KEVIntel
1.1%
actively
exploited

Focus on what’s exploited

Out of 349,964 known CVEs, only 1.1% show real-world exploitation signals.

Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.

3,823
Total Known exploited
279
Added this week

Search

Added
Exploitability

Type to search. Filters apply instantly.

CVE Severity Title
CVE-2021-25298 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-25297 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-25296 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-32648 8.2 High
Account Takeover in Octobercms
Remote Low complexity No user interaction
CVE-2020-13927 9.8 Critical
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...
Remote Low complexity No user interaction
CVE-2020-11978 8.8 High
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...
Remote Low complexity No user interaction
CVE-2020-14864 7.5 High
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...
Remote Low complexity No user interaction
CVE-2021-22991 9.8 Critical
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...
Remote Low complexity No user interaction
CVE-2021-21315 7.1 High
Command Injection Vulnerability
Low complexity No user interaction
CVE-2021-21975 7.5 High
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...
Malware Remote Low complexity No user interaction
CVE-2021-33766 7.3 High
Microsoft Exchange Server Information Disclosure Vulnerability
Remote Low complexity No user interaction
CVE-2021-40870 9.8 Critical
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which...
Remote Low complexity No user interaction
CVE-2021-25298 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-25297 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-25296 8.8 High
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote Low complexity No user interaction
CVE-2021-32648 8.2 High
Account Takeover in Octobercms
Remote Low complexity No user interaction
CVE-2022-21894 4.4 Medium
Secure Boot Security Feature Bypass Vulnerability
Low complexity No user interaction
CVE-2013-3900 5.5 Medium
WinVerifyTrust Signature Validation Vulnerability
Low complexity
CVE-2021-27860 9.8 Critical
Arbitrary file upload vulnerability in FatPipe software
Remote Low complexity No user interaction
CVE-2019-7609 10.0 Critical
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...
Remote Low complexity No user interaction
CVE-2017-1000486 9.8 Critical
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Remote Low complexity No user interaction
CVE-2015-7450 9.8 Critical
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow...
Remote Low complexity No user interaction
CVE-2019-10149 9.0 Critical
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...
Remote No user interaction
CVE-2019-1579 8.1 High
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or...
Malware Remote No user interaction
CVE-2018-13383 4.3 Medium
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy...
Malware Remote Low complexity No user interaction
Displaying vulnerabilities 3001 - 3025 of 3823 in total