imPC@ndo IT

Of 56.198 vulnerabilities, 770 are actually being exploited.

A CVSS score says how bad a flaw is in theory. This tracker crosses NVD data with the CISA catalogue of exploited vulnerabilities and with EPSS probabilities, and puts first the ones somebody is using right now.

Actively exploited, by probability

updated 18:16 · every 2 hours
CVE-2024-3400
Ransomware Critical 10.0

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…

paloaltonetworks pan-os
1.00EPSS
CVE-2023-4966
Ransomware Critical 9.4

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2023-44487
Exploited High 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · and 161 more
1.00EPSS
CVE-2015-1635
Exploited Critical 9.8

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · and 1 more
1.00EPSS
CVE-2014-6271
Exploited Critical 9.8

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · and 70 more
1.00EPSS
CVE-2021-44228
Ransomware Critical 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…

apache log4j · apple xcode · bentley synchro · bentley synchro_4d · and 139 more
1.00EPSS
See all 770 → 56.198 CVE in archive · 173 used by ransomware