IT
57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

NVD · CISA KEV · EPSS — cross-referenced every two hours

Of 57.479 vulnerabilities, 782 are actually being exploited.

A CVSS score says how bad a flaw is in theory. This tracker crosses NVD data with the CISA catalogue of exploited vulnerabilities and with EPSS probabilities, and puts first the ones somebody is using right now.

Actively exploited

in the CISA KEV catalogue

Full list →
Vulnerabilities in the CISA KEV catalogue, ordered by exploitation probability.
Identifier Severity Product and flaw EPSS In KEV since
CVE-2024-3400 CRIT 10.0 ransomware paloaltonetworks pan-os A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbit 100.0%
CVE-2023-4966 CRIT 9.4 ransomware citrix netscaler_application_delivery_controller Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server. 100.0%
CVE-2023-44487 HIGH 7.5 akka http_server The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 100.0%
CVE-2015-1635 CRIT 9.8 microsoft windows_7 HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability." 100.0%
CVE-2014-6271 CRIT 9.8 apple mac_os_x GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature 100.0%

Series

complete paths, not scattered posts

All series →

From the lab

every step redone and verified

All guides →