Live data
Exploited vulnerabilities, page 8
Entries 351 to 400
1,739 in total| Product | What an attacker gains | Concerns | Severity | Added |
|---|---|---|---|---|
PaperCut NG/MFCVE-2023-2533 | Request forgery | Business | 8.8 | |
Google ChromiumCVE-2025-6558 | Improper access control | Everyone | 8.8 | |
CrushFTPCVE-2025-54309 | Vulnerability | Business | 9.8 | |
Microsoft SharePointCVE-2025-49706 | Authentication bypassused by ransomware | Business | 6.5 | |
Microsoft SharePointCVE-2025-49704 | Code executionused by ransomware | Business | 8.8 | |
SysAid On-PremCVE-2025-2776 | XML external entity | Business | 9.8 | |
SysAid On-PremCVE-2025-2775 | XML external entity | Business | 7.5 | |
Microsoft SharePointCVE-2025-53770 | Code executionused by ransomware | Business | 9.8 | |
Fortinet FortiWebCVE-2025-25257 | SQL injection | Business | 9.8 | |
Wing FTP ServerCVE-2025-47812 | Vulnerability | Business | 10.0 | |
Citrix NetScaler ADC and GatewayCVE-2025-5777 | Information disclosureused by ransomware | Business | 9.3 | |
Synacor Zimbra Collaboration Suite (ZCS)CVE-2019-9621 | Server-side request forgery | Business | 7.5 | |
Rails Ruby on RailsCVE-2019-5418 | File access | Business | 7.5 | |
PHPMailerCVE-2016-10033 | Code execution | Business | 9.8 | |
Looking Glass Multi-Router Looking Glass (MRLG)CVE-2014-3931 | Memory corruption | Home network | 9.8 | |
Google Chromium V8CVE-2025-6554 | Memory corruption | Everyone | 8.1 | |
TeleMessage TM SGNLCVE-2025-48928 | Memory corruption | Business | 4.0 | |
TeleMessage TM SGNLCVE-2025-48927 | Memory corruption | Business | 5.3 | |
Citrix NetScaler ADC and GatewayCVE-2025-6543 | Memory corruption | Business | 9.2 | |
AMI MegaRAC SPxCVE-2024-54085 | Authentication bypass | Business | 10.0 | |
D-Link DIR-859 RouterCVE-2024-0769 | File access | Home network | 9.8 | |
Fortinet FortiOSCVE-2019-6693 | Authentication bypassused by ransomware | Business | 6.5 | |
Linux KernelCVE-2023-0386 | Vulnerability | Everyone | 7.8 | |
Apple productsCVE-2025-43200 | Vulnerability | Everyone | 4.2 | |
TP-Link Multiple RoutersCVE-2023-33538 | Code execution | Home network | 8.8 | |
Microsoft WindowsCVE-2025-33053 | File access | Everyone | 8.8 | |
Wazuh ServerCVE-2025-24016 | Code execution | Business | 9.9 | |
Erlang/OTPCVE-2025-32433 | Authentication bypass | Business | 10.0 | |
Roundcube WebmailCVE-2024-42009 | Cross-site scripting | Business | 9.3 | |
Google Chromium V8CVE-2025-5419 | Information disclosure | Everyone | 8.8 | |
Qualcomm productsCVE-2025-27038 | Memory corruption | Everyone | 7.5 | |
Qualcomm productsCVE-2025-21480 | Improper access control | Everyone | 8.6 | |
Qualcomm productsCVE-2025-21479 | Improper access control | Everyone | 8.6 | |
ConnectWise ScreenConnectCVE-2025-3935 | Authentication bypass | Business | 7.2 | |
Craft CMSCVE-2025-35939 | Vulnerability | Business | 6.9 | |
Craft CMSCVE-2024-56145 | Code execution | Business | 9.3 | |
ASUS RT-AX55 RoutersCVE-2023-39780 | Code execution | Home network | 8.8 | |
ASUS RoutersCVE-2021-32030 | Authentication bypass | Home network | 9.8 | |
Samsung MagicINFO 9 ServerCVE-2025-4632 | File access | Business | 9.8 | |
Ivanti Endpoint Manager Mobile (EPMM)CVE-2025-4428 | Code execution | Business | 8.8 | |
Ivanti Endpoint Manager Mobile (EPMM)CVE-2025-4427 | Authentication bypass | Business | 7.5 | |
Srimax Output MessengerCVE-2025-27920 | File access | Business | 8.8 | |
Synacor Zimbra Collaboration Suite (ZCS)CVE-2024-27443 | Cross-site scripting | Business | 6.1 | |
MDaemon Email ServerCVE-2024-11182 | Cross-site scripting | Business | 5.3 | |
ZKTeco BioTimeCVE-2023-38950 | File access | Business | 7.5 | |
SAP NetWeaverCVE-2025-42999 | Code executionused by ransomware | Business | 9.1 | |
DrayTek Vigor RoutersCVE-2024-12987 | Code execution | Home network | 6.9 | |
Fortinet productsCVE-2025-32756 | Memory corruption | Everyone | 9.8 | |
Microsoft WindowsCVE-2025-32709 | Memory corruption | Everyone | 7.8 | |
Microsoft WindowsCVE-2025-32706 | Memory corruption | Everyone | 7.8 |
Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC
Severity (CVSS): NIST NVD