Threat radar
Exploited in the wild, and what is most likely next
Two lists from public vulnerability sources: what an authority has confirmed is being exploited, and what a published model rates as most likely to be exploited soon. They are different claims and the page keeps them apart.
Confirmed exploited in the wild
Every entry below is on CISA’s Known Exploited Vulnerabilities catalog, which means a government authority has published evidence of exploitation. This is the only list here that reports a fact rather than a forecast. Most recent first.
| CVE | What it is | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | not scored | 0.5% | 21 Aug 2026 |
CVE-2026-69836 | Microsoft Entra ID Deserialization of Untrusted Data Vulnerability | not scored | 1.4% | 21 Aug 2026 |
CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | not scored | 0.3% | 20 Aug 2026 |
CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | not scored | 0.3% | 20 Aug 2026 |
CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | not scored | 1.1% | 18 Aug 2026 |
CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | not scored | 4.0% | 18 Aug 2026 |
CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | not scored | 0.5% | 18 Aug 2026 |
CVE-2026-64849 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTT | 9.3 | 0.3% | 17 Aug 2026 |
CVE-2026-63505 | Exploit Available: Probo 0.222.2 - IDOR | not scored | no score | 17 Aug 2026 |
CVE-2026-58058 | Exploit Available: Nmap 7.99 - Extension Header Integer Underflow | not scored | 0.3% | 17 Aug 2026 |
CVE-2026-55584 | Exploit Available: phpSysInfo 3.4.5 - IP Allowlist Bypass | not scored | no score | 17 Aug 2026 |
CVE-2026-55780 | Exploit Available: NanaZip 6.5 - DoS | not scored | 0.1% | 17 Aug 2026 |
CVE-2026-72898 | Metabase SQL Injection Vulnerability | not scored | 1.1% | 11 Aug 2026 |
CVE-2026-61459 | Exploit Available: mcp-server-kubernetes 3.8.x - Argument Injection | not scored | 0.5% | 11 Aug 2026 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | not scored | 0.4% | 11 Aug 2026 |
Highest exploitation probability, not yet in the catalog
Ranked by EPSS, FIRST’s published model of the probability that a vulnerability will be exploited in the next 30 days. Entries already on the CISA catalog are excluded, so this list is what the model is pointing at rather than what is already confirmed.
| CVE | What it is | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2021-45105 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u | 5.9 | 100.0% | 18 Dec 2021 |
CVE-2014-3566 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB | 3.4 | 100.0% | 15 Oct 2014 |
CVE-2023-50387 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow r | 7.5 | 100.0% | 14 Feb 2024 |
CVE-2014-0195 | The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, | 6.8 | 100.0% | 05 Jun 2014 |
CVE-2014-3704 | The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not | 7.5 | 100.0% | 16 Oct 2014 |
CVE-2015-7297 | SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary | 7.5 | 100.0% | 29 Oct 2015 |
CVE-2012-1456 | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Anti | 4.3 | 99.9% | 21 Mar 2012 |
CVE-2025-53771 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp | 6.5 | 99.9% | 20 Jul 2025 |
CVE-2024-29826 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an | 8.8 | 99.9% | 31 May 2024 |
CVE-2024-29825 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an | 8.8 | 99.9% | 31 May 2024 |
CVE-2024-29823 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an | 8.8 | 99.9% | 31 May 2024 |
CVE-2015-4000 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a | 3.7 | 99.9% | 21 May 2015 |
CVE-2020-13379 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This v | 8.2 | 99.9% | 03 Jun 2020 |
CVE-2017-12635 | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible | 9.8 | 99.8% | 14 Nov 2017 |
CVE-2017-8917 | SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL | 9.8 | 99.8% | 17 May 2017 |
Why neither list is ordered by CVSS
CVSS scores how bad a vulnerability would be if exploited. It does not estimate whether anyone is exploiting it. Ordering work by CVSS alone is what sends a team to a 9.8 nobody has ever attacked ahead of a 7.5 being used today — and it is why both tables above show CVSS as a column rather than as the sort order.
Exploit Hound ranks remediation the same way, over an estate rather than over a corpus: what an action removes, weighted by whether the thing is exposed, reachable and actually being exploited. See how that is ranked →
These are the vulnerabilities. The question is which ones reach you.
A catalog cannot tell you that. Point Exploit Hound at the assets you are authorized to assess and it will tell you which of these are present, which are reachable, and what removes the most exposure first.