Vulnerabilities being actively exploited in the wild right now, plus CVEs with public proof-of-concept code. Updated every 4 hours from CISA KEV and NVD.
| CVE / ID | Title | Severity | CVSS | EPSS | Why urgent | Source | Date |
|---|---|---|---|---|---|---|---|
| CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | HIGH | — | 99% | KEV — actively exploited PoC public EPSS 99%ile | CISA-KEV | 2026-08-04 |
| CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu | HIGH | 8.2 | 83% | KEV — actively exploited EPSS 83%ile | NVD | 2026-08-02 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | HIGH | — | 78% | KEV — actively exploited EPSS 78%ile | CISA-KEV | 2026-08-04 |
| CVE-2026-18556 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. | HIGH | 8.2 | 19% | KEV — actively exploited EPSS 19%ile | NVD | 2026-08-01 |
| CVE-2026-20316 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti | MEDIUM | 5.3 | 53% | KEV — actively exploited EPSS 53%ile | NVD | 2026-07-29 |
| CVE / ID | Title | Severity | CVSS | EPSS | Why urgent | Source | Date |
|---|---|---|---|---|---|---|---|
| CVE-2025-53770 | Microsoft SharePoint Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC public EPSS 100%ile | Microsoft | 2025-07-08 |
| CVE-2026-41089 | Windows Netlogon Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC public EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100% | PoC public EPSS 100%ile | Microsoft | 2026-07-14 |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-04-14 |
| CVE-2022-41903 | Integer overflow in `git archive` `git log --format` leading to RCE in git | CRITICAL | 9.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2023-01-10 |
| CVE-2024-1874 | Command injection via array-ish $command parameter of proc_open() | CRITICAL | 9.4 | 98% | PoC public EPSS 98%ile | Microsoft | 2024-04-09 |
| CVE-2024-32002 | GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote | CRITICAL | 9.0 | 98% | PoC public EPSS 98%ile | Microsoft | 2024-05-14 |
| CVE-2024-4323 | Fluent Bit Memory Corruption Vulnerability | CRITICAL | 9.8 | 98% | PoC public EPSS 98%ile | Microsoft | 2024-05-14 |
| CVE-2024-24576 | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | CRITICAL | 10.0 | 97% | PoC public EPSS 97%ile | Microsoft | 2024-04-09 |
| CVE-2025-29972 | Azure Storage Resource Provider Spoofing Vulnerability | CRITICAL | 9.9 | 85% | PoC public EPSS 85%ile | Microsoft | 2025-05-13 |
| CVE-2026-43284 | xfrm: esp: avoid in-place decrypt on shared skb frags | HIGH | 7.8 | 100% | PoC public EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2026-43500 | rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present | HIGH | 7.8 | 100% | PoC public EPSS 100%ile | Microsoft | 2026-05-12 |
| CVE-2024-27316 | Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames | HIGH | 7.5 | 100% | PoC public EPSS 100%ile | Microsoft | 2024-04-09 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 100% | PoC public EPSS 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-2961 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 | HIGH | 7.3 | 100% | PoC public EPSS 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-27983 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets | HIGH | 8.2 | 100% | PoC public EPSS 100%ile | Microsoft | 2024-04-09 |
| CVE-2023-50868 | MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | HIGH | 7.5 | 100% | PoC public EPSS 100%ile | Microsoft | 2024-06-11 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | HIGH | 7.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-01-13 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | HIGH | 8.1 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.0 | 99% | PoC public EPSS 99%ile | Microsoft | 2024-06-11 |
| CVE-2023-21768 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | HIGH | 7.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2023-01-10 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2023-21742 | Microsoft SharePoint Server Remote Code Execution Vulnerability | HIGH | 8.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2023-01-10 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen | HIGH | 7.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2023-01-10 |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | HIGH | 7.5 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-06-09 |
| CVE-2026-23918 | Apache HTTP Server: http2: double free and possible RCE on early reset | HIGH | 8.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2026-05-12 |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | HIGH | 8.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2024-04-09 |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | HIGH | 8.8 | 99% | PoC public EPSS 99%ile | Microsoft | 2023-01-10 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98% | PoC public EPSS 98%ile | Microsoft | 2026-06-09 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 98% | PoC public EPSS 98%ile | Microsoft | 2024-06-11 |
| CVE-2024-26230 | Windows Telephony Server Elevation of Privilege Vulnerability | HIGH | 7.8 | 98% | PoC public EPSS 98%ile | Microsoft | 2024-04-09 |
| CVE-2025-30397 | Scripting Engine Memory Corruption Vulnerability | HIGH | 7.5 | 97% | PoC public EPSS 97%ile | Microsoft | 2025-05-13 |
| CVE-2025-54918 | Windows NTLM Elevation of Privilege Vulnerability | HIGH | 8.8 | 97% | PoC public EPSS 97%ile | Microsoft | 2025-09-09 |
| CVE-2025-55234 | Windows SMB Elevation of Privilege Vulnerability | HIGH | 8.8 | 97% | PoC public EPSS 97%ile | Microsoft | 2025-09-09 |
| CVE-2024-30085 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 96% | PoC public EPSS 96%ile | Microsoft | 2024-06-11 |
| CVE-2024-26218 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 96% | PoC public EPSS 96%ile | Microsoft | 2024-04-09 |
| CVE-2025-40775 | DNS message with invalid TSIG causes an assertion failure | HIGH | 7.5 | 96% | PoC public EPSS 96%ile | Microsoft | 2025-05-13 |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95% | PoC public EPSS 95%ile | Microsoft | 2026-06-09 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 95% | PoC public EPSS 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 95% | PoC public EPSS 95%ile | Microsoft | 2026-05-12 |
| CVE-2024-26229 | Windows CSC Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 95% | PoC public EPSS 95%ile | Microsoft | 2024-04-09 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | HIGH | 8.8 | 95% | PoC public EPSS 95%ile | Microsoft | 2026-05-12 |
| CVE-2025-41244 | VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-202 | HIGH | 7.8 | 94% | PoC public EPSS 94%ile | Microsoft | 2025-09-09 |
| CVE-2026-46300 | net: skbuff: preserve shared-frag marker during coalescing | HIGH | 7.8 | 94% | PoC public EPSS 94%ile | Microsoft | 2026-05-12 |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 94% | PoC public EPSS 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | HIGH | 7.8 | 93% | PoC public EPSS 93%ile | Microsoft | 2026-04-14 |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | HIGH | 7.8 | 92% | PoC public EPSS 92%ile | Microsoft | 2024-05-14 |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 92% | PoC public EPSS 92%ile | Microsoft | 2026-01-13 |
| CVE-2023-21752 | Windows Backup Service Elevation of Privilege Vulnerability | HIGH | 7.1 | 92% | PoC public EPSS 92%ile | Microsoft | 2023-01-10 |
| CVE-2026-40369 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 7.8 | 91% | PoC public EPSS 91%ile | Microsoft | 2026-05-12 |
| CVE-2025-53020 | Apache HTTP Server: HTTP/2 DoS by Memory Increase | HIGH | 7.5 | 91% | PoC public EPSS 91%ile | Microsoft | 2025-07-08 |
| CVE-2025-32023 | Redis allows out of bounds writes in hyperloglog commands leading to RCE | HIGH | 7.0 | 89% | PoC public EPSS 89%ile | Microsoft | 2025-07-08 |
| CVE-2023-38709 | Apache HTTP Server: HTTP response splitting | HIGH | 7.3 | 89% | PoC public EPSS 89%ile | Microsoft | 2024-04-09 |
| CVE-2025-54110 | Windows Kernel Elevation of Privilege Vulnerability | HIGH | 8.8 | 89% | PoC public EPSS 89%ile | Microsoft | 2025-09-09 |
| CVE-2023-0266 | Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel | HIGH | 7.8 | 89% | PoC public EPSS 89%ile | Microsoft | 2023-01-10 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 88% | PoC public EPSS 88%ile | Microsoft | 2026-07-14 |
| CVE-2026-50343 | Microsoft Install Service Elevation of Privilege Vulnerability | HIGH | 7.8 | 88% | PoC public EPSS 88%ile | Microsoft | 2026-07-14 |
| CVE-2026-46242 | eventpoll: fix ep_remove struct eventpoll / struct file UAF | HIGH | 7.8 | 87% | PoC public EPSS 87%ile | Microsoft | 2026-05-12 |
| CVE-2026-5172 | CVE-2026-5172 | HIGH | 7.3 | 84% | PoC public EPSS 84%ile | Microsoft | 2026-05-12 |
| CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | MEDIUM | 6.5 | 100% | PoC public EPSS 100%ile | Microsoft | 2025-07-08 |
| CVE-2024-30043 | Microsoft SharePoint Server Information Disclosure Vulnerability | MEDIUM | 6.5 | 99% | PoC public EPSS 99%ile | Microsoft | 2024-05-14 |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | MEDIUM | 6.8 | 91% | PoC public EPSS 91%ile | Microsoft | 2026-06-09 |
Updated 2026-08-04. KEV source: CISA KEV catalog. PoC data aggregated from Exploit-DB and GitHub advisories. JSON API available.