Of 56.198 vulnerabilities, 770 are actually being exploited.
A CVSS score says how bad a flaw is in theory. This tracker crosses NVD data with the CISA catalogue of exploited vulnerabilities and with EPSS probabilities, and puts first the ones somebody is using right now.
Actively exploited, by probability
updated 18:16 · every 2 hoursA command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit…
paloaltonetworks pan-osSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
citrix netscaler_application_delivery_controller · citrix netscaler_gatewayThe HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · and 161 moreHTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · and 1 moreGNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …
apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · and 70 moreApache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who c…
apache log4j · apple xcode · bentley synchro · bentley synchro_4d · and 139 more