Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2020-1938 | Apache Geode | 9.8critical | 2022-03-03 | 2022-03-17 | |
| CVE-2016-8735 | Apache Tomcat | 9.8critical | 2023-05-12 | 2023-06-02 | |
| CVE-2017-12617 | Apache Tomcat | 8.1high | 2022-03-25 | 2022-04-15 | |
| CVE-2023-46604 | Apache ActiveMQ | 2023-11-02 | 2023-11-23 | ransomware | |
| CVE-2021-45046 | Apache Log4j2 | 2023-05-01 | 2023-05-22 | ransomware | |
| CVE-2021-42013 | Apache HTTP Server | 2021-11-03 | 2021-11-17 | ransomware | |
| CVE-2021-41773 | Apache HTTP Server | 2021-11-03 | 2021-11-17 | ransomware | |
| CVE-2021-40438 | Apache Apache | 2021-12-01 | 2021-12-15 | ransomware | |
| CVE-2017-5638 | Apache Struts | 2021-11-03 | 2022-05-03 | ransomware | |
| CVE-2017-12615 | Apache Tomcat | 2022-03-25 | 2022-04-15 | ransomware | |
| CVE-2026-34486 | Apache Tomcat | 2026-08-04 | 2026-08-07 | ||
| CVE-2026-34197 | Apache ActiveMQ | 2026-04-16 | 2026-04-30 | ||
| CVE-2025-24813 | Apache Tomcat | 2025-04-01 | 2025-04-22 | ||
| CVE-2024-45195 | Apache OFBiz | 2025-02-04 | 2025-02-25 | ||
| CVE-2024-38856 | Apache OFBiz | 2024-08-27 | 2024-09-17 | ||
| CVE-2024-38475 | Apache HTTP Server | 2025-05-01 | 2025-05-22 | ||
| CVE-2024-32113 | Apache OFBiz | 2024-08-07 | 2024-08-28 | ||
| CVE-2024-27348 | Apache HugeGraph-Server | 2024-09-18 | 2024-10-09 | ||
| CVE-2023-33246 | Apache RocketMQ | 2023-09-06 | 2023-09-27 | ||
| CVE-2023-27524 | Apache Superset | 2024-01-08 | 2024-01-29 | ||
| CVE-2022-33891 | Apache Spark | 2023-03-07 | 2023-03-28 | ||
| CVE-2022-24706 | Apache CouchDB | 2022-08-25 | 2022-09-15 | ||
| CVE-2022-24112 | Apache APISIX | 2022-08-25 | 2022-09-15 | ||
| CVE-2020-1956 | Apache Kylin | 2022-03-25 | 2022-04-15 | ||
| CVE-2020-17530 | Apache Struts | 2021-11-03 | 2022-05-03 |
Page 1 of 3 · 64 entriesNext