Live data
Exploited vulnerabilities, page 6
Entries 251 to 300
1,739 in total| Product | What an attacker gains | Concerns | Severity | Added |
|---|---|---|---|---|
Cisco Unified Communications ManagerCVE-2026-20045 | Code execution | Business | 9.8 | |
Microsoft WindowsCVE-2026-20805 | Information disclosure | Everyone | 5.5 | |
GogsCVE-2025-8110 | File access | Business | 8.7 | |
Hewlett Packard Enterprise (HPE) OneViewCVE-2025-37164 | Code execution | Business | 9.8 | |
Microsoft OfficeCVE-2009-0556 | Code execution | Everyone | 8.8 | |
MongoDB and MongoDB ServerCVE-2025-14847 | Memory corruption | Business | 8.7 | |
Digiever DS-2105 ProCVE-2023-52163 | Improper access control | Business | 8.8 | |
WatchGuard FireboxCVE-2025-14733 | Vulnerabilityused by ransomware | Business | 9.3 | |
ASUS Live UpdateCVE-2025-59374 | Vulnerability | Home network | 9.3 | |
SonicWall SMA1000 applianceCVE-2025-40602 | Improper access control | Business | 6.6 | |
Cisco productsCVE-2025-20393 | Improper access control | Everyone | 10.0 | |
Fortinet productsCVE-2025-59718 | Security bypass | Everyone | 9.8 | |
Apple productsCVE-2025-43529 | Memory corruption | Everyone | 8.8 | |
Gladinet CentreStack and TriofoxCVE-2025-14611 | File access | Business | 7.1 | |
Google ChromiumCVE-2025-14174 | Vulnerability | Everyone | 8.8 | |
Sierra Wireless AirLink ALEOSCVE-2018-4063 | File access | Business | 8.8 | |
OSGeo GeoServerCVE-2025-58360 | XML external entity | Business | 9.8 | |
Microsoft WindowsCVE-2025-62221 | Memory corruption | Everyone | 7.8 | |
RARLAB WinRARCVE-2025-6218 | File access | Everyone | 7.8 | |
Array Networks ArrayOS AGCVE-2025-66644 | Code execution | Business | 9.8 | |
D-Link RoutersCVE-2022-37055 | Memory corruption | Home network | 9.8 | |
Meta React Server ComponentsCVE-2025-55182 | Code executionused by ransomware | Business | 10.0 | |
OpenPLC ScadaBRCVE-2021-26828 | File access | Business | 8.8 | |
Android FrameworkCVE-2025-48633 | Information disclosure | Everyone | 5.5 | |
Android FrameworkCVE-2025-48572 | Privilege escalation | Everyone | 7.8 | |
OpenPLC ScadaBRCVE-2021-26829 | Cross-site scripting | Business | 5.4 | |
Oracle Fusion MiddlewareCVE-2025-61757 | Authentication bypass | Business | 9.8 | |
Google Chromium V8CVE-2025-13223 | Memory corruption | Everyone | 8.8 | |
Fortinet FortiWebCVE-2025-58034 | Code execution | Business | 7.2 | |
Fortinet FortiWebCVE-2025-64446 | File access | Business | 9.8 | |
WatchGuard FireboxCVE-2025-9242 | Memory corruption | Business | 9.3 | |
Microsoft WindowsCVE-2025-62215 | Memory corruption | Everyone | 7.0 | |
Gladinet TriofoxCVE-2025-12480 | Improper access control | Business | 9.1 | |
Samsung Mobile DevicesCVE-2025-21042 | Memory corruption | Everyone | 9.8 | |
CWP Control Web PanelCVE-2025-48703 | Code execution | Business | 9.0 | |
Gladinet CentreStack and TriofoxCVE-2025-11371 | Vulnerability | Business | 7.5 | |
Broadcom VMware Aria Operations and VMware ToolsCVE-2025-41244 | Vulnerability | Business | 7.8 | |
XWiki PlatformCVE-2025-24893 | Code execution | Business | 9.8 | |
Dassault Systèmes DELMIA AprisoCVE-2025-6205 | Improper access control | Business | 9.1 | |
Dassault Systèmes DELMIA AprisoCVE-2025-6204 | Code execution | Business | 8.0 | |
Microsoft WindowsCVE-2025-59287 | Code execution | Everyone | 9.8 | |
Adobe Commerce and MagentoCVE-2025-54236 | Improper access control | Business | 9.1 | |
Motex LANSCOPE Endpoint ManagerCVE-2025-61932 | Security bypass | Business | 9.3 | |
Oracle E-Business SuiteCVE-2025-61884 | Server-side request forgeryused by ransomware | Business | 7.5 | |
Microsoft WindowsCVE-2025-33073 | Improper access control | Everyone | 8.8 | |
Kentico Xperience CMSCVE-2025-2747 | Authentication bypass | Business | 9.8 | |
Kentico Xperience CMSCVE-2025-2746 | Authentication bypass | Business | 9.8 | |
Apple productsCVE-2022-48503 | Code execution | Everyone | 8.8 | |
Adobe Experience Manager (AEM) FormsCVE-2025-54253 | Code execution | Business | 10.0 | |
Microsoft WindowsCVE-2025-59230 | Improper access control | Everyone | 7.8 |
Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC
Severity (CVSS): NIST NVD