Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2017-12617 | Apache Tomcat | 8.1high | 2022-03-25 | 2022-04-15 | |
| CVE-2022-25762 | Apache Tomcat | 8.6high | — | — | |
| CVE-2026-41604 | Apache Thrift | 8.2high | — | — | |
| CVE-2026-41602 | Apache Thrift | 7.5high | — | — | |
| CVE-2025-48431 | Apache Thrift | 7.5high | — | — | |
| CVE-2021-40690 | Apache Santuario Xml Security For Java | 7.5high | — | — | |
| CVE-2021-25122 | Apache Tomcat | 7.5high | — | — | |
| CVE-2020-13935 | Apache Tomcat | 7.5high | — | — | |
| CVE-2020-13934 | Apache Tomcat | 7.5high | — | — | |
| CVE-2026-43869 | Apache Thrift | 7.3high | — | — | |
| CVE-2026-41605 | Apache Thrift | 7.3high | — | — | |
| CVE-2026-40542 | Apache Httpclient | 7.3high | — | — | |
| CVE-2019-10086 | Apache Commons Beanutils | 7.3high | — | — | |
| CVE-2021-25329 | Apache Tomcat | 7.0high | — | — | |
| CVE-2020-9484 | Apache Tomcat | 7.0high | — | — |