AL
Analyst accessPublic view · sign in
First-party telemetry

No first-party sensor telemetry configured.

Unknown ≠ not observed
RefineAll threatsAcceleratingKEVConfirmedNew exploit50 results · relevance then recency
01
progress·connection manager for objectscale

CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Public exploitationKEV
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat58.4/ 100
02
checkpoint·multi-domain security management

CVE-2026-16232

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Public exploitationKEV
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat56.7/ 100
03
·

CVE-2026-18577

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityTECHNICAL DETAILS
VelocitySTABLE
VTP threat50.8/ 100
04
microsoft·exchange server

CVE-2021-34473

Microsoft Exchange Server Remote Code Execution Vulnerability

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
05
microsoft·exchange server

CVE-2021-34523

Microsoft Exchange Server Elevation of Privilege Vulnerability

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
06
microsoft·azure automation state configuration

CVE-2021-38647

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
07
microsoft·windows 10 1507

CVE-2021-34527

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting) UpdatePromptSettings = 0 (DWORD) or not defined (default setting) Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design. UPDATE July 6, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. See also KB5005010: Restricting installation of new printer drivers after applying the July 6, 2021 updates. Note that the security updates released on and after July 6, 2021 contain protections for CVE-2021-1675 and the additional remote code execution exploit in the Windows Print Spooler service known as “PrintNightmare”, documented in CVE-2021-34527.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
08
·

CVE-2024-27199

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
09
Adobe·Commerce and Magento Open Source

CVE-2024-34102

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
10
Fortinet·FortiOS

CVE-2018-13379

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
11
Atlassian·Confluence Server and Data Center

CVE-2021-26084

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
12
Ivanti·Pulse Connect Secure

CVE-2019-11510

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
13
Zyxel·Multiple Firewalls

CVE-2022-30525

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
14
Ivanti·Virtual Traffic Manager

CVE-2024-7593

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
15
Webmin·Webmin

CVE-2019-15107

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
16
Ivanti·Endpoint Manager Mobile (EPMM)

CVE-2023-35078

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
17
VMware·vCenter Server

CVE-2021-22005

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
18
Microsoft·Exchange Server

CVE-2021-31207

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
19
PHP Group·PHP

CVE-2024-4577

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
20
Sophos·Firewall

CVE-2022-1040

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
21
Microsoft·SharePoint

CVE-2025-53770

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
22
Elastic·Elasticsearch

CVE-2015-1427

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
23
Atlassian·Confluence Server

CVE-2021-26085

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
24
Fortra·GoAnywhere MFT

CVE-2023-0669

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
25
TP-Link·Archer AX21

CVE-2023-1389

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
26
Ivanti·Connect Secure, Policy Secure, and Neurons

CVE-2024-21893

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
27
Microsoft·SMBv3

CVE-2020-0796

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
28
VMware Tanzu·Spring Cloud

CVE-2022-22963

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
29
Ignite Realtime·Openfire

CVE-2023-32315

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
30
Microsoft·Office

CVE-2017-11882

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
31
Adobe·Flash Player

CVE-2014-0497

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
32
Microsoft·Office and WordPad

CVE-2017-0199

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
33
Cacti·Cacti

CVE-2022-46169

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
34
VMware·vCenter Server

CVE-2021-21985

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
35
·

CVE-2026-10520

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
36
Adobe·Flash Player

CVE-2015-3113

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
37
·

CVE-2024-3273

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
38
·

CVE-2025-22457

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
39
IBM·Aspera Faspex

CVE-2022-47986

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
40
Langflow·Langflow

CVE-2025-3248

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
41
Adobe·ColdFusion

CVE-2018-15961

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
42
Microsoft·SharePoint

CVE-2025-49706

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
43
Oracle·WebLogic Server

CVE-2020-14882

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
44
Zoho·ManageEngine

CVE-2022-47966

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
45
F5·BIG-IP

CVE-2020-5902

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
46
Microsoft·SharePoint

CVE-2025-49704

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
47
Cisco·HyperFlex HX

CVE-2021-1497

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
48
Oracle·WebLogic Server

CVE-2019-2725

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
49
Google·Chromium WebP

CVE-2023-4863

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100
50
Ivanti·Connect Secure and Policy Secure

CVE-2023-46805

Metadata pending authoritative retrieval.

Public exploitationKEV
Exploit maturityNONE KNOWN
VelocitySTABLE
VTP threat50.0/ 100