PatchNow - Analysis History

About this page: All 372 CVEs analysed by PatchNow since inception. The main page and RSS show only T1190 (internet-facing) vulnerabilities within the KEV timeline window.
372
Visible CVEs
372
CISA KEV Listed
39
Ransomware Use
T1190 (213)
Top Technique
β€”
Avg CVSS
ATT&CK Tactics
ATT&CK Techniques
Ransomware Association
Days CVE β†’ KEV

πŸ” Filter

Loading…
to
to
–
CVE ID / KEV Date Published ATT&CK Technique CVSS Days to KEV Ransomware Affected Products Summary
CVE-2025-48595KEV 2026-06-02 2026-06-01 T1068 Exploitation for Privilege Escalation 8.4 1 day No Android 16-qpr2, Android CVE-2025-48595 is an integer overflow vulnerability in Android that allows local privilege escalation without user interaction. While listed in CISA KEV indicating active exploitation, this is a client-side mobile OS vulnerability not typically deployed as an internet-facing service.
CVE-2026-48027KEV 2026-05-27 2026-05-27 T1176 Software Extensions 9.3 0 days Yes (+1d) Nx Console VS Code Extension A compromised version of the Nx Console VS Code extension contained embedded malicious code. This is a supply chain attack targeting developer workstations, not internet-facing servers.
CVE-2026-45247KEV 2026-06-03 2026-05-26 T1190 Exploit Public-Facing Application 9.8 8 days No Magento 2 with Mirasvit Cache Warmer Critical PHP object injection vulnerability in Mirasvit Cache Warmer for Magento 2 allows unauthenticated remote code execution via crafted cookie data. Affects e-commerce platforms that are inherently internet-facing by design. CISA KEV listing confirms active exploitation.
CVE-2026-34926KEV 2026-05-21 2026-05-21 T1068 Exploitation for Privilege Escalation 6.7 0 days No Trend Micro Apex One, Trend Micro Apex One as a Service A directory traversal vulnerability in Trend Micro Apex One on-premise servers allows pre-authenticated local attackers with administrative credentials to inject malicious code for deployment to agents. This requires local access to the server and existing admin credentials, making it a privilege escalation rather than initial access vector.
CVE-2026-48172KEV 2026-05-26 2026-05-21 T1190 Exploit Public-Facing Application 10.0 5 days No LiteSpeed cPanel Plugin, LiteSpeed WHM Plugin Critical privilege escalation vulnerability in LiteSpeed cPanel/WHM plugins allowing attackers to potentially gain root access via network exploitation. This vulnerability is actively exploited in the wild and affects widely deployed web hosting control panel systems.
CVE-2026-9082KEV 2026-05-22 2026-05-20 T1190 Exploit Public-Facing Application 9.1 2 days No Drupal Critical unauthenticated SQL injection vulnerability in Drupal core affecting installations using PostgreSQL databases. Allows direct remote exploitation of internet-facing Drupal websites for full database access and potential remote code execution.
CVE-2026-41091KEV 2026-05-20 2026-05-20 T1068 Exploitation for Privilege Escalation 7.8 0 days No Microsoft Defender, Windows Defender, Microsoft Malware Protection Engine CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Malware Protection Engine affecting Windows Defender. The vulnerability requires local access and existing low-level privileges to exploit, making it unsuitable for direct internet exploitation despite being in CISA KEV.
CVE-2026-45498KEV 2026-05-20 2026-05-20 T1687 Exploitation for Defense Impairment 4.0 0 days No Microsoft Defender Antimalware Platform CVE-2026-45498 is a denial of service vulnerability in Microsoft Defender Antimalware Platform with local attack vector (CVSS AV:L). Despite being on CISA KEV, this is likely being exploited as part of ransomware attacks to disable endpoint protection rather than for initial access.
CVE-2026-8398KEV 2026-05-27 2026-05-15 T1195 Supply Chain Compromise 9.8 12 days No DAEMON Tools Lite CVE-2026-8398 is a supply chain attack that compromised DAEMON Tools Lite installation packages with embedded malicious code. This is not a traditional network vulnerability but rather a software integrity issue requiring user download and installation of trojanized software.
CVE-2026-42897KEV 2026-05-15 2026-05-14 T1190 Exploit Public-Facing Application 8.1 1 day No Exchange Server, Exchange Server Subscription Edition CVE-2026-42897 is a cross-site scripting vulnerability in Microsoft Exchange Server that enables spoofing attacks. This vulnerability is actively exploited in the wild and affects widely deployed internet-facing email servers through crafted network requests.
CVE-2026-20182KEV 2026-05-14 2026-05-14 T1190 Exploit Public-Facing Application 10.0 0 days No Cisco Catalyst SD-WAN Manager Critical authentication bypass in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain administrative privileges through crafted requests. This vulnerability is actively being exploited in the wild and is listed in CISA's KEV catalog.
CVE-2026-0257KEV 2026-05-29 2026-05-13 T1190 Exploit Public-Facing Application 7.8 16 days No PAN-OS, Prisma Access Authentication bypass vulnerability in GlobalProtect portal/gateway components of Palo Alto Networks PAN-OS allows remote attackers to establish unauthorized VPN connections. Active exploitation confirmed with public PoC available.
CVE-2026-45321KEV 2026-05-27 2026-05-12 T1195 Supply Chain Compromise 9.6 15 days Yes (+1d) TanStack Router Development Tools, TanStack React Router, TanStack Vue Router (+5 more) This is a supply chain compromise where malicious versions of npm packages were published, not a vulnerability in internet-facing applications. The threat is to development environments and CI/CD pipelines that download these packages, not to production servers.
CVE-2026-42208KEV 2026-05-08 2026-05-08 T1190 Exploit Public-Facing Application 9.3 0 days No LiteLLM Proxy Server Critical SQL injection vulnerability in LiteLLM proxy server allowing unauthenticated attackers to read/modify database contents including API keys and credentials. Actively exploited within 36 hours of disclosure and added to CISA KEV catalog.
CVE-2026-6973KEV 2026-05-07 2026-05-07 T1190 Exploit Public-Facing Application 7.2 0 days No Ivanti Endpoint Manager Mobile CVE-2026-6973 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated administrators to achieve remote code execution. EPMM is typically deployed as an internet-facing mobile device management server, making this a direct network exploitation risk.
CVE-2026-0300KEV 2026-05-06 2026-05-06 T1190 Exploit Public-Facing Application 9.3 0 days No Palo Alto PAN-OS Critical unauthenticated buffer overflow vulnerability in Palo Alto PAN-OS User-ID Authentication Portal allowing remote code execution with root privileges. Already under active exploitation in the wild against internet-facing firewalls.
CVE-2026-41940KEV 2026-04-30 2026-04-29 T1190 Exploit Public-Facing Application 9.8 1 day Yes (+5d) cPanel, WHM, WP Squared Critical authentication bypass vulnerability in cPanel and WHM control panels allowing unauthenticated remote attackers to gain unauthorized access. These web hosting management platforms are almost universally internet-facing by design and widely exploited in the wild.
CVE-2026-31431KEV 2026-05-01 2026-04-22 T1068 Exploitation for Privilege Escalation 7.8 9 days No Linux Kernel CVE-2026-31431 is a Linux kernel vulnerability in the crypto subsystem (algif_aead) that requires local access to exploit. Despite being in CISA KEV due to active exploitation, this is a privilege escalation vulnerability that cannot be directly exploited over the internet.
CVE-2026-32201KEV 2026-04-14 2026-04-14 T1190 Exploit Public-Facing Application 6.5 0 days No SharePoint Server, SharePoint Server Subscription Edition, SharePoint Enterprise Server SharePoint Server spoofing vulnerability allowing unauthorized attackers to exploit via network access without authentication or user interaction. Listed in CISA KEV indicating active exploitation.
CVE-2026-33825KEV 2026-04-22 2026-04-14 T1068 Exploitation for Privilege Escalation 7.8 8 days No Microsoft Defender Antimalware Platform This is a local privilege escalation vulnerability in Microsoft Defender Antimalware Platform that requires existing local access to the system. Despite being high severity and in CISA KEV, it cannot be exploited directly over the internet as it's an endpoint security tool, not a public-facing service.
CVE-2026-32202KEV 2026-04-28 2026-04-14 T1203 Exploitation for Client Execution 4.3 14 days No Windows, Windows Server, Windows Server 2012 R2 Windows Shell spoofing vulnerability affecting client Windows systems that requires user interaction (UI:R in CVSS). Despite network attack vector, this is primarily a client-side vulnerability requiring user interaction rather than direct server exploitation.
CVE-2026-34621KEV 2026-04-13 2026-04-11 T1203 Exploitation for Client Execution 8.6 2 days No Adobe Acrobat Reader Adobe Acrobat Reader is affected by a prototype pollution vulnerability that enables arbitrary code execution. Exploitation requires a user to open a malicious PDF file, making this a client-side attack rather than server exploitation.
CVE-2026-39987KEV 2026-04-23 2026-04-09 T1190 Exploit Public-Facing Application 9.3 14 days No Marimo Python Notebook Server Marimo Python notebook server has a critical pre-authentication RCE vulnerability allowing unauthenticated attackers to execute arbitrary system commands via an unprotected terminal WebSocket endpoint. This vulnerability is actively exploited in the wild and was added to CISA KEV catalog after being exploited within 10 hours of disclosure.
CVE-2026-34197KEV 2026-04-16 2026-04-07 T1190 Exploit Public-Facing Application 8.8 9 days No Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All Critical remote code execution vulnerability in Apache ActiveMQ through the Jolokia JMX-HTTP bridge exposed on web console. Authenticated attackers can exploit crafted discovery URIs to trigger remote Spring XML loading, leading to arbitrary code execution via bean factory methods.
CVE-2026-35616KEV 2026-04-06 2026-04-04 T1190 Exploit Public-Facing Application 9.1 2 days No Fortinet FortiClient EMS Critical unauthenticated remote code execution vulnerability in Fortinet FortiClient EMS management server. Allows attackers to execute arbitrary code via crafted network requests without authentication.
CVE-2026-5281KEV 2026-04-01 2026-04-01 T1189 Drive-by Compromise 8.8 0 days No Chrome CVE-2026-5281 is a use-after-free vulnerability in Google Chrome's Dawn component that allows arbitrary code execution via crafted HTML pages. While actively exploited in the wild, this affects client-side browser software, not internet-facing servers, making it a phishing/social engineering attack vector rather than direct internet exploitation.
CVE-2026-3502KEV 2026-04-02 2026-03-30 T1557 Adversary-in-the-Middle 7.8 3 days No TrueConf Client TrueConf Client fails to verify update integrity, allowing attackers who can intercept the update delivery path to inject malicious code. This requires network positioning and user-initiated update actions, making direct internet exploitation unlikely.
CVE-2026-33634KEV 2026-03-26 2026-03-23 T1195 Supply Chain Compromise 9.4 3 days No Trivy Security Scanner, LiteLLM, Trivy GitHub Actions CVE-2026-33634 represents a supply chain compromise where malicious code was embedded in security tools (Trivy, LiteLLM) and GitHub Actions. While technically network-exploitable, this is not a direct internet-facing application vulnerability but rather requires victims to download and execute compromised packages.
CVE-2026-3055KEV 2026-03-30 2026-03-23 T1190 Exploit Public-Facing Application 9.3 7 days No NetScaler ADC, NetScaler Gateway Critical memory overread vulnerability in NetScaler ADC and Gateway when configured as SAML IDP. Actively exploited in the wild with CISA KEV listing, directly exploitable over the network without authentication.
CVE-2026-33017KEV 2026-03-25 2026-03-20 T1190 Exploit Public-Facing Application 9.3 5 days No Langflow AI Platform < Critical unauthenticated remote code execution vulnerability in Langflow AI platform via public flow build endpoint. Attackers can execute arbitrary Python code without authentication, leading to complete system compromise.
CVE-2026-3910KEV 2026-03-13 2026-03-12 T1189 Drive-by Compromise 8.8 1 day No Chrome CVE-2026-3910 is a Chrome V8 engine vulnerability that allows remote code execution via malicious HTML pages. While actively exploited, this requires user interaction and targets client browsers, not internet-facing servers.
CVE-2026-3909KEV 2026-03-13 2026-03-12 T1189 Drive-by Compromise 8.8 1 day No Chrome CVE-2026-3909 is an out-of-bounds write vulnerability in Google Chrome's Skia component that requires user interaction (visiting a crafted HTML page). While actively exploited and severe for end-users, it does not affect internet-facing server applications and requires social engineering or phishing for exploitation.
CVE-2026-20131KEV 2026-03-19 2026-03-04 T1190 Exploit Public-Facing Application 10.0 15 days Yes Cisco Secure Firewall Management Center Critical insecure deserialization vulnerability in Cisco Secure Firewall Management Center web interface allows unauthenticated remote code execution as root. Already exploited in the wild by Interlock ransomware group since January 2026.
CVE-2026-21385KEV 2026-03-03 2026-03-02 T1068 Exploitation for Privilege Escalation 7.8 1 day No Snapdragon Mobile Platforms, Snapdragon Automotive Platforms, Snapdragon IoT Platforms (+5 more) CVE-2026-21385 is an integer overflow vulnerability in Qualcomm Snapdragon graphics processing causing memory corruption. While listed in CISA KEV indicating active exploitation, this affects primarily mobile devices, automotive systems, and embedded IoT platforms rather than internet-facing servers.
CVE-2026-22719KEV 2026-03-03 2026-02-25 T1190 Exploit Public-Facing Application 8.1 6 days No VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform (+1 more) Command injection vulnerability in VMware Aria Operations allows unauthenticated remote code execution during support-assisted product migration. Affects critical enterprise infrastructure management platforms commonly exposed to internet.
CVE-2026-20122KEV 2026-04-20 2026-02-25 T1190 Exploit Public-Facing Application 5.4 54 days No Cisco Catalyst SD-WAN Manager CVE-2026-20122 is a critical arbitrary file overwrite vulnerability in Cisco Catalyst SD-WAN Manager's API that allows authenticated attackers to gain elevated privileges. This vulnerability is actively exploited in the wild and listed in CISA's KEV catalog.
CVE-2026-20127KEV 2026-02-25 2026-02-25 T1190 Exploit Public-Facing Application 10.0 0 days No Cisco Catalyst SD-WAN Manager Critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain administrative privileges. CISA has issued Emergency Directive ED 26-03 due to active exploitation in the wild.
CVE-2026-20128KEV 2026-04-20 2026-02-25 T1078 Valid Accounts 7.5 54 days No Cisco Catalyst SD-WAN Manager CVE-2026-20128 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager that exposes DCA user credentials in a readable file. The CVSS shows LOCAL attack vector, requiring high privileges and high complexity, making direct internet exploitation unlikely despite CISA KEV listing.
CVE-2026-20133KEV 2026-04-20 2026-02-25 T1190 Exploit Public-Facing Application 6.5 54 days No Cisco Catalyst SD-WAN Manager CVE-2026-20133 is an information disclosure vulnerability in Cisco Catalyst SD-WAN Manager that allows unauthenticated, remote attackers to view sensitive information by accessing the API. SD-WAN Manager is typically deployed as an internet-facing centralized management platform.
CVE-2026-22769KEV 2026-02-18 2026-02-17 T1190 Exploit Public-Facing Application 10.0 1 day No Dell RecoverPoint for Virtual Machines Dell RecoverPoint for VMs contains hardcoded credentials allowing unauthenticated remote attackers to gain root-level access to the underlying OS. This critical vulnerability is under active exploitation in the wild.
CVE-2026-2441KEV 2026-02-17 2026-02-13 T1189 Drive-by Compromise 8.8 4 days No Chrome CVE-2026-2441 is a use-after-free vulnerability in Chrome's CSS processing that allows remote code execution via malicious HTML pages. Despite active exploitation, this affects client-side browser software, not internet-facing servers, requiring user interaction to visit malicious websites.
CVE-2026-25108KEV 2026-02-24 2026-02-13 T1190 Exploit Public-Facing Application 8.8 11 days No FileZen V5.0.0-V5.0.10, FileZen V4.2.1-V4.2.8 FileZen contains an OS command injection vulnerability allowing authenticated users to execute arbitrary OS commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. This is a critical server-side vulnerability in a file sharing platform commonly deployed as internet-facing infrastructure.
CVE-2026-20700KEV 2026-02-12 2026-02-11 T1068 Exploitation for Privilege Escalation 7.8 1 day No iOS, iPadOS, macOS (+3 more) Memory corruption vulnerability in Apple operating systems that allows arbitrary code execution with memory write capability. Despite being in CISA KEV due to active exploitation, this affects client-side operating systems that are rarely deployed as internet-facing servers.
CVE-2026-21525KEV 2026-02-10 2026-02-10 T1499 Endpoint Denial of Service 6.2 0 days No Windows Server, Windows Server 2012 R2, Windows CVE-2026-21525 is a null pointer dereference vulnerability in Windows Remote Access Connection Manager that allows local denial of service attacks. Despite being in CISA KEV, the CVSS attack vector is LOCAL, making it unsuitable for direct internet exploitation.
CVE-2026-21514KEV 2026-02-10 2026-02-10 T1203 Exploitation for Client Execution 7.8 0 days No Microsoft 365 Apps for Enterprise, Microsoft Office LTSC, Microsoft Office LTSC for Mac Security feature bypass vulnerability in Microsoft Word that allows attackers to bypass security protections when users open malicious documents. Requires local access and user interaction, making it unsuitable for direct internet exploitation despite being in CISA KEV.
CVE-2026-21510KEV 2026-02-10 2026-02-10 T1548 Abuse Elevation Control Mechanism 8.8 0 days No Windows, Windows Server 2012/2012 R2, Windows Server Windows Shell security feature bypass vulnerability with high CVSS score but requires user interaction. Affects primarily client systems with minimal internet-facing deployment likelihood.
CVE-2026-21513KEV 2026-02-10 2026-02-10 T1189 Drive-by Compromise 8.8 0 days No Windows, Windows Server, Windows Server 2012/2012 R2 MSHTML Framework security feature bypass vulnerability requiring user interaction. While CVSS shows network attack vector, MSHTML is a client-side HTML rendering engine used in browsers and applications, not an internet-facing server service.
CVE-2026-21533KEV 2026-02-10 2026-02-10 T1133 External Remote Services 7.8 0 days No Windows Server, Windows Server 2012 R2, Windows Windows Remote Desktop Services privilege escalation vulnerability affecting multiple Windows versions. Allows authorized attackers to elevate privileges locally, potentially leading to full system compromise on RDP-enabled systems. Listed in CISA KEV indicating active exploitation.
CVE-2026-21519KEV 2026-02-10 2026-02-10 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows, Windows Server This is a local privilege escalation vulnerability in the Windows Desktop Window Manager (DWM) that requires local authentication and user interaction. While it affects both client and server Windows systems, it cannot be directly exploited over the internet as it requires local access to the system.
CVE-2026-1603KEV 2026-03-09 2026-02-10 T1190 Exploit Public-Facing Application 8.6 27 days No Ivanti Endpoint Manager CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager that allows remote unauthenticated attackers to leak stored credential data. This vulnerability is actively exploited according to CISA KEV listing and can be directly exploited against internet-facing EPM instances.
CVE-2026-1731KEV 2026-02-13 2026-02-06 T1190 Exploit Public-Facing Application 9.9 7 days Yes (+6d) BeyondTrust Remote Support, BeyondTrust Privileged Remote Access Critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access allowing unauthenticated attackers to execute OS commands via specially crafted requests. Active exploitation confirmed with CISA KEV listing.
CVE-2026-21643KEV 2026-04-13 2026-02-06 T1190 Exploit Public-Facing Application 9.1 66 days No Fortinet FortiClient EMS Critical unauthenticated SQL injection vulnerability in Fortinet FortiClient EMS 7.4.4 allows remote code execution via HTTP requests. This vulnerability is actively being exploited in the wild and has been added to CISA's KEV catalog.
CVE-2025-15556KEV 2026-02-12 2026-02-03 T1203 Exploitation for Client Execution 7.7 9 days No Notepad++ Notepad++ WinGUp updater lacks cryptographic verification of updates, allowing man-in-the-middle attacks to deliver malicious installers. This is a client application vulnerability requiring user interaction (running the updater) and is not directly exploitable against internet-facing services.
CVE-2026-1340KEV 2026-04-08 2026-01-29 T1190 Exploit Public-Facing Application 9.8 69 days No Ivanti Endpoint Manager Mobile Critical code injection vulnerability in Ivanti Endpoint Manager Mobile allowing unauthenticated remote code execution via network exploitation. This vulnerability is actively being exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog.
CVE-2026-1281KEV 2026-01-29 2026-01-29 T1190 Exploit Public-Facing Application 9.8 0 days No Ivanti Endpoint Manager Mobile Critical code injection vulnerability in Ivanti Endpoint Manager Mobile allowing unauthenticated remote code execution. This vulnerability is actively exploited in zero-day attacks and listed on CISA's KEV catalog.
CVE-2025-40551KEV 2026-02-03 2026-01-28 T1190 Exploit Public-Facing Application 9.8 6 days No SolarWinds Web Help Desk 12.8.8 HF1 and below Critical unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk via untrusted data deserialization. Actively exploited in the wild with no authentication required.
CVE-2025-40536KEV 2026-02-12 2026-01-28 T1190 Exploit Public-Facing Application 8.1 15 days No SolarWinds Web Help Desk 12.8.8 HF1 and below CVE-2025-40536 is a security control bypass vulnerability in SolarWinds Web Help Desk that allows unauthenticated attackers to gain access to restricted functionality. This vulnerability is being actively exploited in the wild against internet-facing WHD instances for initial access and lateral movement.
CVE-2026-24858KEV 2026-01-27 2026-01-27 T1190 Exploit Public-Facing Application 9.4 0 days No FortiOS, FortiAnalyzer, FortiManager Authentication bypass vulnerability in Fortinet FortiOS, FortiAnalyzer, and FortiManager allowing attackers with FortiCloud accounts to access other organizations' devices when FortiCloud SSO is enabled. CISA KEV listing indicates active exploitation in the wild.
CVE-2026-21509KEV 2026-01-26 2026-01-26 T1204 User Execution 7.8 0 days No Microsoft 365 Apps for Enterprise, Microsoft Office, Microsoft Office LTSC CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office applications that requires local access and user interaction (AV:L/UI:R). Despite being in CISA KEV, it primarily affects client-side Office applications through malicious documents rather than internet-facing servers.
CVE-2026-24423KEV 2026-02-05 2026-01-23 T1190 Exploit Public-Facing Application 9.3 13 days Yes (+9d) SmarterMail Critical unauthenticated remote code execution vulnerability in SmarterMail servers through the ConnectToHub API method. Attackers can execute arbitrary OS commands by pointing the server to a malicious HTTP server, with active exploitation confirmed by CISA KEV listing.
CVE-2026-23760KEV 2026-01-26 2026-01-22 T1190 Exploit Public-Facing Application 9.3 4 days Yes (+31d) SmarterMail Critical authentication bypass vulnerability in SmarterMail email server allowing complete administrative takeover via password reset API. Over 6,000 vulnerable instances are internet-facing with active exploitation confirmed by CISA KEV listing.
CVE-2026-20045KEV 2026-01-21 2026-01-21 T1190 Exploit Public-Facing Application 8.2 0 days No Cisco Unified Communications Manager, Cisco Unity Connection, Cisco Unified Communications Manager IM and Presence Service Critical remote code execution vulnerability in Cisco Unified Communications products allowing unauthenticated attackers to execute arbitrary commands via crafted HTTP requests to web management interfaces. Cisco confirms active exploitation attempts in the wild with potential for privilege escalation to root access.
CVE-2026-24061KEV 2026-01-26 2026-01-21 T1190 Exploit Public-Facing Application 9.8 5 days No GNU InetUtils telnetd Critical authentication bypass vulnerability in GNU InetUtils telnetd allows remote attackers to gain root access without credentials via malformed USER environment variable. Over 800,000 telnet servers are exposed on the internet with active exploitation observed in the wild.
CVE-2026-20963KEV 2026-03-18 2026-01-13 T1190 Exploit Public-Facing Application 8.8 64 days No SharePoint Server, SharePoint Server Subscription Edition CVE-2026-20963 is a critical deserialization vulnerability in Microsoft SharePoint Server that allows remote code execution for authorized attackers over the network. This vulnerability is actively exploited by nation-state actors and is listed in CISA's KEV catalog, targeting internet-facing SharePoint deployments.
CVE-2026-20805KEV 2026-01-13 2026-01-13 T1068 Exploitation for Privilege Escalation 5.5 0 days No Windows, Windows Server, Windows Server 2012 R2 CVE-2026-20805 is a local information disclosure vulnerability in the Windows Desktop Window Manager (DWM) that requires local access and authentication. Despite being in CISA KEV, this is not directly internet exploitable as it affects client-side Windows desktop components.
CVE-2025-66376KEV 2026-03-18 2026-01-05 T1190 Exploit Public-Facing Application 7.2 72 days No Zimbra Collaboration CVE-2025-66376 is a stored XSS vulnerability in Zimbra Collaboration's Classic UI that allows remote attackers to execute malicious scripts via CSS @import directives in HTML emails. This vulnerability affects internet-facing email servers and has been actively exploited by Russian APT groups.
CVE-2025-52691KEV 2026-01-26 2025-12-29 T1190 Exploit Public-Facing Application 10.0 28 days Yes (+85d) SmarterMail Build 9406 and earlier Critical unauthenticated file upload vulnerability in SmarterMail email servers allowing arbitrary file upload to any server location, leading to remote code execution. Active exploitation is occurring in the wild against internet-facing mail servers.
CVE-2025-68645KEV 2026-01-22 2025-12-22 T1190 Exploit Public-Facing Application 8.8 31 days No Zimbra Collaboration Local File Inclusion vulnerability in Zimbra Collaboration webmail allows unauthenticated remote attackers to include arbitrary files via crafted requests to /h/rest endpoint. Zimbra is commonly deployed as internet-facing email server infrastructure.
CVE-2025-68613KEV 2026-03-11 2025-12-19 T1190 Exploit Public-Facing Application 10.0 82 days No n8n workflow automation platform Critical Remote Code Execution vulnerability in n8n workflow automation platform allowing authenticated users to execute arbitrary code through expression injection. n8n is commonly deployed as an internet-facing service for workflow automation and API integrations.
CVE-2025-14847KEV 2025-12-29 2025-12-19 T1190 Exploit Public-Facing Application 7.5 10 days No MongoDB Server Critical memory disclosure vulnerability in MongoDB Server allowing unauthenticated remote attackers to read heap memory through malformed Zlib compressed protocol headers. CISA has added this to KEV catalog due to confirmed active exploitation in the wild.
CVE-2025-14733KEV 2025-12-19 2025-12-19 T1190 Exploit Public-Facing Application 9.3 0 days No WatchGuard Fireware OS Critical out-of-bounds write vulnerability in WatchGuard Fireware OS affecting IKEv2 VPN services. Remote unauthenticated attackers can execute arbitrary code on internet-facing firewall systems through direct network exploitation.
CVE-2025-40602KEV 2025-12-17 2025-12-18 T1190 Exploit Public-Facing Application 6.6 -1 days No SonicWall SMA1000 CVE-2025-40602 is a local privilege escalation vulnerability in SonicWall SMA1000 appliances that is being actively exploited in the wild when chained with CVE-2025-23006. CISA has added this to the KEV catalog due to confirmed exploitation.
CVE-2025-68461KEV 2026-02-20 2025-12-18 T1190 Exploit Public-Facing Application 7.2 64 days No Roundcube Webmail <, Roundcube Webmail 1.6.x < CVE-2025-68461 is a Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail that allows attackers to execute malicious JavaScript via SVG animate tags. This directly affects internet-facing webmail servers and can lead to email account takeover without user credentials.
CVE-2025-43529KEV 2025-12-15 2025-12-17 T1189 Drive-by Compromise 9.8 -2 days No Safari, iOS and iPadOS, macOS (+3 more) CVE-2025-43529 is a use-after-free vulnerability in WebKit that affects client applications (Safari browser, iOS/iPadOS, tvOS, visionOS) when processing malicious web content. While actively exploited and on CISA KEV, this requires user interaction to visit malicious websites rather than direct exploitation of internet-facing servers.
CVE-2025-20393KEV 2025-12-17 2025-12-17 T1190 Exploit Public-Facing Application 10.0 0 days No Cisco Secure Email Gateway, Cisco Secure Email and Web Manager Critical remote command execution vulnerability in Cisco Secure Email Gateway and Manager appliances with CVSS 10.0 score requiring no authentication or user interaction. CISA has added this to their KEV catalog due to active exploitation in the wild targeting these internet-facing email security appliances.
CVE-2025-59374KEV 2025-12-17 2025-12-17 T1203 Exploitation for Client Execution 9.3 0 days No ASUS Live Update CVE-2025-59374 affects ASUS Live Update, a client-side software utility that was compromised through a supply chain attack with embedded malicious code. While it has network attack vector and is in CISA KEV, it's a client application not typically internet-facing.
CVE-2025-37164KEV 2026-01-07 2025-12-16 T1190 Exploit Public-Facing Application 10.0 22 days No HPE OneView CVE-2025-37164 is a critical unauthenticated remote code execution vulnerability in HPE OneView with a perfect CVSS score of 10.0. CISA has added this to their KEV catalog due to active exploitation in the wild, and a Metasploit module exists for exploitation.
CVE-2025-14611KEV 2025-12-15 2025-12-12 T1190 Exploit Public-Facing Application 7.1 3 days No Gladinet CentreStack, Gladinet TrioFox Gladinet CentreStack and TrioFox use hardcoded AES keys enabling unauthenticated arbitrary local file inclusion on public-facing endpoints. This vulnerability is actively exploited and listed in CISA's KEV catalog.
CVE-2025-43510KEV 2026-03-20 2025-12-12 T1068 Exploitation for Privilege Escalation 7.8 98 days No iOS, iPadOS, macOS (+3 more) CVE-2025-43510 is a memory corruption vulnerability in Apple's consumer operating systems that allows a malicious application to cause unexpected changes in shared memory. This requires local access and user interaction to install a malicious app, making it unsuitable for direct internet exploitation despite being actively exploited in the wild.
CVE-2025-43520KEV 2026-03-20 2025-12-12 T1068 Exploitation for Privilege Escalation 5.5 98 days No iOS and iPadOS, macOS, tvOS (+2 more) CVE-2025-43520 is a memory corruption vulnerability in Apple operating systems that allows malicious applications to cause system termination or write kernel memory. This is a local privilege escalation vulnerability requiring a malicious application to already be running on the device.
CVE-2025-14174KEV 2025-12-12 2025-12-12 T1189 Drive-by Compromise 8.8 0 days No Chrome, Microsoft Edge CVE-2025-14174 is an out-of-bounds memory access vulnerability in Google Chrome that requires user interaction with a crafted HTML page. While actively exploited and in CISA KEV, it affects client-side browser software, not internet-facing servers.
CVE-2025-8110KEV 2026-01-12 2025-12-10 T1190 Exploit Public-Facing Application 8.7 33 days No Gogs versions Critical RCE vulnerability in Gogs Git service allows authenticated users to achieve remote code execution via symbolic link bypass in the PutContents API. Over 700 internet-facing instances have been compromised with active exploitation ongoing.
CVE-2025-62221KEV 2025-12-09 2025-12-09 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows, Windows Server A use-after-free vulnerability in Windows Cloud Files Mini Filter Driver allows local privilege escalation. Despite being in CISA KEV indicating active exploitation, this requires local authenticated access and cannot be exploited directly from the internet.
CVE-2025-59718KEV 2025-12-16 2025-12-09 T1190 Exploit Public-Facing Application 9.1 7 days No FortiOS, FortiProxy, FortiSwitchManager Critical SAML authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiSwitchManager allowing unauthenticated attackers to bypass FortiCloud SSO login authentication via crafted SAML response messages. CISA has confirmed active exploitation of this vulnerability.
CVE-2025-48633KEV 2025-12-02 2025-12-08 T1068 Exploitation for Privilege Escalation 5.5 -6 days No Android A local privilege escalation vulnerability in Android's DevicePolicyManagerService allows adding a Device Owner after provisioning. This is a mobile OS vulnerability requiring local access and cannot be exploited over the internet despite being in CISA KEV.
CVE-2025-48572KEV 2025-12-02 2025-12-08 T1068 Exploitation for Privilege Escalation 7.8 -6 days No Android This is a local privilege escalation vulnerability in Android that allows launching activities from the background due to a permissions bypass. While highly impactful on mobile devices and actively exploited according to CISA KEV, it cannot be exploited over the internet as it requires local access to the Android device.
CVE-2025-34291KEV 2026-05-21 2025-12-05 T1190 Exploit Public-Facing Application 9.4 167 days No Langflow AI Framework Critical CORS misconfiguration in Langflow AI framework allows account takeover and remote code execution through cross-origin token hijacking. Affects internet-facing Langflow deployments up to version 1.6.9, with active exploitation observed in the wild.
CVE-2025-66644KEV 2025-12-08 2025-12-05 T1190 Exploit Public-Facing Application 7.2 3 days No Array Networks ArrayOS AG Critical OS command injection vulnerability in Array Networks ArrayOS AG VPN appliances affecting versions before 9.4.5.9. Active exploitation confirmed in the wild from August-December 2025 with attackers deploying webshells for persistent access.
CVE-2025-55182KEV 2025-12-05 2025-12-03 T1190 Exploit Public-Facing Application 10.0 2 days Yes (+71d) React Server Components, Next.js applications with App Router and Server Actions, react-server-dom-webpack (+2 more) Critical pre-authentication remote code execution vulnerability in React Server Components allowing arbitrary code execution through unsafe deserialization of HTTP requests. Multiple threat actors are actively exploiting this vulnerability against internet-facing React applications.
CVE-2025-58360KEV 2025-12-11 2025-11-25 T1190 Exploit Public-Facing Application 8.2 16 days No GeoServer GeoServer has an unauthenticated XML External Entity (XXE) vulnerability in the WMS GetMap feature that can be exploited directly over the network. CISA has confirmed active exploitation in the wild.
CVE-2025-58034KEV 2025-11-18 2025-11-18 T1190 Exploit Public-Facing Application 6.7 0 days No Fortinet FortiWeb OS command injection vulnerability in Fortinet FortiWeb allowing authenticated attackers to execute unauthorized code via crafted HTTP requests or CLI commands. FortiWeb is a web application firewall that is almost universally deployed as an internet-facing service to protect web applications.
CVE-2025-13223KEV 2025-11-19 2025-11-17 T1189 Drive-by Compromise 8.8 2 days No Chrome CVE-2025-13223 is a type confusion vulnerability in Chrome's V8 engine exploited via crafted HTML pages. While actively exploited in the wild, it requires user interaction to visit malicious websites, making it primarily a client-side phishing attack rather than direct server exploitation.
CVE-2025-64446KEV 2025-11-14 2025-11-14 T1190 Exploit Public-Facing Application 9.1 0 days No Fortinet FortiWeb Critical path traversal vulnerability in Fortinet FortiWeb web application firewalls allows remote execution of administrative commands via crafted HTTP/HTTPS requests. Active exploitation is occurring in the wild with attackers creating administrative accounts for persistent access.
CVE-2025-62215KEV 2025-11-12 2025-11-11 T1068 Exploitation for Privilege Escalation 7.0 1 day No Windows Server, Windows CVE-2025-62215 is a Windows kernel race condition vulnerability that allows local privilege escalation. While it affects Windows Server products, the CVSS attack vector is LOCAL (AV:L) requiring existing system access, making it unsuitable for direct internet exploitation.
CVE-2025-60710KEV 2026-04-13 2025-11-11 T1068 Exploitation for Privilege Escalation 7.8 153 days No Windows Server, Windows 11 Version 24H2, Windows 11 Version 25H2 CVE-2025-60710 is a local privilege escalation vulnerability in the Host Process for Windows Tasks component affecting Windows 11 and Windows Server 2025. The vulnerability requires local authenticated access and exploits improper link resolution to elevate privileges.
CVE-2025-12480KEV 2025-11-12 2025-11-10 T1190 Exploit Public-Facing Application 9.1 2 days No TrioFox File Sharing Platform CVE-2025-12480 is a critical authentication bypass vulnerability in TrioFox file sharing platforms that allows unauthenticated attackers to access administrative setup pages. The vulnerability is being actively exploited in the wild and has been added to CISA's KEV catalog.
CVE-2025-64328KEV 2026-02-03 2025-11-07 T1190 Exploit Public-Facing Application 8.6 88 days No FreePBX Endpoint Manager, FreePBX Administration GUI FreePBX Administration GUI contains an authenticated OS command injection vulnerability that allows attackers to execute arbitrary commands on the system. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2023-43000KEV 2026-03-05 2025-11-05 T1189 Drive-by Compromise 8.8 120 days No Safari, iOS/iPadOS, macOS CVE-2023-43000 is a use-after-free vulnerability in WebKit that affects client-side applications (Safari, iOS/iPadOS browsers, macOS Safari). Despite evidence of active exploitation, this requires user interaction to visit malicious websites and does not qualify as direct internet exploitation of public-facing applications.
CVE-2025-11953KEV 2026-02-05 2025-11-03 T1190 Exploit Public-Facing Application 9.8 94 days No React Native Metro Development Server, React Native Community CLI Critical OS command injection vulnerability in React Native Metro Development Server that binds to external interfaces by default. Allows unauthenticated remote attackers to execute arbitrary commands via HTTP POST requests.
CVE-2025-61757KEV 2025-11-21 2025-10-21 T1190 Exploit Public-Facing Application 9.8 31 days No Oracle Identity Manager Critical pre-authentication remote code execution vulnerability in Oracle Identity Manager REST WebServices component. Allows complete system takeover via unauthenticated HTTP requests with CISA-confirmed active exploitation.
CVE-2025-61932KEV 2025-10-22 2025-10-20 T1190 Exploit Public-Facing Application 9.8 2 days No Motex Lanscope Endpoint Manager On-Premises v9.4.7.1 and earlier Critical vulnerability in Motex Lanscope Endpoint Manager allowing remote code execution through improper verification of incoming network requests. Active exploitation confirmed with CISA KEV listing.
CVE-2025-53521KEV 2026-03-27 2025-10-15 T1190 Exploit Public-Facing Application 9.8 163 days No F5 BIG-IP APM Critical remote code execution vulnerability in F5 BIG-IP APM that can be exploited via network traffic without authentication. BIG-IP systems are commonly deployed as internet-facing load balancers and application delivery controllers.
CVE-2025-59287KEV 2025-10-24 2025-10-14 T1190 Exploit Public-Facing Application 9.8 10 days No Windows Server, Windows Server 2012 R2 Critical deserialization vulnerability in Windows Server Update Services (WSUS) allows unauthenticated remote code execution over the network. WSUS servers are commonly deployed as centralized internet-facing infrastructure for managing Windows updates in enterprise environments.
CVE-2025-59230KEV 2025-10-14 2025-10-14 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows CVE-2025-59230 is a local privilege escalation vulnerability in Windows Remote Access Connection Manager with improper access control (CWE-284). The CVSS vector shows AV:L (Local attack vector) requiring an authorized attacker to be locally authenticated, making this not directly exploitable over the internet.
CVE-2025-24990KEV 2025-10-14 2025-10-14 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows, Windows Server 2008 SP2, Windows Server 2008 R2 SP1 (+2 more) CVE-2025-24990 is a local privilege escalation vulnerability in the Agere Modem driver affecting multiple Windows versions. Despite being listed in CISA KEV, this is a local vulnerability requiring existing system access and is not directly exploitable over the internet.
CVE-2025-61884KEV 2025-10-20 2025-10-12 T1190 Exploit Public-Facing Application 7.5 8 days Yes (+117d) Oracle E-Business Suite Configurator CVE-2025-61884 is a high-severity vulnerability in Oracle E-Business Suite Configurator that allows unauthenticated remote attackers to access critical data via HTTP. The vulnerability has been actively exploited in the wild and added to CISA's KEV catalog.
CVE-2025-11371KEV 2025-11-04 2025-10-09 T1190 Exploit Public-Facing Application 7.5 26 days No CentreStack, TrioFox CVE-2025-11371 is an unauthenticated Local File Inclusion vulnerability in Gladinet CentreStack and TrioFox file-sharing platforms. This zero-day vulnerability has been actively exploited in the wild and allows attackers to access system files without authentication.
CVE-2025-61882KEV 2025-10-06 2025-10-05 T1190 Exploit Public-Facing Application 9.8 1 day Yes (+131d) Oracle E-Business Suite Concurrent Processing Critical unauthenticated remote code execution vulnerability in Oracle E-Business Suite Concurrent Processing component accessible via HTTP. Actively exploited by Cl0p ransomware group for data theft attacks with complete system takeover potential.
CVE-2025-41244KEV 2025-10-30 2025-09-29 T1068 Exploitation for Privilege Escalation 7.8 31 days No VMware Tools, VMware Aria Operations, VMware Cloud Foundation (+3 more) CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools. Despite being listed in CISA KEV, it requires local access to a VM with VMware Tools installed and is not directly exploitable over the internet.
CVE-2025-20362KEV 2025-09-25 2025-09-25 T1190 Exploit Public-Facing Application 6.5 0 days No Cisco ASA Software, Cisco Firepower Threat Defense Software CVE-2025-20362 is a missing authorization vulnerability in Cisco ASA and FTD VPN web servers that allows unauthenticated remote attackers to access restricted URL endpoints. The vulnerability is being actively exploited in the wild and affects internet-facing firewall appliances.
CVE-2025-20333KEV 2025-09-25 2025-09-25 T1190 Exploit Public-Facing Application 9.9 0 days No Cisco ASA Software, Cisco Firepower Threat Defense Software CVE-2025-20333 is a critical buffer overflow vulnerability in the VPN web server component of Cisco ASA and Firepower Threat Defense Software that allows authenticated remote attackers to execute arbitrary code as root. This vulnerability is actively being exploited in the wild and affects internet-facing VPN appliances that are commonly deployed with public internet access.
CVE-2025-20352KEV 2025-09-29 2025-09-24 T1190 Exploit Public-Facing Application 7.7 5 days No Cisco IOS, Cisco IOS XE, Cisco IOS XE Catalyst SD-WAN Critical SNMP stack overflow vulnerability in Cisco IOS/IOS XE that allows remote code execution with high privileges or denial of service with low privileges. Actively exploited in the wild against network infrastructure devices commonly exposed to the internet.
CVE-2025-10585KEV 2025-09-23 2025-09-24 T1189 Drive-by Compromise Not provided in CIRCL data -1 days No Chrome CVE-2025-10585 is a type confusion vulnerability in Chrome's V8 engine that allows remote code execution via crafted HTML pages. While actively exploited as a zero-day, it requires user interaction to visit malicious websites, making it a client-side attack rather than direct server exploitation.
CVE-2025-26399KEV 2026-03-09 2025-09-23 T1190 Exploit Public-Facing Application 9.8 167 days No SolarWinds Web Help Desk Critical unauthenticated remote code execution vulnerability in SolarWinds Web Help Desk affecting the AjaxProxy component. This is a bypass of previous patches and allows direct exploitation over the internet without authentication.
CVE-2025-48703KEV 2025-11-04 2025-09-19 T1190 Exploit Public-Facing Application 9.0 46 days No CentOS Web Panel, Control Web Panel Critical unauthenticated remote code execution vulnerability in CentOS Web Panel through OS command injection in the filemanager module. Actively exploited in the wild with public PoC exploits and Metasploit modules available.
CVE-2025-59689KEV 2025-09-29 2025-09-19 T1190 Exploit Public-Facing Application 6.1 10 days No Libraesva Email Security Gateway 4.5 - 5.5.x Critical command injection vulnerability in Libraesva Email Security Gateway allowing remote code execution via malicious compressed email attachments. This vulnerability is actively exploited in the wild and affects internet-facing email security appliances.
CVE-2025-10035KEV 2025-09-29 2025-09-18 T1190 Exploit Public-Facing Application 10.0 11 days Yes (+138d) Fortra GoAnywhere MFT versions <= CVE-2025-10035 is a critical deserialization vulnerability in Fortra GoAnywhere MFT's License Servlet that allows unauthenticated remote code execution. This vulnerability has been actively exploited as a zero-day and affects internet-facing managed file transfer servers.
CVE-2025-9242KEV 2025-11-12 2025-09-17 T1190 Exploit Public-Facing Application 9.3 56 days No WatchGuard Firewall/Fireware OS Critical out-of-bounds write vulnerability in WatchGuard Fireware OS affecting IKEv2 VPN services that allows unauthenticated remote code execution. This is actively exploited in the wild according to CISA KEV and affects security appliances that are inherently internet-facing by design.
CVE-2025-21043KEV 2025-10-02 2025-09-12 T1203 Exploitation for Client Execution 8.8 20 days No Samsung Android devices CVE-2025-21043 is an out-of-bounds write vulnerability in Samsung Android devices' image codec library that requires user interaction for exploitation. While actively exploited as a zero-day, it affects client devices rather than internet-facing servers.
CVE-2025-21042KEV 2025-11-10 2025-09-12 T1203 Exploitation for Client Execution 8.8 59 days No Samsung Galaxy Mobile Devices CVE-2025-21042 is an out-of-bounds write vulnerability in Samsung mobile devices' image processing library that requires user interaction with malicious DNG image files. While actively exploited via messaging apps like WhatsApp, it targets client devices rather than internet-facing servers.
CVE-2025-54236KEV 2025-10-24 2025-09-09 T1190 Exploit Public-Facing Application 9.1 45 days No Adobe Commerce 2.4.4-p15 and earlier, Magento Open Source CVE-2025-54236 is a critical improper input validation vulnerability in Adobe Commerce (Magento) that enables session takeover and potentially remote code execution without user interaction. This vulnerability is being actively exploited in the wild against internet-facing e-commerce platforms.
CVE-2025-48543KEV 2025-09-04 2025-09-04 T1068 Exploitation for Privilege Escalation 8.8 0 days No Android This is a local privilege escalation vulnerability in Android's Chrome sandbox that allows escaping to attack the system_server. While it has high impact and is actively exploited, it requires local access to the device and does not affect internet-facing services.
CVE-2025-53690KEV 2025-09-04 2025-09-03 T1190 Exploit Public-Facing Application 9.0 1 day No Sitecore Experience Manager to, Sitecore Experience Platform to Critical ViewState deserialization vulnerability in Sitecore Experience Manager/Platform allowing remote code execution. Actively exploited in the wild since December 2024, affecting internet-facing Sitecore deployments using default sample machine keys.
CVE-2025-9377KEV 2025-09-03 2025-08-29 T1190 Exploit Public-Facing Application 8.6 5 days No TP-Link Systems Inc. Archer C7 V2, TP-Link Systems Inc. TL-WR841N/ND V9 CVE-2025-9377 is an authenticated remote command execution vulnerability in TP-Link router web interfaces that allows network-based exploitation of internet-facing devices. CISA has confirmed active exploitation and added it to the KEV catalog.
CVE-2025-55177KEV 2025-09-02 2025-08-29 T1203 Exploitation for Client Execution 5.4 4 days No WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS CVE-2025-55177 affects WhatsApp client applications on iOS and macOS, allowing unauthorized processing of content from arbitrary URLs through crafted synchronization messages. While it has network attack vector and active exploitation evidence, it targets client applications rather than internet-facing servers.
CVE-2025-57819KEV 2025-08-29 2025-08-28 T1190 Exploit Public-Facing Application 10.0 1 day No FreePBX security-reporting < FreePBX security-reporting module contains an authentication bypass vulnerability leading to SQL injection and RCE. This web-based PBX management interface is commonly exposed to the internet for remote administration and has been actively exploited since August 2025.
CVE-2025-7775KEV 2025-08-26 2025-08-26 T1190 Exploit Public-Facing Application 9.2 0 days No NetScaler ADC, NetScaler Gateway Critical memory overflow vulnerability in NetScaler ADC and Gateway allowing unauthenticated remote code execution. Active zero-day exploitation confirmed against internet-facing appliances with CISA KEV listing.
CVE-2025-43300KEV 2025-08-21 2025-08-21 T1203 Exploitation for Client Execution 8.8 0 days No Apple macOS, Apple iOS and iPadOS, Apple iPadOS CVE-2025-43300 is an out-of-bounds write vulnerability in Apple's Image I/O framework affecting macOS, iOS, and iPadOS that requires user interaction to process a malicious image file. While actively exploited as a zero-day, it primarily affects client-side operating systems rather than internet-facing server applications.
CVE-2025-8875KEV 2025-08-13 2025-08-14 T1190 Exploit Public-Facing Application 9.4 -1 days No N-able N-central Critical deserialization vulnerability in N-able N-central allows remote code execution with low privileges over network. This is actively exploited according to CISA KEV listing. N-central is commonly deployed as an internet-facing server for MSP remote management services.
CVE-2025-8876KEV 2025-08-13 2025-08-14 T1190 Exploit Public-Facing Application 9.4 -1 days No N-able N-central before version CVE-2025-8876 is a critical OS command injection vulnerability in N-able N-central RMM platform that allows authenticated attackers to execute arbitrary commands. CISA has confirmed active exploitation in the wild, and the vulnerability affects internet-facing management platforms used by MSPs.
CVE-2025-8088KEV 2025-08-12 2025-08-08 T1203 Exploitation for Client Execution 8.4 4 days No win.rar GmbH WinRAR CVE-2025-8088 is a path traversal vulnerability in WinRAR that allows arbitrary code execution through malicious archive files. This requires user interaction to open/extract crafted archives and is not directly exploitable over the internet against public-facing services.
CVE-2025-54253KEV 2025-10-15 2025-08-05 T1190 Exploit Public-Facing Application 10.0 71 days No Adobe Experience Manager Forms on JEE versions 6.5.23 and earlier Critical misconfiguration vulnerability in Adobe Experience Manager Forms on JEE allowing pre-authentication remote code execution via OGNL injection. The vulnerability requires no user interaction and can be exploited directly over the network against internet-facing AEM instances.
CVE-2025-54948KEV 2025-08-18 2025-08-05 T1190 Exploit Public-Facing Application 9.4 13 days No Trend Micro Apex One 2019 versions < CVE-2025-54948 is a critical OS command injection vulnerability in Trend Micro Apex One on-premise management console that allows pre-authenticated remote attackers to upload malicious code and execute arbitrary commands. CISA has added this vulnerability to the KEV catalog due to active exploitation in the wild.
CVE-2025-6205KEV 2025-10-28 2025-08-04 T1190 Exploit Public-Facing Application 9.1 85 days No DELMIA Apriso Critical missing authorization vulnerability in DELMIA Apriso manufacturing execution system allows unauthenticated attackers to gain privileged access over the network. CISA coordinator notes active exploitation is occurring in the wild.
CVE-2025-6204KEV 2025-10-28 2025-08-04 T1190 Exploit Public-Facing Application 8.0 85 days No Dassault DELMIA Apriso Code injection vulnerability in Dassault Systèmes DELMIA Apriso manufacturing operations management platform allows arbitrary code execution. Requires high privileges but exploitable over network without user interaction.
CVE-2025-31277KEV 2026-03-20 2025-07-29 T1203 Exploitation for Client Execution 8.8 234 days No Safari, iOS, iPadOS (+4 more) Memory corruption vulnerability in Apple WebKit affecting Safari and other Apple client devices when processing malicious web content. This is a client-side vulnerability requiring user interaction to visit a malicious website, not exploitation of internet-facing servers.
CVE-2025-38352KEV 2025-09-04 2025-07-22 T1068 Exploitation for Privilege Escalation 7.4 44 days No Linux Kernel CVE-2025-38352 is a race condition vulnerability in the Linux kernel's POSIX CPU timer subsystem that affects timer handling during process exit. This is a local privilege escalation vulnerability requiring existing system access to exploit, despite being actively exploited according to CISA KEV listing.
CVE-2025-53770KEV 2025-07-20 2025-07-20 T1190 Exploit Public-Facing Application 9.8 0 days Yes (+209d) Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, Microsoft SharePoint Server Subscription Edition Critical deserialization vulnerability in on-premises SharePoint Server allowing unauthenticated remote code execution over the network. Actively exploited in the wild with public exploits available.
CVE-2025-54313KEV 2026-01-22 2025-07-19 T1195 Supply Chain Compromise 7.5 187 days No eslint-config-prettier, Node.js development environments eslint-config-prettier package was compromised with embedded malicious code that executes during installation. This is a supply chain attack that affects development environments rather than production internet-facing servers.
CVE-2025-54309KEV 2025-07-22 2025-07-18 T1190 Exploit Public-Facing Application 9.0 4 days No CrushFTP CrushFTP versions 10 before, CrushFTP CrushFTP versions 11 before 11.3.4_23 Critical vulnerability in CrushFTP file transfer server allows remote attackers to obtain admin access via HTTPS through mishandled AS2 validation. Actively exploited in the wild with large numbers of internet-facing instances vulnerable.
CVE-2025-54068KEV 2026-03-20 2025-07-17 T1190 Exploit Public-Facing Application 9.2 246 days No Livewire for Laravel, Laravel Web Applications using Livewire Livewire v3 contains a critical remote command execution vulnerability during property update hydration that requires no authentication or user interaction. The vulnerability allows unauthenticated attackers to achieve RCE against web applications built with this Laravel framework component.
CVE-2025-25257KEV 2025-07-18 2025-07-17 T1190 Exploit Public-Facing Application 9.6 1 day No Fortinet FortiWeb, FortiWeb Critical SQL injection vulnerability in Fortinet FortiWeb WAF allowing unauthenticated attackers to execute arbitrary SQL and code via crafted HTTP/HTTPS requests. CISA has confirmed active exploitation in the wild with public PoC available.
CVE-2025-20337KEV 2025-07-28 2025-07-16 T1190 Exploit Public-Facing Application 10.0 12 days No Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector Critical unauthenticated remote code execution vulnerability in Cisco ISE API that allows attackers to execute arbitrary code as root. The vulnerability is actively exploited in the wild and requires no authentication or user interaction.
CVE-2025-6558KEV 2025-07-22 2025-07-15 T1189 Drive-by Compromise 8.8 7 days No Google Chrome CVE-2025-6558 is a Google Chrome vulnerability allowing sandbox escape via crafted HTML pages. While actively exploited and on CISA KEV, it requires user interaction to visit malicious websites, making it unsuitable for T1190 direct network exploitation.
CVE-2025-47812KEV 2025-07-14 2025-07-10 T1190 Exploit Public-Facing Application 10.0 4 days No wftpserver Wing FTP Server versions before Critical RCE vulnerability in Wing FTP Server allowing arbitrary Lua code injection through null byte mishandling in web interfaces. Exploitable remotely without authentication, including via anonymous FTP accounts, leading to total server compromise.
CVE-2025-47813KEV 2026-03-16 2025-07-10 T1082 System Information Discovery 4.3 249 days No Wing FTP Server CVE-2025-47813 is an information disclosure vulnerability in Wing FTP Server that reveals the full local installation path through error messages when a long UID cookie value is used. While Wing FTP Server is commonly deployed as internet-facing infrastructure, this vulnerability only leaks path information and does not provide direct system compromise capabilities.
CVE-2025-48384KEV 2025-08-25 2025-07-08 T1204 User Execution 8.1 48 days No git git Git vulnerability allowing arbitrary code execution through malicious repositories with crafted submodule paths. Requires user interaction (git clone --recursive) and primarily affects client-side Git operations rather than internet-facing server applications.
CVE-2025-49706KEV 2025-07-22 2025-07-08 T1190 Exploit Public-Facing Application 6.5 14 days Yes (+207d) Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, Microsoft SharePoint Server Subscription Edition CVE-2025-49706 is an improper authentication vulnerability in Microsoft SharePoint Server that allows network-based spoofing attacks without authentication. The vulnerability is actively exploited in the wild and enables attackers to bypass authentication by manipulating HTTP headers.
CVE-2025-49704KEV 2025-07-22 2025-07-08 T1190 Exploit Public-Facing Application 8.8 14 days Yes (+207d) Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server CVE-2025-49704 is a critical code injection vulnerability in Microsoft SharePoint that allows remote code execution over the network with only low-privilege authentication required. SharePoint servers are commonly deployed as internet-facing enterprise applications, making this vulnerability highly exploitable via T1190.
CVE-2025-6554KEV 2025-07-02 2025-06-30 T1189 Drive-by Compromise 8.1 2 days No Google Chrome CVE-2025-6554 is a type confusion vulnerability in Google Chrome's V8 JavaScript engine that allows arbitrary read/write via crafted HTML pages. While actively exploited and on CISA KEV, it requires user interaction and affects client-side browser software, not internet-facing server applications.
CVE-2025-32463KEV 2025-09-29 2025-06-30 T1068 Exploitation for Privilege Escalation 9.3 91 days No Sudo CVE-2025-32463 is a local privilege escalation vulnerability in Sudo that allows local users to gain root access via the --chroot option. While Sudo is ubiquitous on Linux systems, this is a LOCAL attack vector requiring existing user access to the system.
CVE-2025-20281KEV 2025-07-28 2025-06-25 T1190 Exploit Public-Facing Application 10.0 33 days No Cisco Identity Services Engine Software Critical unauthenticated remote code execution vulnerability in Cisco ISE API that allows attackers to execute arbitrary code as root via crafted API requests. Actively exploited in the wild with CVSS 10.0 severity.
CVE-2025-6543KEV 2025-06-30 2025-06-25 T1190 Exploit Public-Facing Application 9.2 5 days No NetScaler ADC, NetScaler Gateway Critical memory overflow vulnerability in NetScaler ADC and Gateway that allows remote network exploitation leading to denial of service and potential code execution. The vulnerability is actively exploited in the wild as a zero-day since May 2025.
CVE-2025-32975KEV 2026-04-20 2025-06-24 T1190 Exploit Public-Facing Application 10.0 300 days No Quest KACE SMA 13.0.x through 14.1.x Quest KACE Systems Management Appliance contains an authentication bypass vulnerability allowing attackers to impersonate legitimate users and gain complete administrative control without valid credentials. This is a critical CVSS 10.0 vulnerability with active exploitation confirmed by CISA KEV listing.
CVE-2025-48700KEV 2026-04-20 2025-06-23 T1203 Exploitation for Client Execution 6.1 301 days No Zimbra Collaboration Suite CVE-2025-48700 is a Cross-Site Scripting (XSS) vulnerability in Zimbra Collaboration Suite that executes JavaScript in users' email sessions when viewing crafted emails. While Zimbra is widely deployed as an internet-facing email server, this XSS vulnerability compromises user sessions rather than the server itself, making it unsuitable for T1190 direct server exploitation.
CVE-2025-6218KEV 2025-12-09 2025-06-21 T1203 Exploitation for Client Execution 7.8 171 days No WinRAR CVE-2025-6218 is a directory traversal vulnerability in RARLAB WinRAR that allows remote code execution when a user opens a malicious archive file. Despite being on CISA KEV, this is a client-side vulnerability requiring user interaction and does not affect internet-facing services.
CVE-2025-5777KEV 2025-07-10 2025-06-17 T1190 Exploit Public-Facing Application 9.3 23 days Yes (+219d) NetScaler ADC, NetScaler Gateway Critical memory overread vulnerability in NetScaler ADC/Gateway allowing unauthenticated remote attackers to read sensitive memory contents including session tokens. Actively exploited in the wild with CISA KEV listing.
CVE-2025-43200KEV 2025-06-16 2025-06-16 T1203 Exploitation for Client Execution 4.8 0 days No Apple iOS and iPadOS, Apple macOS, Apple iPadOS (+2 more) CVE-2025-43200 is a logic issue in Apple client operating systems (iOS, macOS, iPadOS, watchOS, visionOS) that processes malicious media shared via iCloud Links. While it has network attack vector and is actively exploited, it targets client devices rather than internet-facing server applications.
CVE-2025-33073KEV 2025-10-20 2025-06-10 T1557 Adversary-in-the-Middle 8.8 132 days No Windows, Windows Server 2008 SP2, Windows Server 2008 R2 SP1 (+2 more) CVE-2025-33073 is an SMB client elevation of privilege vulnerability that allows authenticated attackers to perform NTLM reflection attacks. While it has a network attack vector, it targets SMB client functionality rather than internet-facing server services, making direct internet exploitation unlikely.
CVE-2025-33053KEV 2025-06-10 2025-06-10 T1204 User Execution 8.8 0 days No Microsoft Windows 10 Version, Microsoft Windows Server, Microsoft Windows 10 Version 21H2 (+1 more) CVE-2025-33053 is a remote code execution vulnerability in Windows Internet Shortcut Files that requires user interaction (clicking malicious WebDAV links). While it has CVSS attack vector NETWORK, it primarily relies on spearphishing rather than direct exploitation of internet-facing services.
CVE-2025-47827KEV 2025-10-14 2025-06-05 T1543 Create or Modify System Process 4.6 131 days No IGEL OS IGEL OS Secure Boot bypass vulnerability that requires physical access to mount crafted root filesystem from unverified SquashFS image. This is a local boot-time security control bypass, not a network-exploitable vulnerability.
CVE-2025-21479KEV 2025-06-03 2025-06-03 T1068 Exploitation for Privilege Escalation 8.6 0 days No Snapdragon Mobile Platforms, FastConnect WiFi Chips, Snapdragon Compute Platforms (+4 more) CVE-2025-21479 is a memory corruption vulnerability in Snapdragon GPU components that requires local access and user interaction. Despite being in CISA KEV, it affects mobile/client chipsets rather than internet-facing servers.
CVE-2025-27038KEV 2025-06-03 2025-06-03 T1203 Exploitation for Client Execution 7.5 0 days No Snapdragon Mobile Platforms, Snapdragon Industrial IoT, Snapdragon Consumer IoT (+3 more) Use-after-free vulnerability in Qualcomm Adreno GPU drivers when rendering graphics in Chrome. This affects mobile devices, wearables, and IoT platforms rather than internet-facing servers. Exploitation requires user interaction to view malicious content.
CVE-2025-21480KEV 2025-06-03 2025-06-03 T1068 Exploitation for Privilege Escalation 8.6 0 days No Snapdragon Mobile Platforms, Snapdragon Compute Platforms, Snapdragon Industrial IoT (+4 more) Memory corruption vulnerability in Qualcomm Snapdragon GPU micronode allowing unauthorized command execution. Despite being in CISA KEV, this is a local privilege escalation requiring user interaction on mobile/IoT devices, not an internet-facing server vulnerability.
CVE-2025-5419KEV 2025-06-05 2025-06-02 T1203 Exploitation for Client Execution 8.8 3 days No Chrome CVE-2025-5419 is an out-of-bounds read/write vulnerability in Chrome's V8 engine that allows remote code execution via crafted HTML pages. While severe for client security, this is a browser vulnerability requiring user interaction and does not qualify as T1190 since Chrome is client software, not a public-facing server application.
CVE-2025-5086KEV 2025-09-11 2025-06-02 T1190 Exploit Public-Facing Application 9.0 101 days No DELMIA Apriso Release Critical deserialization vulnerability in DELMIA Apriso manufacturing execution system allowing remote code execution without authentication. Active exploitation observed in the wild targeting internet-facing instances.
CVE-2025-49113KEV 2026-02-20 2025-06-02 T1190 Exploit Public-Facing Application 9.9 263 days No Roundcube Webmail Critical RCE vulnerability in Roundcube Webmail allowing authenticated users to achieve remote code execution via PHP object deserialization. This is actively exploited in the wild and affects internet-facing webmail servers globally.
CVE-2025-48927KEV 2025-07-01 2025-05-28 T1190 Exploit Public-Facing Application 5.3 34 days No TeleMessage service TeleMessage service exposes an unauthenticated Spring Boot Actuator /heapdump endpoint that allows attackers to extract sensitive credentials remotely. This vulnerability is actively exploited in the wild and affects internet-facing enterprise messaging systems.
CVE-2025-48928KEV 2025-07-01 2025-05-28 T1005 Data from Local System 4.0 34 days No TeleMessage TeleMessage service exposes heap content similar to a core dump containing previously transmitted passwords. This is classified as CWE-528 (exposure of core dump file) with local attack vector, indicating the vulnerability requires local system access rather than direct internet exploitation.
CVE-2025-34026KEV 2026-01-22 2025-05-21 T1190 Exploit Public-Facing Application 9.2 246 days No Versa Concerto SD-WAN orchestration platform Versa Concerto SD-WAN orchestration platform contains an authentication bypass vulnerability in the Traefik reverse proxy configuration, allowing attackers to access administrative endpoints and internal Actuator endpoints. This vulnerability provides direct network-based access to heap dumps and trace logs containing sensitive information.
CVE-2025-4008KEV 2025-10-02 2025-05-21 T1190 Exploit Public-Facing Application 8.7 134 days No Smartbedded MeteoBridge v6.1 and earlier Remote command injection vulnerability in Smartbedded MeteoBridge weather station management systems allows unauthenticated attackers to execute arbitrary commands with root privileges. Despite CVSS rating as ADJACENT network, many MeteoBridge systems are deployed as internet-facing weather monitoring stations.
CVE-2025-30397KEV 2025-05-13 2025-05-13 T1203 Exploitation for Client Execution 7.5 0 days No Windows, Windows Server CVE-2025-30397 is a type confusion vulnerability in Microsoft's scripting engine affecting Windows client and server operating systems. Despite being in CISA KEV, this requires user interaction (UI:R in CVSS) and primarily targets client-side script execution rather than internet-facing server services.
CVE-2025-32709KEV 2025-05-13 2025-05-13 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server 2008/2008 R2/2012/2012 R2/2016/2019/2022/2025, Windows CVE-2025-32709 is a local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock affecting all major Windows versions. While the affected products include Windows Server editions that can be internet-facing, this vulnerability requires local access and authorized user privileges to exploit, making it unsuitable for direct internet exploitation via T1190.
CVE-2025-32706KEV 2025-05-13 2025-05-13 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server 2008/2008 R2/2012/2012 R2/2016/2019/2022/2025, Windows CVE-2025-32706 is a local privilege escalation vulnerability in the Windows Common Log File System Driver that requires authenticated local access. Despite being in CISA KEV, this is not directly exploitable over the internet as it requires local access with authentication to escalate privileges.
CVE-2025-32701KEV 2025-05-13 2025-05-13 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows CVE-2025-32701 is a local privilege escalation vulnerability in the Windows Common Log File System Driver affecting all Windows versions. Despite being on CISA KEV due to active exploitation, this is a local-only vulnerability requiring existing access to the system to exploit.
CVE-2025-30400KEV 2025-05-13 2025-05-13 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows, Windows Server CVE-2025-30400 is a use-after-free vulnerability in Windows Desktop Window Manager (DWM) Core Library that allows local privilege escalation. Despite being on CISA KEV, this is a local-only vulnerability requiring existing system access and cannot be exploited directly over the internet.
CVE-2025-4428KEV 2025-05-19 2025-05-13 T1190 Exploit Public-Facing Application 7.2 6 days No Ivanti Endpoint Manager Mobile Remote Code Execution vulnerability in Ivanti Endpoint Manager Mobile API component that allows authenticated attackers to execute arbitrary code via crafted API requests. This vulnerability is actively exploited and listed in CISA KEV.
CVE-2025-4427KEV 2025-05-19 2025-05-13 T1190 Exploit Public-Facing Application 5.3 6 days No Ivanti Endpoint Manager Mobile CVE-2025-4427 is an authentication bypass vulnerability in the API component of Ivanti Endpoint Manager Mobile that allows unauthenticated attackers to access protected resources. This vulnerability is actively being exploited in the wild and is listed in CISA's KEV catalog.
CVE-2025-32756KEV 2025-05-14 2025-05-13 T1190 Exploit Public-Facing Application 9.6 1 day No FortiMail, FortiVoice, FortiNDR (+2 more) Critical stack-based buffer overflow vulnerability in multiple Fortinet server products that allows remote unauthenticated code execution via crafted HTTP requests. This vulnerability is actively exploited in the wild and affects enterprise-grade security and communications infrastructure commonly exposed to the internet.
CVE-2025-4632KEV 2025-05-22 2025-05-13 T1190 Exploit Public-Facing Application 9.8 9 days No Samsung MagicINFO 9 Server Critical path traversal vulnerability in Samsung MagicINFO 9 Server allows unauthenticated remote attackers to write arbitrary files with system authority. The vulnerability is actively exploited in the wild and listed in CISA KEV, with CAPEC-650 indicating web shell upload capability.
CVE-2025-42999KEV 2025-05-15 2025-05-13 T1190 Exploit Public-Facing Application 9.1 2 days No SAP NetWeaver Visual Composer Critical insecure deserialization vulnerability in SAP NetWeaver Visual Composer development server that allows privileged users to upload malicious content leading to complete system compromise. CISA KEV listing indicates active exploitation in the wild.
CVE-2025-47729KEV 2025-05-12 2025-05-08 T1005 Data from Local System 1.9 4 days No TeleMessage archiving backend TeleMessage archiving backend stores cleartext copies of encrypted messages, contrary to documentation claiming end-to-end encryption. This is a data exposure vulnerability rather than a traditional exploitable security flaw, requiring prior unauthorized access to the system.
CVE-2025-35939KEV 2025-06-02 2025-05-07 T1190 Exploit Public-Facing Application 5.3 26 days No Craft CMS Craft CMS allows unauthenticated attackers to write arbitrary content (including PHP code) to predictable session file locations on the server. This vulnerability enables potential remote code execution without authentication and is actively being exploited in the wild according to CISA KEV.
CVE-2025-2776KEV 2025-07-22 2025-05-07 T1190 Exploit Public-Facing Application 9.3 76 days No SysAid On-Prem versions <= CVE-2025-2776 is an unauthenticated XML External Entity (XXE) vulnerability in SysAid On-Prem that allows remote attackers to achieve administrator account takeover and file read access without any authentication. This vulnerability is actively being exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog.
CVE-2025-2775KEV 2025-07-22 2025-05-07 T1190 Exploit Public-Facing Application 9.3 76 days No SysAid SysAid On-Prem versions <= SysAid On-Prem is vulnerable to an unauthenticated XML External Entity (XXE) vulnerability allowing administrator account takeover and file read primitives. This is a server-side application typically deployed with internet-facing interfaces for IT support services.
CVE-2025-27920KEV 2025-05-19 2025-05-05 T1190 Exploit Public-Facing Application 7.2 14 days No Srimax Output Messenger Directory traversal vulnerability in Srimax Output Messenger allows remote attackers to access sensitive files outside intended directories. This vulnerability is actively exploited by APT group 'Marbled Dust' for regional espionage and is listed in CISA KEV catalog.
CVE-2025-3935KEV 2025-06-02 2025-04-25 T1190 Exploit Public-Facing Application 8.1 38 days No ConnectWise ScreenConnect ConnectWise ScreenConnect versions 25.2.3 and earlier are vulnerable to ViewState code injection leading to remote code execution. ScreenConnect is a remote access and support software typically deployed as an internet-facing web application for technicians to remotely access client systems.
CVE-2025-3928KEV 2025-04-28 2025-04-25 T1505 Server Software Component 8.8 3 days No Commvault Web Server Commvault Web Server contains an unspecified vulnerability that allows remote authenticated attackers to compromise web servers by creating and executing web shells. This vulnerability is actively exploited in the wild and is listed in the CISA KEV catalog.
CVE-2025-32432KEV 2026-03-20 2025-04-25 T1190 Exploit Public-Facing Application 10.0 329 days No Craft CMS 3.x, Craft CMS 4.x, Craft CMS 5.x Craft CMS contains a critical remote code execution vulnerability that requires no authentication or user interaction. With a CVSS score of 10.0 and inclusion in CISA's KEV catalog, this vulnerability is actively exploited in the wild against internet-facing CMS installations.
CVE-2025-31324KEV 2025-04-29 2025-04-24 T1190 Exploit Public-Facing Application 10.0 5 days Yes (+401d) SAP NetWeaver Visual Composer development server VCFRAMEWORK Critical file upload vulnerability in SAP NetWeaver Visual Composer development server allows unauthenticated attackers to upload malicious executables for remote code execution. The vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2025-1976KEV 2025-04-28 2025-04-24 T1068 Exploitation for Privilege Escalation 8.6 4 days No Brocade Fabric OS CVE-2025-1976 is a privilege escalation vulnerability in Brocade Fabric OS that allows local admin users to execute arbitrary code with root privileges. Despite being on CISA KEV, this requires adjacent network access and existing admin credentials, making direct internet exploitation unlikely.
CVE-2025-34028KEV 2025-05-02 2025-04-22 T1190 Exploit Public-Facing Application 9.3 10 days No Commvault Command Center Innovation Release 11.38.0 Critical unauthenticated remote code execution vulnerability in Commvault Command Center that allows attackers to upload malicious ZIP packages containing JSP files via path traversal. The vulnerability enables complete server compromise without authentication and is actively being exploited in the wild.
CVE-2025-42599KEV 2025-04-28 2025-04-18 T1190 Exploit Public-Facing Application 9.8 10 days No Active! mail Critical stack-based buffer overflow in Active! mail 6 email server allows remote unauthenticated code execution. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2025-32433KEV 2025-06-09 2025-04-16 T1190 Exploit Public-Facing Application 10.0 54 days No erlang otp CVE-2025-32433 is a critical pre-authentication remote code execution vulnerability in Erlang/OTP SSH servers with a CVSS score of 10.0. The vulnerability allows unauthenticated attackers to execute arbitrary commands by exploiting flaws in SSH protocol message handling, with active exploitation confirmed in the wild.
CVE-2025-31200KEV 2025-04-17 2025-04-16 T1203 Exploitation for Client Execution 7.1 1 day No iOS/iPadOS, macOS, Apple TV (+1 more) Memory corruption vulnerability in Apple's media processing affecting iOS, macOS, visionOS, and tvOS. Exploitation requires users to process maliciously crafted media files. Apple reports active exploitation in targeted attacks.
CVE-2025-31201KEV 2025-04-17 2025-04-16 T1203 Exploitation for Client Execution 7.5 1 day No iOS, iPadOS, macOS (+2 more) CVE-2025-31201 is a Pointer Authentication bypass vulnerability affecting Apple consumer devices (iOS, iPadOS, macOS, tvOS, visionOS). Despite being exploited in the wild and requiring network access, this affects client-side operating systems that are rarely exposed as internet-facing servers.
CVE-2024-58136KEV 2025-05-02 2025-04-10 T1190 Exploit Public-Facing Application 9.0 22 days No Yii 2 Framework Critical vulnerability in Yii 2 framework involving improper protection of behavior attachment mechanism. This is a regression of CVE-2024-4990 that allows remote code execution and has been actively exploited in the wild according to CISA KEV listing.
CVE-2025-29824KEV 2025-04-08 2025-04-08 T1068 Exploitation for Privilege Escalation 7.8 0 days Yes (+422d) Windows, Windows Server, Windows Server 2012/2012 R2 (+1 more) CVE-2025-29824 is a use-after-free vulnerability in the Windows Common Log File System Driver that allows local privilege escalation. Despite being listed in CISA KEV indicating active exploitation, this is a local vulnerability that requires existing access to a Windows system and cannot be directly exploited over the internet.
CVE-2025-3248KEV 2025-05-05 2025-04-07 T1190 Exploit Public-Facing Application 9.8 28 days No Langflow AI Langflow is an AI workflow platform that allows remote code execution through an unauthenticated API endpoint. This vulnerability enables direct server compromise via crafted HTTP requests to /api/v1/validate/code.
CVE-2025-22457KEV 2025-04-04 2025-04-03 T1133 External Remote Services 9.0 1 day Yes (+426d) Ivanti Connect Secure, Ivanti Policy Secure, Ivanti Neurons for ZTA Critical stack-based buffer overflow in Ivanti remote access gateways allows unauthenticated remote code execution. These products are specifically designed to be internet-facing to provide secure remote access to corporate networks.
CVE-2025-30406KEV 2025-04-08 2025-04-03 T1190 Exploit Public-Facing Application 9.0 5 days No Gladinet CentreStack Critical deserialization vulnerability in Gladinet CentreStack due to hardcoded machineKey, enabling remote code execution on the server. This vulnerability is actively exploited in the wild and listed in CISA KEV.
CVE-2025-31161KEV 2025-04-07 2025-04-03 T1190 Exploit Public-Facing Application 9.8 4 days Yes (+423d) CrushFTP versions 10.x before, CrushFTP versions 11.x before Critical authentication bypass vulnerability in CrushFTP server allows attackers to takeover admin accounts via malformed AWS4-HMAC headers. The vulnerability has been actively exploited in the wild and is listed in CISA KEV.
CVE-2025-31125KEV 2026-01-22 2025-03-31 T1190 Exploit Public-Facing Application 5.3 297 days No Vite Development Server Vite development server vulnerability allows bypass of filesystem restrictions to expose sensitive files via crafted URLs with ?inline&import or ?raw&import parameters. Only affects Vite dev servers explicitly exposed to the network using --host configuration.
CVE-2025-2783KEV 2025-03-27 2025-03-26 T1203 Exploitation for Client Execution 8.3 1 day No Chrome This is a sandbox escape vulnerability in Google Chrome requiring a malicious file to be opened by a user. While it has a high CVSS score and is in CISA KEV, it affects a client application (browser) rather than a server application, making it unsuitable for direct internet exploitation via T1190.
CVE-2025-29635KEV 2026-04-24 2025-03-25 T1190 Exploit Public-Facing Application 7.2 395 days No D-Link DIR-823X Router Command injection vulnerability in D-Link DIR-823X routers allows authorized attackers to execute arbitrary commands via POST request to /goform/set_prohibiting. This vulnerability is actively exploited in Mirai botnet campaigns and is listed on CISA KEV.
CVE-2025-2749KEV 2026-04-20 2025-03-24 T1190 Exploit Public-Facing Application 7.2 392 days No Kentico Xperience CMS Authenticated remote code execution vulnerability in Kentico Xperience CMS allowing file upload via path traversal. Attackers can upload web shells to achieve server-side code execution. Listed in CISA KEV indicating active exploitation.
CVE-2025-2747KEV 2025-10-20 2025-03-24 T1190 Exploit Public-Facing Application 9.8 210 days No Kentico Xperience CMS Critical authentication bypass vulnerability in Kentico Xperience CMS allows complete bypass of authentication via Staging Sync Server component. The vulnerability gives attackers control over administrative objects and is actively being exploited in the wild according to CISA KEV listing.
CVE-2025-2746KEV 2025-10-20 2025-03-24 T1190 Exploit Public-Facing Application 9.8 210 days No Kentico Xperience CMS Authentication bypass vulnerability in Kentico Xperience CMS allows attackers to control administrative objects via empty SHA1 username handling in digest authentication. The vulnerability is actively exploited and affects internet-facing CMS deployments.
CVE-2025-30154KEV 2025-03-24 2025-03-19 T1195 Supply Chain Compromise 8.6 5 days No Reviewdog GitHub Actions, GitHub Actions CI/CD pipelines Multiple Reviewdog GitHub Actions were compromised with malicious code that dumped exposed secrets to workflow logs during a specific timeframe (March 11, 2025). This is a supply chain attack against CI/CD pipeline tools, not a direct internet-facing application vulnerability.
CVE-2025-30066KEV 2025-03-18 2025-03-15 T1195 Supply Chain Compromise 8.6 3 days No tj-actions changed-files, GitHub Actions workflows using affected versions A supply chain attack compromised the tj-actions changed-files GitHub Action where threat actors modified tags v1-v45.0.7 to point to malicious code that exfiltrates secrets from GitHub Actions workflows. This is not a direct server exploitation but rather a software supply chain compromise affecting CI/CD pipelines.
CVE-2025-21590KEV 2025-03-13 2025-03-12 T1068 Exploitation for Privilege Escalation 4.4 1 day No Juniper Junos OS CVE-2025-21590 is a local privilege escalation vulnerability in Juniper Junos OS that requires high privileges and shell access to exploit. Despite being in CISA KEV due to active exploitation, it cannot be directly exploited from the internet as it requires LOCAL attack vector and existing high-privilege access to the device shell.
CVE-2025-27915KEV 2025-10-07 2025-03-12 T1203 Exploitation for Client Execution 5.4 209 days No Zimbra Collaboration Server This is a stored XSS vulnerability in Zimbra Collaboration Server that requires a user to view a malicious email containing a crafted ICS calendar file. Despite being in CISA KEV, this is not a direct server compromise but rather a client-side attack targeting user sessions.
CVE-2025-24201KEV 2025-03-13 2025-03-11 T1203 Exploitation for Client Execution 10.0 2 days No Safari, iOS and iPadOS, macOS (+2 more) An out-of-bounds write vulnerability in Apple's WebKit engine allows maliciously crafted web content to break out of the Web Content sandbox. This affects client devices (iOS, macOS, Safari) when users visit malicious websites, not internet-facing servers.
CVE-2025-26633KEV 2025-03-11 2025-03-11 T1068 Exploitation for Privilege Escalation 7.0 0 days Yes (+450d) Windows Server, Windows Server 2012 R2, Windows Server 2008 R2 (+1 more) This is a local security feature bypass vulnerability in Microsoft Management Console (MMC) that allows attackers to bypass security features locally. The vulnerability requires local access and user interaction, making it unsuitable for direct internet exploitation.
CVE-2025-24993KEV 2025-03-11 2025-03-11 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows, Windows Server, Windows Server 2008 R2 (+1 more) CVE-2025-24993 is a heap-based buffer overflow in Windows NTFS that allows local code execution with user interaction required. Despite being on CISA KEV, this is a LOCAL vulnerability (CVSS AV:L/UI:R) affecting the NTFS file system, not internet-facing services.
CVE-2025-24991KEV 2025-03-11 2025-03-11 T1068 Exploitation for Privilege Escalation 5.5 0 days No Windows, Windows Server CVE-2025-24991 is an out-of-bounds read vulnerability in Windows NTFS that allows local information disclosure. Despite being on CISA KEV, this is a local vulnerability requiring existing system access and user interaction, not directly exploitable over the internet.
CVE-2025-24985KEV 2025-03-11 2025-03-11 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows Server 2012/2012 R2, Windows Server 2008/2008 R2 (+1 more) CVE-2025-24985 is an integer overflow vulnerability in the Windows Fast FAT File System Driver that allows local code execution. The vulnerability requires local access and user interaction (mounting/accessing malicious FAT file systems), making it unsuitable for direct internet exploitation despite being in CISA KEV.
CVE-2025-24984KEV 2025-03-11 2025-03-11 T1005 Data from Local System 4.6 0 days No Windows Server 2012/2012 R2, Windows Server, Windows Windows NTFS information disclosure vulnerability that allows unauthorized attackers to access sensitive information from log files through physical access to affected systems. Despite being in CISA KEV, this requires physical access and cannot be exploited remotely over the internet.
CVE-2025-24983KEV 2025-03-11 2025-03-11 T1068 Exploitation for Privilege Escalation 7.0 0 days No Windows Server 2008 SP2, Windows Server, Windows Server 2012 R2 (+1 more) CVE-2025-24983 is a local privilege escalation vulnerability in the Windows Win32 Kernel Subsystem affecting older Windows versions. The CVSS attack vector is LOCAL (AV:L), requiring an authorized attacker with existing system access to exploit a use-after-free condition for privilege escalation.
CVE-2025-24054KEV 2025-04-17 2025-03-11 T1557 Adversary-in-the-Middle 6.5 37 days No Windows Server 2008 R2, Windows Server 2012/2012 R2, Windows Server (+1 more) CVE-2025-24054 is an NTLM hash disclosure spoofing vulnerability affecting Windows operating systems that allows attackers to perform spoofing attacks over a network. The vulnerability enables credential theft and man-in-the-middle attacks against NTLM authentication, particularly affecting Windows Server deployments that are commonly internet-facing.
CVE-2024-54085KEV 2025-06-25 2025-03-11 T1190 Exploit Public-Facing Application 10.0 106 days No AMI MegaRAC-SPx versions 12.0 to <12.7 and 13.0 to <13.5 Critical authentication bypass vulnerability in AMI MegaRAC BMC software affecting server management interfaces. Allows remote unauthenticated attackers to bypass authentication through the Redfish Host Interface with no user interaction required.
CVE-2025-27363KEV 2025-05-06 2025-03-11 T1203 Exploitation for Client Execution 8.1 56 days No FreeType, Android, Linux distributions (+1 more) CVE-2025-27363 is an out-of-bounds write vulnerability in FreeType versions 2.13.0 and below that allows arbitrary code execution when parsing malicious TrueType font files. While highly severe and actively exploited in the wild, this primarily affects client applications that process fonts rather than internet-facing servers.
CVE-2025-24813KEV 2025-04-01 2025-03-10 T1190 Exploit Public-Facing Application 10.0 22 days No Apache Tomcat Apache Tomcat path traversal vulnerability enabling remote code execution and information disclosure via malicious PUT requests. Affects millions of internet-facing web applications globally. Listed in CISA KEV with active exploitation evidence and public POCs available.
CVE-2025-1316KEV 2025-03-19 2025-03-04 T1190 Exploit Public-Facing Application 9.8 15 days No Edimax IC-7100 IP Camera Critical OS command injection vulnerability in Edimax IC-7100 IP cameras allows unauthenticated remote code execution via specially crafted network requests. The vulnerability has been added to CISA KEV indicating active exploitation in the wild.
CVE-2025-22226KEV 2025-03-04 2025-03-04 T1068 Exploitation for Privilege Escalation 7.1 0 days No VMware ESXi, VMware Workstation, VMware Fusion (+2 more) CVE-2025-22226 is an information disclosure vulnerability in VMware virtualization products affecting HGFS (Host-Guest File System). Despite being in CISA KEV, this is a local vulnerability requiring administrative access to a virtual machine to leak memory from the vmx process, not directly exploitable over the internet.
CVE-2025-22225KEV 2025-03-04 2025-03-04 T1068 Exploitation for Privilege Escalation 8.2 0 days Yes (+457d) VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform (+1 more) VMware ESXi contains an arbitrary write vulnerability allowing sandbox escape from the VMX process to kernel level. This is a local privilege escalation vulnerability requiring existing privileged access within the VMX process, not directly exploitable over the internet.
CVE-2025-22224KEV 2025-03-04 2025-03-04 T1068 Exploitation for Privilege Escalation 9.3 0 days No VMware ESXi, VMware Workstation, VMware Cloud Foundation (+2 more) CVE-2025-22224 is a critical TOCTOU vulnerability in VMware virtualization products that allows VM escape from guest to host. Despite being in CISA KEV, this requires local administrative privileges within a VM and primarily affects infrastructure software not typically exposed to the internet.
CVE-2024-48248KEV 2025-03-19 2025-03-04 T1190 Exploit Public-Facing Application 8.6 15 days No NAKIVO Backup & Replication Director NAKIVO Backup & Replication Director contains an absolute path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files and potentially achieve remote code execution. The vulnerability is actively being exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.
CVE-2025-24893KEV 2025-10-30 2025-02-20 T1190 Exploit Public-Facing Application 9.8 252 days No XWiki Platform XWiki Platform contains a critical remote code execution vulnerability (CVE-2025-24893) that allows unauthenticated attackers to execute arbitrary code via the SolrSearch endpoint. This vulnerability affects a widely-deployed enterprise wiki platform that is commonly internet-facing and has been added to CISA's Known Exploited Vulnerabilities catalog.
CVE-2025-24989KEV 2025-02-21 2025-02-19 T1190 Exploit Public-Facing Application 8.2 2 days No Microsoft Power Pages Microsoft Power Pages contains an improper access control vulnerability that allows unauthorized attackers to elevate privileges over a network, potentially bypassing user registration controls. This vulnerability is actively exploited in the wild and affects a cloud-based web application platform that is inherently internet-facing.
CVE-2025-0111KEV 2025-02-20 2025-02-12 T1190 Exploit Public-Facing Application 7.1 8 days No PAN-OS Firewalls, Palo Alto Networks NGFW, Palo Alto Networks PA-Series CVE-2025-0111 is an authenticated file read vulnerability in Palo Alto Networks PAN-OS management web interface that allows attackers to read files on the filesystem. This vulnerability is being actively exploited in the wild and is part of CISA's Known Exploited Vulnerabilities catalog.
CVE-2025-0108KEV 2025-02-18 2025-02-12 T1190 Exploit Public-Facing Application 8.8 6 days No Palo Alto PAN-OS Firewalls, Palo Alto Cloud NGFW, Palo Alto Prisma Access Authentication bypass vulnerability in Palo Alto Networks PAN-OS management web interface allows unauthenticated attackers to bypass authentication and invoke PHP scripts that can compromise firewall integrity and confidentiality. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2025-21418KEV 2025-02-11 2025-02-11 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows CVE-2025-21418 is a heap-based buffer overflow in the Windows Ancillary Function Driver for WinSock that allows local privilege escalation. Despite affecting both Windows client and server systems, this is fundamentally a local vulnerability requiring existing system access to exploit.
CVE-2025-21391KEV 2025-02-11 2025-02-11 T1068 Exploitation for Privilege Escalation 7.1 0 days No Windows Server, Windows CVE-2025-21391 is a Windows Storage elevation of privilege vulnerability affecting multiple Windows versions and Windows Server editions. Despite being in CISA KEV, this is a local privilege escalation vulnerability requiring prior system access, not a direct internet-exploitable flaw.
CVE-2025-24472KEV 2025-03-18 2025-02-11 T1190 Exploit Public-Facing Application 8.1 35 days Yes (+443d) Fortinet FortiOS, Fortinet FortiProxy Authentication bypass vulnerability in Fortinet FortiOS and FortiProxy allows remote unauthenticated attackers to gain super-admin privileges via crafted CSF proxy requests when Security Fabric is enabled. This is actively exploited and listed in CISA KEV.
CVE-2025-24016KEV 2025-06-10 2025-02-10 T1190 Exploit Public-Facing Application 9.9 120 days No Wazuh Security Platform Critical unsafe deserialization vulnerability in Wazuh security platform allows remote code execution through the DistributedAPI. Attackers with API access can inject malicious dictionaries to execute arbitrary Python code on Wazuh servers.
CVE-2025-24200KEV 2025-02-12 2025-02-10 T1200 Hardware Additions 6.1 2 days No iOS, iPadOS CVE-2025-24200 is a physical access vulnerability in iOS/iPadOS that allows disabling USB Restricted Mode on locked devices. This requires direct physical access to the device and cannot be exploited over the internet.
CVE-2025-0994KEV 2025-02-07 2025-02-06 T1190 Exploit Public-Facing Application 8.6 1 day No Trimble Cityworks Trimble Cityworks contains a deserialization vulnerability allowing authenticated remote code execution against IIS web servers. CISA reports active exploitation of this vulnerability in the wild.
CVE-2024-40891KEV 2025-02-11 2025-02-04 T1190 Exploit Public-Facing Application 8.8 7 days No Zyxel VMG4325-B10A DSL Modem Post-authentication command injection vulnerability in Zyxel VMG4325-B10A DSL modem allows authenticated attackers to execute OS commands via Telnet. This is a legacy, unsupported device that is actively exploited in the wild according to CISA KEV listing.
CVE-2024-40890KEV 2025-02-11 2025-02-04 T1190 Exploit Public-Facing Application 8.8 7 days No Zyxel VMG4325-B10A DSL Router Command injection vulnerability in Zyxel VMG4325-B10A DSL router allows authenticated attackers to execute OS commands via crafted HTTP POST requests. This legacy CPE device is commonly internet-facing and is listed in CISA KEV indicating active exploitation.
CVE-2023-52163KEV 2025-12-22 2025-02-03 T1190 Exploit Public-Facing Application 8.8 322 days No Digiever DS-2105 Pro NVR, Digiever Network Video Recorder devices Command injection vulnerability in Digiever DS-2105 Pro NVR devices allows remote code execution via the time_tzsetup.cgi endpoint. This IoT surveillance device is commonly internet-facing for remote monitoring and is actively exploited in the wild.
CVE-2024-57968KEV 2025-03-10 2025-02-03 T1505 Server Software Component 9.9 35 days No Advantive VeraCore Advantive VeraCore contains an unrestricted file upload vulnerability allowing authenticated remote attackers to upload malicious files to web-accessible directories. This vulnerability is actively exploited in the wild by the XE Group and listed in CISA KEV.
CVE-2025-25181KEV 2025-03-10 2025-02-03 T1190 Exploit Public-Facing Application 5.8 35 days No Advantive VeraCore SQL injection vulnerability in Advantive VeraCore's timeoutWarning.asp allows remote attackers to execute arbitrary SQL commands without authentication. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2025-24085KEV 2025-01-29 2025-01-27 T1068 Exploitation for Privilege Escalation 10.0 2 days No iOS, iPadOS, macOS (+3 more) CVE-2025-24085 is a use-after-free vulnerability in Apple operating systems that allows a malicious application to elevate privileges. While it has a CVSS score of 10.0 and is in CISA KEV, this is primarily a local privilege escalation vulnerability affecting client-side Apple devices, not internet-facing servers.
CVE-2025-0411KEV 2025-02-06 2025-01-25 T1204 User Execution 7.0 12 days No 7-Zip CVE-2025-0411 is a Mark-of-the-Web bypass vulnerability in 7-Zip that allows attackers to deliver malware without Windows security warnings. Despite being listed in CISA KEV, this is a client-side vulnerability requiring user interaction (opening a malicious archive) and does not affect internet-facing servers.
CVE-2025-23006KEV 2025-01-24 2025-01-23 T1190 Exploit Public-Facing Application 9.8 1 day Yes (+496d) SonicWall SMA1000 Critical pre-authentication deserialization vulnerability in SonicWall SMA1000 remote access appliances that allows unauthenticated remote attackers to execute arbitrary OS commands. This vulnerability is actively being exploited in the wild according to CISA KEV.
CVE-2025-23209KEV 2025-02-20 2025-01-18 T1190 Exploit Public-Facing Application 8.1 33 days No Craft CMS 4.x, Craft CMS 5.x Remote Code Execution vulnerability in Craft CMS when the security key is compromised. This vulnerability has been actively exploited in the wild and is listed in CISA KEV catalog.
CVE-2024-57726KEV 2026-04-24 2025-01-15 T1190 Exploit Public-Facing Application 9.9 464 days Yes (+41d) SimpleHelp Remote Support Software SimpleHelp remote support software v5.5.7 and earlier contains a privilege escalation vulnerability allowing low-privilege technicians to create API keys with excessive permissions, escalating to server admin role. This vulnerability is actively exploited in the wild and listed in CISA KEV.
CVE-2024-57727KEV 2025-02-13 2025-01-15 T1190 Exploit Public-Facing Application 9.1 29 days Yes (+476d) SimpleHelp Remote Support Software SimpleHelp remote support software v5.5.7 and earlier contains critical path traversal vulnerabilities allowing unauthenticated attackers to download arbitrary files including server configuration files and hashed passwords. This vulnerability is actively exploited and listed in CISA KEV.
CVE-2024-57728KEV 2026-04-24 2025-01-15 T1190 Exploit Public-Facing Application 7.2 464 days Yes (+41d) SimpleHelp Remote Support Software SimpleHelp remote support software v5.5.7 and earlier contains a zip slip vulnerability allowing admin users to upload arbitrary files anywhere on the file system and execute code. This remote support software is commonly deployed as internet-facing infrastructure for IT support organizations.
CVE-2025-21334KEV 2025-01-14 2025-01-14 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows Server 2022 23H2, Windows CVE-2025-21334 is a local privilege escalation vulnerability in Windows Hyper-V NT Kernel Integration VSP component with a use-after-free flaw. Despite being in CISA KEV indicating active exploitation, it requires local access and authenticated user privileges to exploit.
CVE-2025-21333KEV 2025-01-14 2025-01-14 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows Server, Windows Server 2022 23H2, Windows CVE-2025-21333 is a local privilege escalation vulnerability in Windows Hyper-V NT Kernel Integration VSP affecting multiple Windows versions. Despite being in CISA KEV, it requires local access and is not directly exploitable from the internet against public-facing applications.
CVE-2025-21335KEV 2025-01-14 2025-01-14 T1068 Exploitation for Privilege Escalation 7.8 0 days No Windows 10 21H2, Windows 10 22H2, Windows 11 22H2 (+4 more) This is a local privilege escalation vulnerability in Windows Hyper-V's NT Kernel Integration VSP component affecting multiple Windows versions. The vulnerability requires local access and low-level privileges to exploit, making it unsuitable for direct internet exploitation.
CVE-2024-13159KEV 2025-03-10 2025-01-14 T1190 Exploit Public-Facing Application 9.8 55 days No Ivanti Endpoint Manager Critical absolute path traversal vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to access sensitive information. The vulnerability is actively exploited in the wild according to CISA KEV listing.
CVE-2024-13160KEV 2025-03-10 2025-01-14 T1190 Exploit Public-Facing Application 9.8 55 days No Ivanti Endpoint Manager CVE-2024-13160 is a critical absolute path traversal vulnerability in Ivanti Endpoint Manager that allows remote unauthenticated attackers to leak sensitive information. This vulnerability is actively exploited in the wild and listed in CISA's Known Exploited Vulnerabilities catalog.
CVE-2024-13161KEV 2025-03-10 2025-01-14 T1190 Exploit Public-Facing Application 9.8 55 days No Ivanti Endpoint Manager Critical absolute path traversal vulnerability in Ivanti Endpoint Manager allowing remote unauthenticated attackers to leak sensitive information. The vulnerability has a CVSS score of 9.8 and is actively being exploited in the wild according to CISA KEV.
CVE-2024-55591KEV 2025-01-14 2025-01-14 T1190 Exploit Public-Facing Application 9.6 0 days Yes (+506d) Fortinet FortiOS, Fortinet FortiProxy 7.0.0-7.0.19 Critical authentication bypass vulnerability in Fortinet FortiOS and FortiProxy allows remote attackers to gain super-admin privileges via crafted requests to Node.js websocket module. This vulnerability is actively exploited in the wild and listed in CISA KEV.
CVE-2024-53704KEV 2025-02-18 2025-01-09 T1133 External Remote Services 8.2 40 days Yes (+471d) SonicWall Firewalls Authentication bypass vulnerability in SonicWall firewall SSL VPN authentication mechanism allows remote attackers to bypass authentication without credentials. This affects the SSL VPN service which is specifically designed for internet exposure to provide remote access.
CVE-2025-0282KEV 2025-01-08 2025-01-08 T1133 External Remote Services 9.0 0 days Yes (+512d) Ivanti Connect Secure, Ivanti Policy Secure, Ivanti Neurons for ZTA Critical stack-based buffer overflow in Ivanti VPN and secure gateway products allows remote unauthenticated attackers to achieve remote code execution. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2024-50603KEV 2025-01-16 2025-01-08 T1190 Exploit Public-Facing Application 10.0 8 days No Aviatrix Controller Critical unauthenticated OS command injection vulnerability in Aviatrix Controller allowing remote code execution via API endpoints. The vulnerability is actively exploited in the wild and listed in CISA KEV. Aviatrix Controllers are typically deployed as internet-facing cloud management platforms.
CVE-2024-12987KEV 2025-05-15 2024-12-27 T1190 Exploit Public-Facing Application 7.3 139 days No DrayTek Vigor2960 Router, DrayTek Vigor300B Router Critical OS command injection vulnerability in DrayTek router web management interfaces allowing unauthenticated remote code execution. The vulnerability affects the apmcfgupload endpoint and has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation.
CVE-2024-53197KEV 2025-04-09 2024-12-27 T1068 Exploitation for Privilege Escalation 7.8 103 days No Linux Kernel CVE-2024-53197 is a Linux kernel vulnerability in the USB audio subsystem that allows out-of-bounds memory access when handling malicious USB audio devices. The vulnerability requires physical access to connect a malicious USB device and has a LOCAL attack vector, making it unsuitable for internet exploitation.
CVE-2024-53150KEV 2025-04-09 2024-12-24 T1068 Exploitation for Privilege Escalation 7.1 106 days No Linux Kernel CVE-2024-53150 is a Linux kernel vulnerability in the USB audio driver that allows out-of-bounds reads when processing malicious USB device descriptors. Despite being in CISA KEV, this is primarily a local privilege escalation issue requiring physical USB device insertion or prior system access.
CVE-2024-56145KEV 2025-06-02 2024-12-18 T1190 Exploit Public-Facing Application 9.3 166 days No Craft CMS 3.x-5.x Critical remote code execution vulnerability in Craft CMS affecting all versions since 3.0.0 when PHP register_argc_argv is enabled. This vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable web servers and is actively exploited in the wild.
CVE-2024-12686KEV 2025-01-13 2024-12-18 T1133 External Remote Services 6.6 26 days No BeyondTrust Remote Support, BeyondTrust Privileged Remote Access OS command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access allowing attackers with administrative privileges to execute commands as site users. This affects remote access platforms that are inherently internet-facing by design and is actively exploited in the wild per CISA KEV.
CVE-2024-55550KEV 2025-01-07 2024-12-10 T1068 Exploitation for Privilege Escalation 4.4 28 days Yes (+513d) Mitel MiCollab This vulnerability affects Mitel MiCollab and allows authenticated administrators to read local files through path traversal. Despite being in CISA KEV, it has a LOCAL attack vector and requires administrative privileges, limiting its internet exploitability.
CVE-2024-53104KEV 2025-02-05 2024-12-02 T1068 Exploitation for Privilege Escalation 7.8 65 days No Linux Kernel CVE-2024-53104 is a Linux kernel vulnerability in the UVC video driver that causes out-of-bounds writes during USB camera parsing. Despite being in CISA KEV, this is a local privilege escalation vulnerability requiring physical access or malicious USB devices, not an internet-facing service vulnerability.
CVE-2024-49035KEV 2025-02-25 2024-11-26 T1190 Exploit Public-Facing Application 8.7 91 days No Microsoft Partner Center This is an improper access control vulnerability in Microsoft Partner Center (Partner.Microsoft.com) that allows unauthenticated attackers to elevate privileges over a network. The vulnerability is classified as an 'exclusively-hosted-service' and is actively being exploited in the wild according to CISA KEV.
CVE-2024-50302KEV 2025-03-04 2024-11-19 T1068 Exploitation for Privilege Escalation 5.5 105 days No Linux Kernel CVE-2024-50302 is a Linux kernel HID (Human Interface Device) subsystem vulnerability that allows information disclosure through uninitialized memory in report buffers. Despite being in CISA KEV, this is a LOCAL attack vector vulnerability requiring existing system access, making it unsuitable for direct internet exploitation.
CVE-2024-11182KEV 2025-05-19 2024-11-15 T1203 Exploitation for Client Execution 5.3 185 days No MDaemon Email Server CVE-2024-11182 is a stored XSS vulnerability in MDaemon Email Server's webmail component that requires an attacker to send a malicious HTML email to victims. While the email server itself is internet-facing, this vulnerability targets user browser sessions rather than providing direct server access, making it a phishing/social engineering attack vector rather than direct server exploitation.
CVE-2024-11120KEV 2025-05-07 2024-11-15 T1190 Exploit Public-Facing Application 9.8 173 days No GeoVision GV-VS12 Video Server, GeoVision GV-VS11 Video Server, GeoVision GV-DSP LPR V3 License Plate Recognition System (+2 more) Critical OS command injection vulnerability in GeoVision video surveillance and license plate recognition devices allows unauthenticated remote attackers to execute arbitrary system commands. The vulnerability is being actively exploited in the wild and affected devices are end-of-life with no patches available.
CVE-2024-8069KEV 2025-08-25 2024-11-12 T1133 External Remote Services 5.1 286 days No Citrix Session Recording CVE-2024-8069 is an adjacent network RCE vulnerability in Citrix Session Recording requiring authenticated intranet access. Despite CISA KEV listing indicating active exploitation, the attack vector is limited to adjacent networks, not direct internet exploitation.
CVE-2024-8068KEV 2025-08-25 2024-11-12 T1068 Exploitation for Privilege Escalation 5.1 286 days No Citrix Session Recording CVE-2024-8068 is a privilege escalation vulnerability in Citrix Session Recording that allows an authenticated Active Directory domain user to escalate privileges to NetworkService Account level. Despite being in CISA KEV, this requires existing domain authentication and adjacent network access, making it primarily useful for lateral movement rather than initial access.
CVE-2024-41713KEV 2025-01-07 2024-10-21 T1190 Exploit Public-Facing Application 9.1 78 days Yes (+513d) Mitel MiCollab Critical unauthenticated path traversal vulnerability in Mitel MiCollab NuPoint Unified Messaging component allows remote attackers to view, corrupt, or delete user data and system configurations. This vulnerability is actively exploited and listed in CISA KEV.
CVE-2024-43468KEV 2026-02-12 2024-10-08 T1190 Exploit Public-Facing Application 9.8 492 days No Microsoft Configuration Manager Critical SQL injection vulnerability in Microsoft Configuration Manager (SCCM) allowing unauthenticated remote code execution. CISA has listed this in their Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
CVE-2024-20439KEV 2025-03-31 2024-09-04 T1078 Valid Accounts 9.8 208 days No Cisco Smart License Utility CVE-2024-20439 is a critical authentication bypass vulnerability in Cisco Smart License Utility due to hardcoded administrative credentials. Attackers can remotely login with administrative privileges over the CSLU application API without any authentication. Active exploitation has been observed in the wild.
CVE-2024-45195KEV 2025-02-04 2024-09-04 T1190 Exploit Public-Facing Application 9.8 153 days No Apache OFBiz CVE-2024-45195 is a Critical forced browsing vulnerability in Apache OFBiz allowing unauthorized access to protected application areas without authentication. This vulnerability has active exploitation confirmed by CISA KEV listing and affects enterprise ERP systems commonly deployed as internet-facing web applications.
CVE-2024-7694KEV 2026-02-17 2024-08-12 T1190 Exploit Public-Facing Application 7.2 554 days No TeamT5 ThreatSonar Anti-Ransomware CVE-2024-7694 is an unrestricted file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware that allows remote attackers with admin privileges to upload malicious files and execute arbitrary system commands. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2024-41710KEV 2025-02-12 2024-08-12 T1133 External Remote Services 6.8 184 days No Mitel 6800 Series SIP Phones, Mitel 6900 Series SIP Phones, Mitel 6900w Series SIP Phones (+1 more) Mitel SIP phones contain an argument injection vulnerability allowing authenticated administrators to execute arbitrary commands. While these phones are network devices often deployed on corporate networks with some internet exposure, the attack vector is adjacent network and requires high privileges.
CVE-2024-27443KEV 2025-05-19 2024-08-12 T1203 Exploitation for Client Execution 6.1 280 days No Zimbra Collaboration Server This is a Cross-Site Scripting (XSS) vulnerability in Zimbra webmail that requires sending a malicious email with crafted calendar headers to victims. While Zimbra is internet-facing, this XSS only compromises user sessions, not the server itself, making it a phishing attack rather than direct server exploitation.
CVE-2024-7399KEV 2026-04-24 2024-08-09 T1190 Exploit Public-Facing Application 8.8 623 days No Samsung MagicINFO 9 Server Path traversal vulnerability in Samsung MagicINFO 9 Server allows remote attackers to write arbitrary files with system authority. The vulnerability is actively exploited in the wild and listed in CISA KEV catalog.
CVE-2024-42009KEV 2025-06-09 2024-08-05 T1203 Exploitation for Client Execution 9.3 308 days No Roundcube Webmail Cross-Site Scripting vulnerability in Roundcube webmail allows attackers to steal and send emails via crafted email messages. Despite high CVSS score and CISA KEV listing, this is client-side XSS requiring user interaction, not direct server compromise.
CVE-2024-21182KEV 2026-06-01 2024-07-16 T1190 Exploit Public-Facing Application 7.5 685 days No Oracle WebLogic Server CVE-2024-21182 is an unauthenticated network vulnerability in Oracle WebLogic Server allowing unauthorized access to critical data via T3/IIOP protocols. WebLogic Server is commonly deployed as an internet-facing enterprise application server, making this vulnerability highly exploitable from the internet.
CVE-2024-38475KEV 2025-05-01 2024-07-01 T1190 Exploit Public-Facing Application 9.1 304 days No Apache HTTP Server, NetApp ONTAP systems CVE-2024-38475 is a critical vulnerability in Apache HTTP Server's mod_rewrite module that allows remote attackers to map URLs to unintended filesystem locations, leading to code execution or source code disclosure. This vulnerability affects one of the world's most widely deployed web servers and has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
CVE-2024-4885KEV 2025-03-03 2024-06-25 T1190 Exploit Public-Facing Application 9.8 251 days No WhatsUp Gold Critical unauthenticated remote code execution vulnerability in WhatsUp Gold's API endpoint allows attackers to execute arbitrary commands with IIS application pool privileges. This network monitoring software is commonly deployed as an internet-facing service for remote monitoring capabilities.
CVE-2024-37079KEV 2026-01-23 2024-06-18 T1190 Exploit Public-Facing Application 9.8 584 days No VMware vCenter Server, VMware Cloud Foundation Critical heap-overflow vulnerability in VMware vCenter Server's DCERPC protocol implementation allows remote code execution via specially crafted network packets. This vulnerability is actively exploited in the wild and affects a core infrastructure product commonly exposed to networks.
CVE-2024-6047KEV 2025-05-07 2024-06-17 T1190 Exploit Public-Facing Application 9.8 324 days No GeoVision IP Cameras, GeoVision Video Servers, GeoVision License Plate Recognition (+1 more) Critical OS command injection vulnerability affecting multiple end-of-life GeoVision IP cameras and video servers. Unauthenticated attackers can execute arbitrary system commands remotely over the network with CVSS 9.8 severity.
CVE-2023-50224KEV 2025-09-03 2024-05-03 T1078 Valid Accounts 6.5 488 days No TP-Link TL-WR841N Router Authentication bypass vulnerability in TP-Link TL-WR841N router's httpd service allows unauthenticated attackers to disclose stored credentials via TCP port 80. This is actively exploited and listed in CISA KEV.
CVE-2024-29059KEV 2025-02-04 2024-03-22 T1190 Exploit Public-Facing Application 7.5 319 days No .NET Framework, .NET Framework 4.7/4.7.1/4.7.2, .NET Framework 2.0/3.0 (+3 more) CVE-2024-29059 is an information disclosure vulnerability in .NET Framework that can expose sensitive information through error messages. While CISA has added it to the KEV catalog indicating active exploitation, the vulnerability is limited to information disclosure rather than remote code execution.
CVE-2024-27199KEV 2026-04-20 2024-03-04 T1190 Exploit Public-Facing Application 7.3 777 days Yes (+45d) JetBrains TeamCity Path traversal vulnerability in JetBrains TeamCity allowing unauthenticated attackers to perform limited admin actions. This CI/CD server is commonly exposed to the internet for developer access and is actively being exploited in the wild.
CVE-2024-1708KEV 2026-04-28 2024-02-21 T1190 Exploit Public-Facing Application 8.4 797 days Yes (+37d) ConnectWise ScreenConnect CVE-2024-1708 is a critical path traversal vulnerability in ConnectWise ScreenConnect that enables remote code execution on internet-facing remote access servers. This vulnerability is actively exploited in the wild and listed in CISA KEV.
CVE-2024-20953KEV 2025-02-24 2024-02-17 T1190 Exploit Public-Facing Application 8.8 373 days No Oracle Agile PLM This is a critical deserialization vulnerability in Oracle Agile PLM that allows complete system takeover via HTTP network access with low privileges. The vulnerability is actively exploited in the wild and listed in CISA KEV.
CVE-2024-21413KEV 2025-02-06 2024-02-13 T1203 Exploitation for Client Execution 9.8 359 days No Microsoft Outlook, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC Microsoft Outlook Remote Code Execution vulnerability affects client email applications, not server infrastructure. Despite the critical CVSS score and CISA KEV listing, this requires phishing/social engineering to deliver malicious content to Outlook clients rather than direct internet exploitation of servers.
CVE-2024-0769KEV 2025-06-25 2024-01-21 T1190 Exploit Public-Facing Application 5.3 521 days No D-Link DIR-859 Router D-Link DIR-859 router has a critical path traversal vulnerability in hedwig.cgi that allows remote attackers to access arbitrary files without authentication. This vulnerability is actively exploited and listed in CISA KEV, affecting an end-of-life router model.
CVE-2023-41974KEV 2026-03-05 2024-01-10 T1068 Exploitation for Privilege Escalation 7.8 785 days No iOS, iPadOS CVE-2023-41974 is a use-after-free vulnerability in iOS and iPadOS that allows malicious apps to execute arbitrary code with kernel privileges. While listed in CISA KEV and actively exploited, this affects mobile client devices, not internet-facing servers.
CVE-2023-44221KEV 2025-05-01 2023-12-05 T1133 External Remote Services 7.2 513 days No SonicWall SMA100 SSL-VPN SonicWall SMA100 SSL-VPN appliances contain an OS command injection vulnerability in the management interface allowing authenticated administrators to execute arbitrary commands. These appliances are specifically designed to be internet-facing and this vulnerability is actively exploited in the wild.
CVE-2023-48365KEV 2025-01-13 2023-11-15 T1190 Exploit Public-Facing Application 9.6 425 days Yes (+507d) Qlik Sense Enterprise for Windows CVE-2023-48365 is an unauthenticated remote code execution vulnerability in Qlik Sense Enterprise for Windows caused by improper HTTP header validation. Attackers can tunnel HTTP requests to execute commands on the backend repository server, leading to complete system compromise.
CVE-2023-36424KEV 2026-04-13 2023-11-14 T1068 Exploitation for Privilege Escalation 7.8 881 days No Windows, Windows Server, Windows Server Core installations Windows Common Log File System Driver privilege escalation vulnerability affecting Windows client and server operating systems. Requires local access and authentication to exploit, making it unsuitable for direct internet exploitation despite being in CISA KEV.
CVE-2023-39780KEV 2025-06-02 2023-09-11 T1190 Exploit Public-Facing Application 8.8 630 days No ASUS RT-AX55 Router Critical OS command injection vulnerability in ASUS RT-AX55 router web management interface. Authenticated attackers can execute arbitrary commands via the qos_bw_rulelist parameter. Listed in CISA KEV with evidence of active exploitation.
CVE-2022-48503KEV 2025-10-20 2023-08-14 T1203 Exploitation for Client Execution 8.8 798 days No Safari, iOS/iPadOS, macOS (+2 more) CVE-2022-48503 is a WebKit bounds check vulnerability affecting Apple's client-side products (Safari, iOS, macOS, etc.) that allows arbitrary code execution when processing malicious web content. While listed in CISA KEV indicating active exploitation, this is a client-side vulnerability requiring user interaction rather than a server-side exploit.
CVE-2023-38950KEV 2025-05-19 2023-08-03 T1190 Exploit Public-Facing Application 7.5 655 days No ZKTeco BioTime, ZKBioTime CVE-2023-38950 is a path traversal vulnerability in ZKTeco BioTime's iclock API that allows unauthenticated attackers to read arbitrary files remotely. This is actively exploited in the wild and listed in CISA's KEV catalog.
CVE-2023-34192KEV 2025-02-25 2023-07-06 T1203 Exploitation for Client Execution 9.0 600 days No Zimbra Collaboration Suite Cross-site scripting vulnerability in Zimbra Collaboration Suite 8.8.15 affecting the /h/autoSaveDraft function. Despite being in CISA KEV, this is an XSS vulnerability that compromises user sessions rather than the server itself, requiring authenticated user interaction for exploitation.
CVE-2023-2533KEV 2025-07-28 2023-06-20 T1204 User Execution 8.4 769 days No PaperCut NG/MF CSRF vulnerability in PaperCut NG/MF that requires an admin to click a malicious link while logged in. Despite the high CVSS score and CISA KEV listing, this is not direct server exploitation but requires social engineering to trick administrators.
CVE-2023-33538KEV 2025-06-16 2023-06-07 T1190 Exploit Public-Facing Application 8.8 740 days No TP-Link TL-WR940N V2/V4, TP-Link TL-WR841N V8/V10, TP-Link TL-WR740N V1/V2 TP-Link routers contain a command injection vulnerability in the /userRpm/WlanNetworkRpm component that allows authenticated attackers to execute arbitrary commands. This vulnerability is actively exploited in the wild and affects commonly deployed home/small business routers that are inherently internet-facing.
CVE-2023-27351KEV 2026-04-20 2023-04-20 T1190 Exploit Public-Facing Application 8.2 1096 days Yes (+45d) PaperCut NG PaperCut NG contains an authentication bypass vulnerability that allows remote attackers to bypass authentication without any user interaction. This vulnerability is actively exploited in the wild and listed in CISA's Known Exploited Vulnerabilities catalog.
CVE-2023-20118KEV 2025-03-03 2023-04-05 T1190 Exploit Public-Facing Application 6.5 698 days No Cisco Small Business RV Series Routers Command injection vulnerability in Cisco Small Business Router web management interface allows authenticated remote attackers to execute arbitrary commands with root privileges. Proof-of-concept exploits exist and active exploitation has been observed in the wild since March 2025.
CVE-2022-43939KEV 2025-03-03 2023-04-03 T1190 Exploit Public-Facing Application 8.6 700 days No Pentaho Business Analytics Server Authentication bypass vulnerability in Pentaho Business Analytics Server allows attackers to circumvent security restrictions using non-canonical URLs. The vulnerability leads to SSTI (Server-Side Template Injection) and code execution according to exploit references.
CVE-2022-43769KEV 2025-03-03 2023-04-03 T1190 Exploit Public-Facing Application 8.8 700 days No Pentaho Business Analytics Server Hitachi Vantara Pentaho Business Analytics Server contains a Spring Template injection vulnerability allowing authenticated attackers to execute arbitrary code. This affects web services that improperly sanitize user input containing Spring templates, leading to server-side template injection (SSTI).
CVE-2023-0386KEV 2025-06-17 2023-03-22 T1068 Exploitation for Privilege Escalation 7.8 818 days No Linux Kernel, Debian Linux, Ubuntu (+4 more) CVE-2023-0386 is a local privilege escalation vulnerability in the Linux kernel's OverlayFS subsystem that allows a local user to escalate privileges by exploiting a uid mapping bug when copying capable files between mounts. This requires local access and cannot be exploited directly over the internet, making it a post-compromise escalation tool rather than an initial attack vector.
CVE-2023-21529KEV 2026-04-13 2023-02-14 T1190 Exploit Public-Facing Application 8.8 1154 days Yes (+52d) Exchange Server CVE-2023-21529 is a remote code execution vulnerability in Microsoft Exchange Server caused by deserialization of untrusted data (CWE-502). This vulnerability allows authenticated attackers to execute arbitrary code on Exchange servers, which are commonly internet-facing for email services.
CVE-2022-40799KEV 2025-08-05 2022-11-29 T1190 Exploit Public-Facing Application 8.8 980 days No D-Link DNR-322L Network Video Recorder Critical command injection vulnerability in D-Link DNR-322L Cloud Network Video Recorder allowing authenticated attackers to execute OS-level commands via the 'Backup Config' functionality. This network device is commonly internet-facing for remote monitoring purposes and is actively exploited according to CISA KEV.
CVE-2022-23748KEV 2025-02-06 2022-11-17 T1204 User Execution 7.8 812 days No Audinate Dante Application Library for Windows CVE-2022-23748 is a DLL sideloading vulnerability in mDNSResponder.exe from Audinate Dante Application Library. Despite being listed in CISA KEV, this is a local attack requiring user interaction to execute the malicious DLL alongside the legitimate executable.
CVE-2022-20775KEV 2026-02-25 2022-09-30 T1068 Exploitation for Privilege Escalation 7.8 1244 days No Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vContainer (+2 more) CVE-2022-20775 is a local privilege escalation vulnerability in Cisco SD-WAN Software CLI that allows authenticated, local attackers to execute commands as root. While the affected products are commonly internet-facing, the vulnerability itself requires existing local access and cannot be directly exploited over the internet.
CVE-2022-37055KEV 2025-12-08 2022-08-28 T1190 Exploit Public-Facing Application 9.8 1198 days No D-Link GO-RT-AC750 Wireless Router Critical buffer overflow vulnerability in D-Link GO-RT-AC750 wireless routers affecting cgibin and hnap_main components. This vulnerability is actively exploited in the wild and listed in CISA KEV, allowing unauthenticated remote code execution.
CVE-2022-0492KEV 2026-06-02 2022-03-03 T1068 Exploitation for Privilege Escalation 7.8 1552 days No Linux Kernel, Docker containers, Kubernetes clusters (+3 more) CVE-2022-0492 is a Linux kernel privilege escalation vulnerability in the cgroups v1 release_agent feature that allows bypassing namespace isolation. This is a local exploit requiring existing access to a system or container, commonly used for Docker container escapes.
CVE-2021-22054KEV 2026-03-09 2021-12-17 T1190 Exploit Public-Facing Application 7.5 1543 days No VMware Workspace ONE UEM VMware Workspace ONE UEM console contains an unauthenticated SSRF vulnerability that allows remote attackers to access sensitive information. This enterprise mobility management platform is commonly exposed to the internet for device management purposes.
CVE-2021-43226KEV 2025-10-06 2021-12-15 T1068 Exploitation for Privilege Escalation 7.8 1391 days No Windows, Windows Server, Windows Server 2012/2012 R2 (+1 more) CVE-2021-43226 is a local privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver that requires local access and low-level privileges to exploit. While it affects both client and server Windows systems, it cannot be exploited directly over the internet as it requires local system access.
CVE-2021-39935KEV 2026-02-03 2021-12-13 T1190 Exploit Public-Facing Application 6.8 1513 days No GitLab Community Edition, GitLab Enterprise Edition Server-Side Request Forgery (SSRF) vulnerability in GitLab CI Lint API allows unauthorized external users to perform internal network requests. GitLab instances are commonly internet-facing, making this vulnerability directly exploitable over the network without authentication.
CVE-2021-43798KEV 2025-10-09 2021-12-07 T1190 Exploit Public-Facing Application 7.5 1402 days No Grafana Grafana instances are vulnerable to directory traversal attacks allowing unauthorized access to local files through crafted URLs. This affects internet-facing Grafana dashboards commonly exposed for monitoring and observability purposes. The vulnerability has been actively exploited in the wild.
CVE-2021-20035KEV 2025-04-16 2021-09-27 T1190 Exploit Public-Facing Application 6.5 1297 days No SonicWall SMA100 OS Command Injection vulnerability in SonicWall SMA100 management interface allows remote authenticated attackers to execute arbitrary commands as 'nobody' user. The vulnerability is actively exploited in the wild according to CISA KEV listing.
CVE-2021-30952KEV 2026-03-05 2021-08-24 T1203 Exploitation for Client Execution 8.8 1654 days No Safari, iOS/iPadOS, macOS (+2 more) WebKit integer overflow vulnerability in Apple client operating systems requiring user interaction with malicious web content. Despite CISA KEV listing, this affects client-side web browsers, not internet-facing servers, making it unsuitable for T1190 exploitation.
CVE-2021-22555KEV 2025-10-06 2021-07-07 T1068 Exploitation for Privilege Escalation 8.3 1552 days No Linux Kernel, Ubuntu, Red Hat Enterprise Linux (+4 more) Linux kernel netfilter heap out-of-bounds write vulnerability allowing privilege escalation and DoS. Requires adjacent network access and high attack complexity. Despite high deployment, this is primarily a privilege escalation vulnerability requiring existing local or adjacent network access.
CVE-2021-22175KEV 2026-02-18 2021-06-11 T1190 Exploit Public-Facing Application 6.8 1713 days No GitLab Server-Side Request Forgery (SSRF) vulnerability in GitLab allows unauthenticated attackers to make requests to internal networks when webhook internal network requests are enabled. This affects GitLab instances from version 10.5 through multiple 13.x versions and is actively exploited according to CISA KEV.
CVE-2021-26828KEV 2025-12-03 2021-06-11 T1190 Exploit Public-Facing Application 8.8 1636 days No OpenPLC ScadaBR, ScadaBR Linux versions through, ScadaBR Windows versions through CVE-2021-26828 is a critical file upload vulnerability in OpenPLC ScadaBR that allows authenticated remote users to upload and execute arbitrary JSP files. This vulnerability enables direct remote code execution on SCADA/HMI systems that are commonly internet-facing for remote monitoring and control operations.
CVE-2021-26829KEV 2025-11-28 2021-06-11 T1204 User Execution 5.4 1631 days No OpenPLC ScadaBR Stored XSS vulnerability in OpenPLC ScadaBR system settings that requires user interaction. Despite CISA KEV listing, this targets user sessions rather than the server infrastructure itself.
CVE-2021-32030KEV 2025-06-02 2021-05-06 T1190 Exploit Public-Facing Application 9.8 1488 days No ASUS GT-AC2900 Router, ASUS Lyra Mini Router Authentication bypass vulnerability in ASUS router administrator interfaces allows unauthenticated remote attackers to gain full administrative access. The vulnerability affects router web management interfaces that are commonly exposed to the internet for remote administration.
CVE-2021-22681KEV 2026-03-05 2021-03-03 T1190 Exploit Public-Facing Application 9.8 1828 days No Rockwell Automation Studio 5000 Logix Designer, RSLogix, CompactLogix Controllers (+4 more) Critical authentication bypass vulnerability in Rockwell Automation industrial control systems allowing unauthenticated attackers to bypass verification mechanisms and authenticate with Logix controllers over the network. This vulnerability is actively exploited and listed in CISA KEV catalog.
CVE-2021-21311KEV 2025-09-29 2021-02-11 T1190 Exploit Public-Facing Application 7.2 1691 days No Adminer Adminer, a popular PHP-based database management tool, contains an SSRF vulnerability (CWE-918) that allows unauthenticated attackers to make server-side requests. This vulnerability is actively exploited in the wild and listed in CISA's KEV catalog.
CVE-2020-29574KEV 2025-02-06 2020-12-11 T1190 Exploit Public-Facing Application 9.8 1518 days No Cyberoam OS, Sophos Cyberoam firewalls Critical SQL injection vulnerability in Cyberoam OS WebAdmin interface allows unauthenticated remote attackers to execute arbitrary SQL statements. This affects network security appliances that are typically deployed as internet-facing gateway devices.
CVE-2020-25078KEV 2025-08-05 2020-09-02 T1190 Exploit Public-Facing Application 7.5 1798 days No D-Link DCS-2530L IP Camera, D-Link DCS-2670L IP Camera D-Link DCS-2530L and DCS-2670L IP cameras expose an unauthenticated /config/getuser endpoint that allows remote disclosure of administrator passwords. This vulnerability enables direct network exploitation against internet-facing security cameras commonly deployed for remote monitoring.
CVE-2020-25079KEV 2025-08-05 2020-09-02 T1190 Exploit Public-Facing Application 8.8 1798 days No D-Link DCS-2530L IP Camera, D-Link DCS-2670L IP Camera Command injection vulnerability in D-Link IP cameras' web management interface allows authenticated attackers to execute arbitrary commands. These cameras are commonly deployed with internet-facing web interfaces for remote monitoring.
CVE-2020-24363KEV 2025-09-02 2020-08-31 T1190 Exploit Public-Facing Application 8.8 1828 days No TP-Link TL-WA855RE V5 WiFi Range Extender TP-Link TL-WA855RE V5 WiFi range extender allows unauthenticated attackers on the same network to perform factory reset via TDDP_RESET POST request and then set new administrative password. This vulnerability is actively exploited and listed in CISA KEV.
CVE-2020-9715KEV 2026-04-13 2020-08-19 T1203 Exploitation for Client Execution 7.8 2063 days No Adobe Acrobat, Adobe Reader CVE-2020-9715 is a use-after-free vulnerability in Adobe Acrobat and Reader that allows arbitrary code execution. This affects client-side PDF applications that require user interaction to open malicious documents, not internet-facing servers.
CVE-2020-15069KEV 2025-02-06 2020-06-29 T1190 Exploit Public-Facing Application 9.8 1683 days No Sophos XG Firewall Critical buffer overflow vulnerability in Sophos XG Firewall's HTTP/S Bookmarks feature that allows remote code execution without authentication. This vulnerability affects firewall appliances that are inherently internet-facing and is actively exploited in the wild.
CVE-2020-11023KEV 2025-01-23 2020-04-29 T1203 Exploitation for Client Execution 6.9 1730 days No jQuery CVE-2020-11023 is a cross-site scripting (XSS) vulnerability in jQuery that allows execution of untrusted JavaScript code in victims' browsers when processing malicious HTML with
CVE-2020-2883KEV 2025-01-07 2020-04-15 T1190 Exploit Public-Facing Application 9.8 1728 days No Oracle WebLogic Server Critical unauthenticated deserialization vulnerability in Oracle WebLogic Server allowing complete server takeover via network protocols IIOP and T3. This vulnerability is actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.
CVE-2020-7796KEV 2026-02-17 2020-02-18 T1190 Exploit Public-Facing Application 9.8 2191 days No Zimbra Collaboration Suite before 8.8.15 Patch SSRF vulnerability in Zimbra Collaboration Suite when WebEx zimlet is installed and JSP is enabled. This is a critical server-side vulnerability in a commonly internet-facing email/collaboration platform with active exploitation confirmed by CISA KEV listing.
CVE-2019-19006KEV 2026-02-03 2019-11-21 T1190 Exploit Public-Facing Application 9.8 2266 days No Sangoma FreePBX Authentication bypass vulnerability in Sangoma FreePBX allowing remote unauthenticated access to administrative functions. This is a critical vulnerability with CVSS 9.8 that has been actively exploited in the wild and added to CISA KEV.
CVE-2019-6693KEV 2025-06-25 2019-11-21 T1078 Valid Accounts 6.5 2043 days Yes (+344d) Fortinet FortiGate CVE-2019-6693 is a hard-coded cryptographic key vulnerability in Fortinet FortiGate configuration backup files. An attacker with access to backup files can decrypt sensitive data including user passwords and private key passphrases, potentially leading to credential theft and unauthorized access.
CVE-2019-9875KEV 2025-03-26 2019-05-31 T1190 Exploit Public-Facing Application 8.8 2126 days No Sitecore CMS Sitecore CMS platforms through version 9.1 contain a deserialization vulnerability in the anti-CSRF module that allows authenticated attackers to execute arbitrary code via HTTP POST parameters. This vulnerability is actively exploited in the wild and affects a widely deployed web content management platform.
CVE-2019-9874KEV 2025-03-26 2019-05-31 T1190 Exploit Public-Facing Application 9.8 2126 days No Sitecore CMS, Sitecore XP Critical deserialization vulnerability in Sitecore CMS allowing unauthenticated remote code execution via malicious .NET objects in CSRF tokens. Actively exploited in the wild and listed in CISA KEV catalog.
CVE-2018-4063KEV 2025-12-12 2019-05-06 T1190 Exploit Public-Facing Application 8.8 2412 days No Sierra Wireless AirLink ES450 Remote code execution vulnerability in Sierra Wireless AirLink ES450 router allowing authenticated attackers to upload and execute malicious code via HTTP request to upload.cgi. This vulnerability is in CISA KEV indicating active exploitation in the wild.
CVE-2019-9621KEV 2025-07-07 2019-04-30 T1190 Exploit Public-Facing Application 7.5 2260 days No Zimbra Collaboration Suite Server-Side Request Forgery (SSRF) vulnerability in Zimbra Collaboration Suite's ProxyServlet component allows unauthenticated network-based exploitation. Zimbra is widely deployed as an internet-facing email and collaboration server, making this vulnerability directly exploitable from the internet against the server itself.
CVE-2019-5418KEV 2025-07-07 2019-03-27 T1190 Exploit Public-Facing Application 7.5 2294 days No Ruby on Rails, Rails-based web applications CVE-2019-5418 is a file content disclosure vulnerability in Rails Action View that allows attackers to read arbitrary files from the server filesystem using specially crafted Accept headers. This affects web applications built with Rails, which are commonly deployed as internet-facing services.
CVE-2018-8639KEV 2025-03-03 2018-12-12 T1068 Exploitation for Privilege Escalation 8.4 2273 days Yes (+458d) Windows, Windows Server, Windows Server 2012 R2 (+2 more) CVE-2018-8639 is a local privilege escalation vulnerability in the Windows Win32k component that allows attackers with existing access to escalate privileges. This affects both Windows desktop and server systems but requires local access to exploit.
CVE-2018-19410KEV 2025-02-04 2018-11-21 T1190 Exploit Public-Facing Application 9.8 2267 days No PRTG Network Monitor Critical authentication bypass in PRTG Network Monitor allowing remote unauthenticated attackers to create administrator accounts via Local File Inclusion. Exploitation requires only crafting HTTP requests to the publicly accessible web interface.
CVE-2018-14634KEV 2026-01-26 2018-09-25 T1068 Exploitation for Privilege Escalation 7.8 2680 days No Linux Kernel 2.6.x, Linux Kernel 3.10.x, Linux Kernel 4.14.x (+4 more) CVE-2018-14634 is a local privilege escalation vulnerability in the Linux kernel's create_elf_tables() function that allows unprivileged users to gain root privileges. Despite being in CISA KEV, this requires local access and cannot be exploited directly from the internet.
CVE-2018-9276KEV 2025-02-04 2018-07-02 T1190 Exploit Public-Facing Application 7.2 2409 days No PRTG Network Monitor PRTG Network Monitor contains an OS command injection vulnerability in the web administrative console that allows authenticated attackers with admin privileges to execute arbitrary commands on the server. This is a high-risk vulnerability for internet-facing deployments, confirmed by CISA KEV listing indicating active exploitation.
CVE-2017-1000353KEV 2025-10-02 2018-01-29 T1190 Exploit Public-Facing Application 9.8 2803 days No Jenkins, Oracle products containing Jenkins components Jenkins automation servers prior to version 2.56 (and 2.46.1 LTS) contain an unauthenticated remote code execution vulnerability through the CLI interface via Java deserialization. This vulnerability allows complete server compromise without any user interaction and has active exploitation documented by CISA KEV.
CVE-2017-12637KEV 2025-03-19 2017-08-07 T1190 Exploit Public-Facing Application 7.5 2781 days No SAP NetWeaver Application Server Java Directory traversal vulnerability in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via path traversal in a JavaScript UI endpoint. This vulnerability has been actively exploited in the wild and is included in CISA's Known Exploited Vulnerabilities catalog.
CVE-2016-7836KEV 2025-10-14 2017-06-09 T1190 Exploit Public-Facing Application 9.8 3049 days No SKYSEA Client View CVE-2016-7836 is a remote code execution vulnerability in SKYSEA Client View's management console TCP connection authentication. While technically exploitable over the network without user interaction, this is primarily enterprise endpoint management software that is rarely deployed as internet-facing.
CVE-2017-7921KEV 2026-03-05 2017-05-06 T1190 Exploit Public-Facing Application 9.8 3225 days No Hikvision IP Cameras Authentication bypass vulnerability in Hikvision IP cameras allows attackers to escalate privileges and gain unauthorized access. The vulnerability is classified as CWE-287 (Improper Authentication) and is actively exploited in the wild according to CISA KEV.
CVE-2017-3066KEV 2025-02-24 2017-04-27 T1190 Exploit Public-Facing Application 9.8 2860 days No Adobe ColdFusion Critical Java deserialization vulnerability in Adobe ColdFusion allowing remote code execution via the Apache BlazeDS library. ColdFusion is primarily deployed as an internet-facing web application server, making this vulnerability directly exploitable over the internet without authentication.
CVE-2014-3931KEV 2025-07-07 2017-03-31 T1190 Exploit Public-Facing Application 9.8 3020 days No MRLG < Memory corruption vulnerability in MRLG (Multi-Router Looking Glass) fastping.c allows remote attackers to cause arbitrary memory write and corruption. This is a web-based network diagnostic tool typically deployed on internet-facing web servers for public network troubleshooting services.
CVE-2016-10033KEV 2025-07-07 2016-12-30 T1190 Exploit Public-Facing Application 9.8 3111 days No PHPMailer, WordPress, Drupal (+2 more) PHPMailer before 5.2.18 contains a command injection vulnerability allowing remote attackers to execute arbitrary code via a crafted Sender property. This vulnerability affects countless web applications that use PHPMailer for email functionality and is actively exploited in the wild.
CVE-2015-7755KEV 2025-10-02 2015-12-19 T1078 Valid Accounts 9.8 3575 days No Juniper ScreenOS Firewalls, Juniper SSG Series, Juniper ISG Series Critical authentication bypass backdoor in Juniper ScreenOS firewalls allowing remote administrative access via SSH/Telnet with an unknown hardcoded password. This is the infamous Juniper backdoor that compromised enterprise network perimeters worldwide.
CVE-2014-6278KEV 2025-10-02 2014-09-30 T1190 Exploit Public-Facing Application 8.8 4020 days No Apache HTTP Server, OpenSSH Server, DHCP Servers (+5 more) CVE-2014-6278 is a Bash Shellshock vulnerability allowing remote command execution via crafted environment variables. It affects internet-facing services using Bash for CGI scripts, SSH, DHCP, and other network services that process environment variables.
CVE-2013-3918KEV 2025-10-06 2013-11-12 T1203 Exploitation for Client Execution 8.8 4346 days No Internet Explorer, Windows XP, Windows Server (+3 more) ActiveX control vulnerability in Internet Explorer allowing remote code execution when users visit malicious web pages. This is a client-side vulnerability requiring user interaction, not a server-side vulnerability exploitable over the internet.
CVE-2013-3893KEV 2025-08-12 2013-09-18 T1203 Exploitation for Client Execution 8.8 4346 days No Internet Explorer CVE-2013-3893 is a use-after-free vulnerability in Internet Explorer 6-11 that allows remote code execution via crafted JavaScript when a user visits a malicious website. This is a client-side browser vulnerability requiring user interaction, not a server-side vulnerability.
CVE-2012-1854KEV 2026-04-13 2012-07-10 T1204 User Execution 7.8 5025 days No Microsoft Office, Visual Basic for Applications, Summit VBA SDK CVE-2012-1854 is an untrusted search path vulnerability in Microsoft Office VBA that allows local privilege escalation via DLL hijacking. Exploitation requires a user to open a malicious Office document from a directory containing a Trojan horse DLL.
CVE-2011-3402KEV 2025-10-06 2011-11-04 T1203 Exploitation for Client Execution 8.8 5085 days No Windows XP SP2/SP3, Windows Server 2003 SP2, Windows Vista SP2 (+2 more) CVE-2011-3402 is a TrueType font parsing vulnerability in Windows kernel-mode drivers that was exploited by the Duqu malware. The vulnerability requires user interaction to open a malicious Word document or visit a compromised web page containing crafted font data.
CVE-2010-3962KEV 2025-10-06 2010-11-05 T1203 Exploitation for Client Execution 8.1 5449 days No Internet Explorer CVE-2010-3962 is a use-after-free vulnerability in Internet Explorer 6, 7, and 8 that allows remote code execution via malicious CSS. While it was actively exploited in the wild and is on CISA KEV, it targets client-side browsers, not internet-facing servers.
CVE-2010-3765KEV 2025-10-06 2010-10-27 T1203 Exploitation for Client Execution 9.8 5458 days No Firefox 3.5.x through, Firefox 3.6.x through, Thunderbird 3.0.x before (+2 more) CVE-2010-3765 is a memory corruption vulnerability in Mozilla Firefox, Thunderbird, and SeaMonkey browsers that allows remote code execution when JavaScript is enabled. Despite being in CISA KEV and having a high CVSS score, this is a client-side browser vulnerability requiring users to visit malicious websites, not a server-side vulnerability.
CVE-2010-0806KEV 2026-05-20 2010-03-10 T1203 Exploitation for Client Execution 8.8 5915 days No Internet Explorer, Internet Explorer 6 SP1 Use-after-free vulnerability in Internet Explorer 6-7 that allows remote code execution when users visit malicious websites. This is a client-side browser vulnerability exploited through malicious web content, not a server-side vulnerability.
CVE-2010-0249KEV 2026-05-20 2010-01-15 T1203 Exploitation for Client Execution 8.8 5969 days No Internet Explorer, Windows XP/Vista/7, Windows Server 2003/2008 Use-after-free vulnerability in Internet Explorer 6-8 that allows remote code execution when users visit malicious websites. This was famously exploited in Operation Aurora attacks but requires user interaction to visit attacker-controlled content.
CVE-2009-3459KEV 2026-05-20 2009-10-13 T1203 Exploitation for Client Execution 8.8 6063 days No Adobe Reader 7.x before, Adobe Reader 8.x before, Adobe Reader 9.x before (+3 more) CVE-2009-3459 is a heap-based buffer overflow in Adobe Reader/Acrobat that allows remote code execution via crafted PDF files. This is a client-side vulnerability requiring user interaction to open a malicious PDF, not a server-side vulnerability that can be directly exploited over the internet.
CVE-2008-0015KEV 2026-02-17 2009-07-07 T1203 Exploitation for Client Execution 8.8 6069 days No Windows XP SP2/SP3, Windows Vista, Windows Server 2003 SP2 (+2 more) CVE-2008-0015 is a stack-based buffer overflow in Microsoft's Video ActiveX Control that allows remote code execution via crafted web pages. While the vulnerability enables remote code execution, it targets client-side ActiveX components in web browsers rather than server infrastructure, requiring user interaction to visit a malicious website.
CVE-2009-1537KEV 2026-05-20 2009-05-29 T1203 Exploitation for Client Execution 8.8 6200 days No DirectX 7.0-9.0c, Windows XP SP2/SP3, Windows Server 2003 SP2 (+1 more) CVE-2009-1537 is a vulnerability in Microsoft DirectX's QuickTime Movie Parser that allows remote code execution when processing crafted QuickTime media files. This is a client-side vulnerability requiring user interaction to open malicious media files, not a server-side vulnerability exploitable over the internet.
CVE-2009-0556KEV 2026-01-07 2009-04-03 T1203 Exploitation for Client Execution 8.8 6123 days No Microsoft PowerPoint 2000 SP3, Microsoft PowerPoint 2002 SP3, Microsoft PowerPoint 2003 SP3 (+1 more) Microsoft PowerPoint memory corruption vulnerability that allows remote code execution when a user opens a specially crafted PowerPoint file. Despite being in CISA KEV, this is a client-side application vulnerability requiring user interaction, not a server-side exploit.
CVE-2009-0238KEV 2026-04-14 2009-02-25 T1203 Exploitation for Client Execution 8.8 6257 days No Microsoft Excel, Excel Viewer, Office Compatibility Pack (+1 more) CVE-2009-0238 is a client-side vulnerability in Microsoft Excel that allows remote code execution via malicious Excel documents. While it has been exploited in the wild via Trojan.Mdropper.AC, it requires user interaction to open a crafted document and does not directly compromise internet-facing servers.
CVE-2008-4250KEV 2026-05-20 2008-10-23 T1190 Exploit Public-Facing Application 9.8 6418 days No Windows Server, Windows XP, Windows Vista (+1 more) CVE-2008-4250 is a critical buffer overflow in Windows Server service that allows remote code execution via crafted RPC requests. This vulnerability was actively exploited by the Conficker worm and affects network-accessible Windows systems including servers commonly exposed to the internet.
CVE-2007-0671KEV 2025-08-12 2007-02-03 T1203 Exploitation for Client Execution 8.8 6765 days No Microsoft Excel, Microsoft Excel XP, Microsoft Excel 2004 for Mac Microsoft Excel vulnerability allowing arbitrary code execution when users open malicious Excel files. Requires user interaction to open the file. This is client-side exploitation, not server compromise.