CVE Intelligence
Skip to main content

Weakness and search-intent cluster

Curated intelligence cluster

Unclassified vulnerabilities

147 of 192 pages in this cluster are on CISA's KEV catalog, and 145 are past its remediation deadline.

Pages

192

Ransomware-linked

20

confirmed

Public PoC

135

repositories found

192 pages · showing 1–100 · sorted by kev listed ↓

Published CVE pages, sorted by KEV listed descending
TitleVendorSignals
CVE-2025-39682tls: fix handling of zero-length records on the rx_listLinux+12026-09-182025-09-051%7.13
CVE-2026-87886Acronis Backup Incorrect Default Permissions VulnerabilityAcronis2026-09-162026-09-170%7.87
CVE-2026-48710Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksKludex+12026-09-022026-05-262%6.5235SOCRadar
CVE-2026-53362Linux Kernel Unspecified Vulnerabilitylinux2026-08-272026-07-041%7.81
CVE-2026-34486Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptorApache2026-08-042026-04-0999%7.532
CVE-2023-4346KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism VulnerabilityKNX Association2026-07-152023-08-291%7.516
CVE-2026-54420LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following VulnerabilityLiteSpeed Technologies2026-06-152026-06-141%8.56
CVE-2026-7473Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding BypassArista Networks2026-06-092026-06-051%5.86
CVE-2024-21182Oracle WebLogic Server Unspecified VulnerabilityOracle2026-06-012024-07-1674%7.514
CVE-2026-48027Compromised Nx Console version 18.95.0nrwl2026-05-272026-05-272%9.85
CVE-2026-45321Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys@tanstack2026-05-272026-05-122%9.6145SOCRadar
CVE-2026-8398Daemon Tools Lite Embedded Malicious Code VulnerabilityAVB Disc Soft2026-05-272026-05-151%9.85
CVE-2009-1537Microsoft DirectX NULL Byte Overwrite VulnerabilityMicrosoft2026-05-202009-05-2951%9.358
CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeLinux2026-05-012026-04-22100%7.8793
CVE-2026-32202Windows Shell Spoofing VulnerabilityMicrosoft2026-04-282026-04-1464%4.3114SOCRadar
CVE-2026-20122Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite VulnerabilityCisco2026-04-202026-02-2525%5.411
CVE-2026-34621Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)Adobe2026-04-132026-04-117%8.618
CVE-2026-3502TrueConf Client Update Integrity Verification BypassTrueConf2026-04-022026-03-306%7.8114SOCRadar
CVE-2026-33634Trivy ecosystem supply chain briefly compromisedaquasecurity+22026-03-262026-03-2359%8.8149SOCRadar
CVE-2025-40536SolarWinds Web Help Desk Security Control Bypass VulnerabilitySolarWinds2026-02-122026-01-2882%9.81
CVE-2025-15556Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus2026-02-122026-02-032%7.51
CVE-2026-21514Microsoft Word Security Feature Bypass VulnerabilityMicrosoft2026-02-102026-02-102%7.81
CVE-2026-21513MSHTML Framework Security Feature Bypass VulnerabilityMicrosoft2026-02-102026-02-1015%8.86SOCRadar
CVE-2026-21510Windows Shell Security Feature Bypass VulnerabilityMicrosoft2026-02-102026-02-1026%8.815SOCRadar
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityMicrosoft2026-01-262026-01-2673%7.81624SOCRadar
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion VulnerabilitySynacor2026-01-222025-12-2249%8.8413SOCRadar
CVE-2025-54313Prettier eslint-config-prettier Embedded Malicious Code Vulnerabilityprettier2026-01-222025-07-194%7.543SOCRadar
CVE-2025-14847Zlib compressed protocol header length confusion may allow memory readMongoDB Inc.2025-12-292025-12-1983%7.5969SOCRadar
CVE-2025-59374ASUS Live Update Embedded Malicious Code VulnerabilityASUS2025-12-172025-12-171%9.8none yet
CVE-2025-59718Fortinet Multiple Products Improper Verification of Cryptographic Signature VulnerabilityFortinet2025-12-162025-12-0969%9.8166SOCRadar
CVE-2025-11371Gladinet CentreStack and TrioFox Local File Inclusion FlawGladinet2025-11-042025-10-0992%7.5125SOCRadar
CVE-2025-61932Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerabilitymotex2025-10-222025-10-203%9.8none yet
CVE-2022-48503Apple Multiple Products Unspecified Vulnerabilityapple2025-10-202023-08-143%8.8none yet
CVE-2025-47827IGEL OS Use of a Key Past its Expiration Date VulnerabilityIGEL2025-10-142025-06-054%4.633SOCRadar
CVE-2025-32463Sudo Inclusion of Functionality from Untrusted Control Sphere VulnerabilitySudo project2025-09-292025-06-3059%7.88157SOCRadar
CVE-2022-40799D-Link DNR-322L Download of Code Without Integrity Check VulnerabilityD-Link2025-08-052022-11-2932%8.865SOCRadar
CVE-2020-25078D-Link DCS-2530L and DCS-2670L Devices Unspecified VulnerabilityD-Link2025-08-052020-09-0298%7.5641SOCRadar
CVE-2025-54309 CrushFTP Unprotected Alternate Channel VulnerabilityCrushFTP2025-07-222025-07-1895%9.8413SOCRadar
CVE-2025-47812Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerabilitywftpserver2025-07-142025-07-1095%101
CVE-2025-48928TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerabilitytelemessage2025-07-012025-05-281%4none yet
CVE-2025-48927TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerabilitytelemessage2025-07-012025-05-2811%5.3none yet
CVE-2023-0386Linux Kernel Improper Ownership Management VulnerabilityLinux2025-06-172023-03-228%7.81
CVE-2025-43200Apple Multiple Products Unspecified Vulnerabilityapple2025-06-162025-06-161%4.2none yet
CVE-2025-35939Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerabilitycraft2025-06-022025-05-071%5.3none yet
CVE-2025-47729TeleMessage TM SGNL Hidden Functionality Vulnerabilitytelemessage2025-05-122025-05-080%4.9none yet
CVE-2024-58136Yiiframework Yii Improper Protection of Alternate Path Vulnerabilityyiiframework2025-05-022025-04-1085%9.8none yet
CVE-2024-38475Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.Apache2025-05-012024-07-01100%9.15131SOCRadar
CVE-2025-3928Commvault Web Server Unspecified Vulnerabilitycommvault2025-04-282025-04-252%8.8none yet
CVE-2025-2783Google Chromium Mojo Sandbox Escape Vulnerabilitygoogle2025-03-272025-03-269%8.31
CVE-2025-30154reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerabilityreviewdog2025-03-242025-03-192%8.6none yet
CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerabilitytj actions2025-03-182025-03-1570%8.61
CVE-2025-21590Juniper Junos OS Improper Isolation or Compartmentalization Vulnerabilityjuniper networks2025-03-132025-03-122%4.4none yet
CVE-2025-26633Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerabilitymicrosoft2025-03-112025-03-1130%71
CVE-2025-04117-Zip Mark of the Web Bypass Vulnerability7 zip2025-02-062025-01-2567%71
CVE-2018-19410Paessler PRTG Network Monitor Local File Inclusion VulnerabilityPaessler2025-02-042018-11-2198%9.81
CVE-2023-48365Qlik Sense HTTP Tunneling VulnerabilityQlik2025-01-132023-11-1525%9.9
CVE-2020-2883Oracle WebLogic Server Unspecified Vulnerabilityoracle2025-01-072020-04-1595%9.81
CVE-2024-35250Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability microsoft2024-12-162024-06-1125%7.81
CVE-2024-20481Cisco ASA and FTD Denial-of-Service Vulnerabilitycisco2024-10-242024-10-2316%5.8none yet
CVE-2024-9537ScienceLogic SL1 Unspecified Vulnerabilitysciencelogic2024-10-212024-10-184%9.8none yet
CVE-2024-23113Fortinet Multiple Products Format String VulnerabilityFortinet2024-10-092024-02-1562%9.81
CVE-2024-43461Microsoft Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft2024-09-162024-09-1054%8.8none yet
CVE-2024-38226Microsoft Publisher Protection Mechanism Failure Vulnerabilitymicrosoft2024-09-102024-09-103%7.3none yet
CVE-2024-38217Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerabilitymicrosoft2024-09-102024-09-1010%5.4none yet
CVE-2024-38213Microsoft Windows SmartScreen Security Feature Bypass Vulnerabilitymicrosoft2024-08-132024-08-1314%6.5none yet
CVE-2024-5217ServiceNow Incomplete List of Disallowed Inputs Vulnerabilityservicenow2024-07-292024-07-10100%9.8none yet
CVE-2024-4879Jelly Template Injection Vulnerability in ServiceNow UI MacrosServiceNow2024-07-292024-07-10100%9.8239SOCRadar
CVE-2023-45249Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerabilityacronis2024-07-292024-07-2453%9.81
CVE-2022-22948VMware vCenter Server Incorrect Default File Permissions Vulnerability vmware2024-07-172022-03-2913%6.51
CVE-2024-38112Microsoft Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft2024-07-092024-07-0984%7.51
CVE-2024-4978Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code VulnerabilityJustice AV Solutions2024-05-292024-05-2327%8.4none yet
CVE-2023-7028Weak Password Recovery Mechanism for Forgotten Password in GitLabGitLab2024-05-012024-01-1295%9.81
CVE-2024-29988Microsoft SmartScreen Prompt Security Feature Bypass Vulnerabilitymicrosoft2024-04-302024-04-0945%8.81
CVE-2023-29360Microsoft Streaming Service Untrusted Pointer Dereference Vulnerabilitymicrosoft2024-02-292023-06-1422%8.41
CVE-2024-21412Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerabilitymicrosoft2024-02-132024-02-1395%8.11
CVE-2023-27524Apache Superset Insecure Default Initialization of Resource Vulnerabilityapache2024-01-082023-04-2497%9.81
CVE-2023-41265Qlik Sense HTTP Tunneling Vulnerabilityqlik2023-12-072023-08-2985%9.91
CVE-2023-36584Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerabilitymicrosoft2023-11-162023-10-103%5.4none yet
CVE-2020-2551Oracle Fusion Middleware Unspecified Vulnerabilityoracle2023-11-162020-01-1593%9.81
CVE-2023-36025Microsoft Windows SmartScreen Security Feature Bypass Vulnerabilitymicrosoft2023-11-142023-11-1488%8.81
CVE-2023-36845Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerabilityjuniper networks2023-11-132023-08-1794%9.81
CVE-2023-36844Juniper Junos OS EX Series PHP External Variable Modification Vulnerabilityjuniper networks2023-11-132023-08-1791%5.31
CVE-2023-29552Service Location Protocol (SLP) Denial-of-Service VulnerabilityIETF2023-11-082023-04-2566%7.5none yet
CVE-2021-3129Laravel Ignition File Upload VulnerabilityLaravel2023-09-182021-01-12100%9.85213SOCRadar
CVE-2023-38606Apple Multiple Products Kernel Unspecified Vulnerabilityapple2023-07-262023-07-273%5.5none yet
CVE-2023-32049Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerabilitymicrosoft2023-07-112023-07-114%8.8none yet
CVE-2021-25371Samsung Mobile Devices Unspecified Vulnerabilitysamsung mobile2023-06-292021-03-261%6.7none yet
CVE-2023-32409Apple Multiple Products WebKit Sandbox Escape Vulnerabilityapple2023-05-222023-06-2317%8.6none yet
CVE-2021-27878Veritas Backup Exec Agent Command Execution VulnerabilityVeritas2023-04-072021-03-0124%8.81
CVE-2021-27877Veritas Backup Exec Agent Improper Authentication VulnerabilityVeritas2023-04-072021-03-0165%9.81
CVE-2021-27876Veritas Backup Exec Agent File Access VulnerabilityVeritas2023-04-072021-03-0114%8.11
CVE-2022-36537ZK Framework AuUploader Unspecified VulnerabilityZK Framework2023-02-272022-08-2695%7.51
CVE-2022-44698Microsoft Defender SmartScreen Security Feature Bypass Vulnerabilitymicrosoft2022-12-132022-12-1376%5.4
CVE-2022-41049Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerabilitymicrosoft2022-11-142022-11-092%5.4none yet
CVE-2018-19320GIGABYTE Multiple Products Unspecified VulnerabilityGIGABYTE2022-10-242018-12-214%7.81
CVE-2022-40139Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerabilitytrend micro2022-09-152022-09-193%7.2none yet
CVE-2022-27593QNAP Photo Station Externally Controlled Reference Vulnerabilityqnap systems2022-09-082022-09-0888%9.1
CVE-2020-9934Apple iOS, iPadOS, and macOS Input Validation Vulnerabilityapple2022-09-082020-10-163%5.51
CVE-2011-4723D-Link DIR-300 Router Cleartext Storage of a Password VulnerabilityD-Link2022-09-082011-12-203%6.8none yet
CVE-2022-24706Apache CouchDB Insecure Default Initialization of Resource Vulnerabilityapache2022-08-252022-04-2692%9.81

Field coverage across these 192 pages: KEV listing date 147 · CVSS base score 187 · publication date 192 · EPSS 192 · threat-intel signals 21. Rows with no value on the column being sorted are listed last in both directions rather than counted as zero.

Reading a row

ransomware
CISA records known use in ransomware campaigns. Varies across this index, which is why it is on the row.
PoC
Public proof-of-concept repositories this deployment found on GitHub, and how many.
EPSS
FIRST's estimate of the probability the CVE is exploited in the next 30 days. Present on every record here.
CVSS
Base score, from scored sources only. "n/a" means no source scored it — not that the score is low.