Likely next
As of , 24 CVEs published in the last year have an EPSS score of 0.50 or more and are not on CISA's list of exploited vulnerabilities. EPSS is a prediction, not evidence of exploitation.
These CVEs are not known to be exploited. EPSS, from FIRST, scores every published CVE by the chance of exploitation activity in the next 30 days. We list the 100 highest scores among CVEs published in the last 365 days that CISA has not listed. They have no page of their own here: each links its CVE record.
| # | CVE | Product | Published | EPSS |
|---|---|---|---|---|
| 1 | CVE-2025-66516Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected | Apache Software Foundation Apache Tika core | 0.89 | |
| 2 | CVE-2026-21858n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling | n8n-io n8n | 0.78 | |
| 3 | CVE-2025-6389Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback | Sneeit Sneeit Framework | 0.76 | |
| 4 | CVE-2025-11749AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation | tigroumeow AI Engine – The Chatbot, AI Framework & MCP for WordPress | 0.75 | |
| 5 | CVE-2026-22200osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read | Enhancesoft osTicket | 0.74 | |
| 6 | CVE-2026-2041Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios Host | 0.74 | |
| 7 | CVE-2026-2043Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability | Nagios Host | 0.74 | |
| 8 | CVE-2025-34299Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload | Monsta Limited of New Zealand Monsta FTP | 0.73 | |
| 9 | CVE-2025-40553SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | SolarWinds Web Help Desk | 0.68 | |
| 10 | CVE-2025-13486Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form | hwk-fr Advanced Custom Fields: Extended | 0.68 | |
| 11 | CVE-2026-23744REC in MCPJam inspector due to HTTP Endpoint exposes | MCPJam inspector | 0.68 | |
| 12 | CVE-2025-55184A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1… | Meta react-server-dom-webpack | 0.67 | |
| 13 | CVE-2025-55315ASP.NET Security Feature Bypass Vulnerability | Microsoft ASP.NET Core 2.3 | 0.66 | |
| 14 | CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled | Apache Software Foundation Apache Tomcat | 0.64 | |
| 15 | CVE-2025-55183An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and… | Meta react-server-dom-webpack | 0.64 | |
| 16 | CVE-2025-62168Squid vulnerable to information disclosure via authentication credential leakage in error handling | squid-cache squid | 0.63 | |
| 17 | CVE-2026-0740Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload | SaturdayDrive Ninja Forms - File Uploads | 0.63 | |
| 18 | CVE-2025-11833Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure | saadiqbal Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 0.61 | |
| 19 | CVE-2025-40554SolarWinds Web Help Desk Authentication Bypass Vulnerability | SolarWinds Web Help Desk | 0.61 | |
| 20 | CVE-2026-19478Improper Control of Generation of Code ('Code Injection') in GitLab | GitLab GitLab | 0.60 | |
| 21 | CVE-2025-12420Unauthenticated Privilege Escalation in ServiceNow AI Platform | ServiceNow Now Assist AI Agents | 0.53 | |
| 22 | CVE-2026-10523An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to… | ivanti Sentry | 0.53 | |
| 23 | CVE-2025-15467Stack buffer overflow in CMS (Auth)EnvelopedData parsing | OpenSSL OpenSSL | 0.52 | |
| 24 | CVE-2025-40552SolarWinds Web Help Desk Authentication Bypass Vulnerability | SolarWinds Web Help Desk | 0.52 |