Exploited, but EPSS says unlikely, page 2
As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 101 | CVE-2008-3431Insufficient Input Validation | Oracle VirtualBox | Patch soonVerified Exploit-DB entry | 0.07 | ||
| 102 | CVE-2002-0367Privilege Escalation | Microsoft Windows | Patch soonVerified Exploit-DB entry | 0.05 | ||
| 103 | CVE-2026-35616Improper Access Control | Fortinet FortiClient EMS | Patch soon | 0.09 | ||
| 104 | CVE-2025-43529Use-After-Free WebKit | Apple Multiple Products | Patch soon | 0.09 | ||
| 105 | CVE-2025-6558ANGLE and GPU Improper Input Validation | Google Chromium | Patch soon | 0.09 | ||
| 106 | CVE-2025-2783Sandbox Escape | Google Chromium Mojo | Patch soon | 0.09 | ||
| 107 | CVE-2022-23748Process Control | Audinate Dante Discovery | Patch soon | 0.09 | ||
| 108 | CVE-2023-42917WebKit Memory Corruption | Apple Multiple Products | Patch soon | 0.09 | ||
| 109 | CVE-2021-34486Event Tracing Privilege Escalation | Microsoft Windows | Patch soon | 0.09 | ||
| 110 | CVE-2018-0156Smart Install Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.09 | ||
| 111 | CVE-2022-20703Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.09 | ||
| 112 | CVE-2018-14558Command Injection | Tenda AC7, AC9, and AC10 Routers | Patch soon | 0.09 | ||
| 113 | CVE-2021-21206Use-After-Free | Google Chromium Blink | Patch soon | 0.09 | ||
| 114 | CVE-2021-30563Type Confusion | Google Chromium V8 | Patch soon | 0.09 | ||
| 115 | CVE-2026-42016Incorrect Authorization | JFrog Artifactory | Patch soon | 0.09 | ||
| 116 | CVE-2026-48710HTTP Request/Response Smuggling | Kludex Starlette | Patch soon | 0.07 | ||
| 117 | CVE-2026-20128Storing Passwords in a Recoverable Format | Cisco Catalyst SD-WAN Manager | Patch soon | 0.07 | ||
| 118 | CVE-2026-20805Information Disclosure | Microsoft Windows | Patch soon | 0.07 | ||
| 119 | CVE-2025-41244Privilege Defined with Unsafe Actions | Broadcom VMware Aria Operations and VMware Tools | Patch soon | 0.08 | ||
| 120 | CVE-2025-5419Out-of-Bounds Read and Write | Google Chromium V8 | Patch soon | 0.08 | ||
| 121 | CVE-2019-0344Deserialization of Untrusted Data | SAP Commerce Cloud | Patch soon | 0.07 | ||
| 122 | CVE-2024-38189Remote Code Execution | Microsoft Project | Patch soon | 0.08 | ||
| 123 | CVE-2024-38080Hyper-V Privilege Escalation | Microsoft Windows | Patch soon | 0.07 | ||
| 124 | CVE-2024-5274Type Confusion | Google Chromium V8 | Patch soon | 0.07 | ||
| 125 | CVE-2024-4671Visuals Use-After-Free | Google Chromium | Patch soon | 0.08 | ||
| 126 | CVE-2023-28434Security Feature Bypass | MinIO MinIO | Patch soon | 0.08 | ||
| 127 | CVE-2022-42856Type Confusion | Apple iOS | Patch soon | 0.09 | ||
| 128 | CVE-2022-3723Type Confusion | Google Chromium V8 | Patch soon | 0.08 | ||
| 129 | CVE-2019-0676Information Disclosure | Microsoft Internet Explorer | Patch soon | 0.08 | ||
| 130 | CVE-2012-2034Memory Corruption | Adobe Flash Player | Patch soon | 0.08 | ||
| 131 | CVE-2017-6744SNMP Remote Code Execution | Cisco IOS software | Patch soon | 0.07 | ||
| 132 | CVE-2017-12231Network Address Translation Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 133 | CVE-2017-12233Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 134 | CVE-2017-12234Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 135 | CVE-2017-12235for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 136 | CVE-2017-12237Internet Key Exchange Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.07 | ||
| 137 | CVE-2018-0154Integrated Services Module for VPN Denial-of-Service | Cisco IOS Software | Patch soon | 0.07 | ||
| 138 | CVE-2018-0155Catalyst Bidirectional Forwarding Detection Denial-of-Service | Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Patch soon | 0.08 | ||
| 139 | CVE-2018-0158IOS and XE Software Internet Key Exchange Memory Leak | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 140 | CVE-2018-0172Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 141 | CVE-2018-0173Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 142 | CVE-2018-0174IOS Software and Cisco IOS XE Software Improper Input Validation | Cisco IOS XE Software | Patch soon | 0.08 | ||
| 143 | CVE-2021-4102Use-After-Free | Google Chromium V8 | Patch soon | 0.08 | ||
| 144 | CVE-2020-0683Installer Privilege Escalation | Microsoft Windows | Patch soon | 0.08 | ||
| 145 | CVE-2020-1040vGPU Remote Code Execution | Microsoft Hyper-V RemoteFX | Patch soon | 0.07 | ||
| 146 | CVE-2020-6820Use-After-Free | Mozilla Firefox and Thunderbird | Patch soon | 0.07 | ||
| 147 | CVE-2021-1870WebKit Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.08 | ||
| 148 | CVE-2021-1879WebKit Cross-Site Scripting (XSS) | Apple iOS, iPadOS, and watchOS | Patch soon | 0.07 | ||
| 149 | CVE-2021-28310Privilege Escalation | Microsoft Win32k | Patch soon | 0.08 | ||
| 150 | CVE-2021-30554Use-After-Free | Google Chromium WebGL | Patch soon | 0.07 | ||
| 151 | CVE-2021-30713Unspecified | Apple macOS | Patch soon | 0.07 | ||
| 152 | CVE-2026-34486Missing Encryption of Sensitive Data | Apache Tomcat | Patch soon | 0.07 | ||
| 153 | CVE-2021-30952Integer Overflow or Wraparound | Apple Multiple Products | Patch soon | 0.07 | ||
| 154 | CVE-2025-62215Race Condition | Microsoft Windows | Patch soon | 0.06 | ||
| 155 | CVE-2025-24990Untrusted Pointer Dereference | Microsoft Windows | Patch soon | 0.06 | ||
| 156 | CVE-2024-38014Installer Improper Privilege Management | Microsoft Windows | Patch soon | 0.06 | ||
| 157 | CVE-2024-38106Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 158 | CVE-2023-7024Heap Buffer Overflow | Google Chromium WebRTC | Patch soon | 0.07 | ||
| 159 | CVE-2023-26369Out-of-Bounds Write | Adobe Acrobat and Reader | Patch soon | 0.07 | ||
| 160 | CVE-2022-27518Authentication Bypass | Citrix Application Delivery Controller (ADC) and Gateway | Patch soon | 0.07 | ||
| 161 | CVE-2012-0767Cross-Site Scripting (XSS) | Adobe Flash Player | Patch soon | 0.06 | ||
| 162 | CVE-2021-22600Privilege Escalation | Linux Kernel | Patch soon | 0.07 | ||
| 163 | CVE-2013-1675Information Disclosure | Mozilla Firefox | Patch soon | 0.07 | ||
| 164 | CVE-2017-6627IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.06 | ||
| 165 | CVE-2018-0159IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 166 | CVE-2020-8468Multiple Products Content Validation Escape | Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents | Patch soon | 0.06 | ||
| 167 | CVE-2020-16010Heap Buffer Overflow | Google Chrome for Android UI | Patch soon | 0.06 | ||
| 168 | CVE-2021-1871WebKit Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.07 | ||
| 169 | CVE-2021-27059Remote Code Execution | Microsoft Office | Patch soon | 0.06 | ||
| 170 | CVE-2021-33739Desktop Window Manager (DWM) Core Library Privilege Escalation | Microsoft Windows | Patch soon | 0.07 | ||
| 171 | CVE-2026-25108OS Command Injection | Soliton Systems K.K FileZen | Patch soon | 0.05 | ||
| 172 | CVE-2025-13223Type Confusion | Google Chromium V8 | Patch soon | 0.05 | ||
| 173 | CVE-2025-10585Type Confusion | Google Chromium V8 | Patch soon | 0.05 | ||
| 174 | CVE-2023-2136Chrome Skia Integer Overflow | Google Chromium Skia | Patch soon | 0.06 | ||
| 175 | CVE-2021-30900Out-of-Bounds Write | Apple iOS, iPadOS, and macOS | Patch soon | 0.05 | ||
| 176 | CVE-2023-21823Graphic Component Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 177 | CVE-2022-32917Remote Code Execution | Apple iOS, iPadOS, and macOS | Patch soon | 0.06 | ||
| 178 | CVE-2022-3075Insufficient Data Validation | Google Chromium Mojo | Patch soon | 0.06 | ||
| 179 | CVE-2019-15271Deserialization of Untrusted Data | Cisco RV Series Routers | Patch soon | 0.05 | ||
| 180 | CVE-2015-6175Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 181 | CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-Service | Cisco IOS XR | Patch soon | 0.06 | ||
| 182 | CVE-2017-12319Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service | Cisco IOS XE Software | Patch soon | 0.05 | ||
| 183 | CVE-2022-20700Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.06 | ||
| 184 | CVE-2019-0863Error Reporting (WER) Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 185 | CVE-2020-17087Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 186 | CVE-2021-27085Remote Code Execution | Microsoft Internet Explorer | Patch soon | 0.05 | ||
| 187 | CVE-2021-28664Unspecified | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.05 | ||
| 188 | CVE-2026-32202Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.05 | ||
| 189 | CVE-2026-21525NULL Pointer Dereference | Microsoft Windows | Patch soon | 0.05 | ||
| 190 | CVE-2025-54313Embedded Malicious Code | Prettier eslint-config-prettier | Patch soon | 0.05 | ||
| 191 | CVE-2026-20045Unified Communications Products Code Injection | Cisco Unified Communications Manager | Patch soon | 0.05 | ||
| 192 | CVE-2025-47827Use of a Key Past its Expiration Date | IGEL IGEL OS | Patch soon | 0.05 | ||
| 193 | CVE-2025-24200Incorrect Authorization | Apple iOS and iPadOS | Patch soon | 0.04 | ||
| 194 | CVE-2023-46748SQL Injection | F5 BIG-IP Configuration Utility | Patch soon | 0.04 | ||
| 195 | CVE-2023-41061Wallet Code Execution | Apple iOS, iPadOS, and watchOS | Patch soon | 0.04 | ||
| 196 | CVE-2004-1464Denial-of-Service | Cisco IOS | Patch soon | 0.05 | ||
| 197 | CVE-2022-2856Insufficient Input Validation | Google Chromium Intents | Patch soon | 0.05 | ||
| 198 | CVE-2019-7287Memory Corruption | Apple iOS | Patch soon | 0.05 | ||
| 199 | CVE-2020-1027Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 200 | CVE-2012-0518Unspecified | Oracle Fusion Middleware | Patch soon | 0.05 |