Skip to main content
EVULNABLE Home

Priority feed

The highest risk items, ranked by real-world exploitation signals.

Ranked by EVRS — New to CISA KEV

Showing all 29 entries added to CISA KEV in the last 30 days. Data checked 07 Sep 11:30 UTC. Show all tracked items.

#1 ExigentOverdue by 24 daysCISA KEV
CVE-2026-72898

Metabase SQL Injection Vulnerability

Listed in the CISA KEV catalog, and an EPSS probability of 0.942.

#2 90 Immediate CVE-2026-60004 Overdue by 10 daysCISA KEV Gitea — Gitea Code Injection Vulnerability Patch Immediately
CVSS9.8 (NVD)EPSS99+KEV since2026-08-25

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.868.

#3 89 Immediate CVE-2021-23758 ExigentCISA deadline in 2 daysCISA KEV Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability Out-of-Band / Urgent Remediation
CVSS9.8 (NVD)EPSS99+KEV since2026-08-26

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.836.

#4 85 Immediate CVE-2026-82078 ExigentCISA deadline in 7 daysCISA KEV PaperCut — PaperCut NG/MF Unsafe Reflection Vulnerability Out-of-Band / Urgent Remediation
CVSS9.4 (NVD)EPSS75+KEV since2026-08-31

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#5 79 Urgent CVE-2026-59310 Overdue by 17 daysCISA KEV Broadcom — Broadcom VMware vCenter Path Traversal Vulnerability Patch This Cycle
CVSS9.8 (NVD)EPSS98+KEV since2026-08-18

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#6 78 Urgent CVE-2023-49105 Overdue by 8 daysCISA KEV ownCloud — ownCloud Improper Authentication Vulnerability Patch This Cycle
CVSS9.8 (NVD)EPSS98+KEV since2026-08-27

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#7 78 Urgent CVE-2026-21962 Overdue by 11 daysCISA KEV Oracle — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability Patch This Cycle
CVSS10.0 (NVD)EPSS98+KEV since2026-08-24

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#8 75 Urgent CVE-2026-48710 CISA deadline in 9 daysCISA KEV Kludex — Kludex Starlette HTTP Request/Response Smuggling Vulnerability Patch This Cycle
CVSS6.5 (NVD)EPSS98+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#9 75 Urgent CVE-2026-73570 Overdue by 14 daysCISA KEV Synacor — Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability Patch This Cycle
CVSS8.9 (NVD)EPSS98+KEV since2026-08-21

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#10 75 Urgent CVE-2025-62593 Overdue by 18 daysCISA KEV Ray-Project — Ray-Project Ray Code Injection Vulnerability Patch This Cycle
CVSS9.4 (NVD)EPSS96+KEV since2026-08-17

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#11 75 Urgent CVE-2026-64849 Overdue by 5 daysCISA KEV MLflow — MLflow Server-Side Request Forgery Vulnerability Patch This Cycle
CVSS8.5 (Red Hat est.)EPSS96+KEV since2026-08-19

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#12 75 Urgent CVE-2026-9586 Overdue by 2 daysCISA KEV Sangoma — Sangoma Switchvox SQL Injection Vulnerability Patch This Cycle
CVSS9.3 (NVD)EPSS95+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#13 75 Urgent CVE-2026-65400 Overdue by 17 daysCISA KEV Apple — Apple macOS Improper Authentication Vulnerability Patch This Cycle
CVSS9.8 (NVD)EPSS95+KEV since2026-08-18

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#14 75 Urgent CVE-2022-0995 CISA deadline in 2 daysCISA KEV Linux — Linux Kernel Out-of-Bounds Write Vulnerability Patch This Cycle
CVSS7.8 (NVD)EPSS95+KEV since2026-08-26

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#15 75 Urgent CVE-2015-3246 CISA deadline in 2 daysCISA KEV Red Hat — Red Hat Libuser Race Condition Vulnerability Patch This Cycle
CVSS5.1 (NVD)EPSS94+KEV since2026-08-26

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#16 75 Urgent CVE-2026-82329 Overdue by 2 daysCISA KEV JFrog — JFrog Artifactory Improper Authentication Vulnerability Patch This Cycle
CVSS9.8 (NVD)EPSS94+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#17 75 Urgent CVE-2015-5287 CISA deadline in 2 daysCISA KEV Red Hat — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability Patch This Cycle
CVSS7.8 (NVD)EPSS91+KEV since2026-08-26

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#18 75 Urgent CVE-2026-20349 Overdue by 24 daysCISA KEV Cisco — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability Patch This Cycle
CVSS8.6 (Cisco est.)EPSS81+KEV since2026-08-11

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#19 75 Urgent CVE-2026-49869 Overdue by 2 daysCISA KEV Kestra — Kestra OSS OS Command Injection Vulnerability Patch This Cycle
CVSS10.0 (NVD)EPSS78+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#20 75 Urgent CVE-2026-72530 Overdue by 4 daysCISA KEV TrueConf — TrueConf Server Code Injection Vulnerability Patch This Cycle
CVSS9.5 (NVD)EPSS77+KEV since2026-08-20

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#21 75 Urgent CVE-2026-83549 Overdue by 2 daysCISA KEV SonicWall — SonicWall SMA1000 Appliances OS Command Injection Vulnerability Patch This Cycle
CVSS7.8 (NVD)EPSS74+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#22 75 Urgent CVE-2026-81578 CISA deadline in 7 daysCISA KEV PaperCut — PaperCut NG/MF Missing Authentication for Critical Function Vulnerability Patch This Cycle
CVSS8.8 (NVD)EPSS74+KEV since2026-08-31

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#23 75 Urgent CVE-2026-8452 Overdue by 9 daysCISA KEV Citrix — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability Patch This Cycle
CVSS8.8 (NVD)EPSS74+KEV since2026-08-26

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#24 75 Urgent CVE-2026-72529 Overdue by 15 daysCISA KEV TrueConf — TrueConf Server Missing Authentication for Critical Function Vulnerability Patch This Cycle
CVSS9.3 (NVD)EPSS73+KEV since2026-08-20

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#25 75 Urgent CVE-2026-85046 CISA deadline in 11 daysCISA KEV Google — Google Chromium V8 Type Confusion Vulnerability Patch This Cycle
CVSS7.5 (Chrome)EPSS65+KEV since2026-09-04

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#26 75 Urgent CVE-2026-59822 CISA deadline in 9 daysCISA KEV BerriAI — BerriAI LiteLLM Improper Authentication Vulnerability Patch This Cycle
CVSS8.8 (NVD)EPSS56+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#27 75 Urgent CVE-2026-83548 Overdue by 2 daysCISA KEV SonicWall — SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability Patch This Cycle
CVSS10.0 (NVD)EPSS51+KEV since2026-09-02

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#28 75 Urgent CVE-2026-66384 CISA deadline in 3 daysCISA KEV JFrog — JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability Patch This Cycle
CVSS5.3 (NVD)EPSS45+KEV since2026-08-27

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

#29 75 Urgent CVE-2026-53362 Overdue by 8 daysCISA KEV Linux — Linux Kernel Unspecified Vulnerability Patch This Cycle
CVSS7.8 (NVD)EPSS41+KEV since2026-08-27

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.