Exploited vulnerabilities
The CISA Known Exploited Vulnerabilities catalogue, with severity and affected-product data from the National Vulnerability Database. Everything on this list has been observed in real attacks — it is not a forecast.
- 1695
- On the catalogue
- 8
- Added in 7 days
- 7
- Due within 7 days
- 354
- Used in ransomware
| CVE | Affected | CVSS | Added | Due | |
|---|---|---|---|---|---|
| CVE-2024-44309 | Apple Multiple Products | 2024-11-21 | 2024-12-12 | ||
| CVE-2024-44308 | Apple Multiple Products | 2024-11-21 | 2024-12-12 | ||
| CVE-2024-4358 | Progress Telerik Report Server | 2024-06-13 | 2024-07-04 | ||
| CVE-2024-43573 | Microsoft Windows | 2024-10-08 | 2024-10-29 | ||
| CVE-2024-43572 | Microsoft Windows | 2024-10-08 | 2024-10-29 | ||
| CVE-2024-43468 | Microsoft Configuration Manager | 2026-02-12 | 2026-03-05 | ||
| CVE-2024-43461 | Microsoft Windows | 2024-09-16 | 2024-10-07 | ||
| CVE-2024-43451 | Microsoft Windows | 2024-11-12 | 2024-12-03 | ||
| CVE-2024-43093 | Android Framework | 2024-11-07 | 2024-11-28 | ||
| CVE-2024-43047 | Qualcomm Multiple Chipsets | 2024-10-08 | 2024-10-29 | ||
| CVE-2024-42009 | Roundcube Webmail | 2025-06-09 | 2025-06-30 | ||
| CVE-2024-41710 | Mitel SIP Phones | 2025-02-12 | 2025-03-05 | ||
| CVE-2024-40891 | Zyxel DSL CPE Devices | 2025-02-11 | 2025-03-04 | ||
| CVE-2024-40890 | Zyxel DSL CPE Devices | 2025-02-11 | 2025-03-04 | ||
| CVE-2024-4040 | CrushFTP CrushFTP | 2024-04-24 | 2024-05-01 | ||
| CVE-2024-39891 | Twilio Authy | 2024-07-23 | 2024-08-13 | ||
| CVE-2024-39717 | Versa Director | 2024-08-23 | 2024-09-13 | ||
| CVE-2024-38856 | Apache OFBiz | 2024-08-27 | 2024-09-17 | ||
| CVE-2024-38813 | VMware vCenter Server | 2024-11-20 | 2024-12-11 | ||
| CVE-2024-38812 | VMware vCenter Server | 2024-11-20 | 2024-12-11 | ||
| CVE-2024-38475 | Apache HTTP Server | 2025-05-01 | 2025-05-22 | ||
| CVE-2024-38226 | Microsoft Publisher | 2024-09-10 | 2024-10-01 | ||
| CVE-2024-38217 | Microsoft Windows | 2024-09-10 | 2024-10-01 | ||
| CVE-2024-38213 | Microsoft Windows | 2024-08-13 | 2024-09-03 | ||
| CVE-2024-38193 | Microsoft Windows | 2024-08-13 | 2024-09-03 |