-33767 | Microsoft Open Enclave Software Development Kit | 8.2high | — | — | |
| CVE-2021-33627 | Insyde Insydeh2o | 8.2high | — | — | |
| CVE-2021-2351 | Oracle Advanced Networking Option | 8.3high | — | — | |
| CVE-2020-3514 | Cisco Secure Firewall Management Center | 8.2high | — | — | |
| CVE-2019-12674 | Cisco Secure Firewall Threat Defense | 8.2high | — | — | |
| CVE-2018-0453 | Cisco Secure Firewall Threat Defense | 8.2high | — | — | |
| CVE-2026-9256 | F5 Nginx Open Source | 8.1high | — | — | |
| CVE-2026-47930 | Adobe Coldfusion | 8.1high | — | — | |
| CVE-2026-42945 | F5 Dos | 8.1high | — | — | |
| CVE-2026-42055 | F5 Dos | 8.1high | — | — | |
| CVE-2026-41316 | Not specified | 8.1high | — | — | |
| CVE-2026-34693 | Adobe Experience Manager | 8.0high | — | — | |
| CVE-2026-21361 | Adobe Commerce | 8.1high | — | — | |
| CVE-2026-21311 | Adobe Commerce | 8.0high | — | — | |
| CVE-2026-21284 | Adobe Commerce B2b | 8.1high | — | — | |
| CVE-2024-22373 | Malaterre Grassroots Dicom | 8.1high | — | — | |
| CVE-2022-37966 | Microsoft Windows Server 2008 | 8.1high | — | — | |
| CVE-2021-36967 | Microsoft Windows 10 | 8.0high | — | — | |
| CVE-2021-34762 | Cisco Firepower Management Center Virtual Appliance | 8.1high | — | — | |
| CVE-2021-34524 | Microsoft Dynamics 365 | 8.1high | — | — |