Likely next

As of , 24 CVEs published in the last year have an EPSS score of 0.50 or more and are not on CISA's list of exploited vulnerabilities. EPSS is a prediction, not evidence of exploitation.

These CVEs are not known to be exploited. EPSS, from FIRST, scores every published CVE by the chance of exploitation activity in the next 30 days. We list the 100 highest scores among CVEs published in the last 365 days that CISA has not listed. They have no page of their own here: each links its CVE record.

#CVEProductPublishedEPSS
1CVE-2025-66516Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedApache Software Foundation Apache Tika core0.89
2CVE-2026-21858n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handlingn8n-io n8n0.78
3CVE-2025-6389Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callbackSneeit Sneeit Framework0.76
4CVE-2025-11749AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalationtigroumeow AI Engine – The Chatbot, AI Framework & MCP for WordPress0.75
5CVE-2026-22200osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File ReadEnhancesoft osTicket0.74
6CVE-2026-2041Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution VulnerabilityNagios Host0.74
7CVE-2026-2043Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution VulnerabilityNagios Host0.74
8CVE-2025-34299Monsta FTP <= 2.11 Unauthenticated Arbitrary File UploadMonsta Limited of New Zealand Monsta FTP0.73
9CVE-2025-40553SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution VulnerabilitySolarWinds Web Help Desk0.68
10CVE-2025-13486Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_formhwk-fr Advanced Custom Fields: Extended0.68
11CVE-2026-23744REC in MCPJam inspector due to HTTP Endpoint exposesMCPJam inspector0.68
12CVE-2025-55184A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1…Meta react-server-dom-webpack0.67
13CVE-2025-55315ASP.NET Security Feature Bypass VulnerabilityMicrosoft ASP.NET Core 2.30.66
14CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabledApache Software Foundation Apache Tomcat0.64
15CVE-2025-55183An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and…Meta react-server-dom-webpack0.64
16CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache squid0.63
17CVE-2026-0740Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File UploadSaturdayDrive Ninja Forms - File Uploads0.63
18CVE-2025-11833Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosuresaadiqbal Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App0.61
19CVE-2025-40554SolarWinds Web Help Desk Authentication Bypass VulnerabilitySolarWinds Web Help Desk0.61
20CVE-2026-19478Improper Control of Generation of Code ('Code Injection') in GitLabGitLab GitLab0.60
21CVE-2025-12420Unauthenticated Privilege Escalation in ServiceNow AI PlatformServiceNow Now Assist AI Agents0.53
22CVE-2026-10523An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to…ivanti Sentry0.53
23CVE-2025-15467Stack buffer overflow in CMS (Auth)EnvelopedData parsingOpenSSL OpenSSL0.52
24CVE-2025-40552SolarWinds Web Help Desk Authentication Bypass VulnerabilitySolarWinds Web Help Desk0.52