Exploited, but EPSS says unlikely, page 3
As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 201 | CVE-2020-1631Path Traversal | Juniper Junos OS | Patch soon | 0.05 | ||
| 202 | CVE-2009-1123Improper Input Validation | Microsoft Windows | Patch soon | 0.05 | ||
| 203 | CVE-2018-0179Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 204 | CVE-2018-0180Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 205 | CVE-2019-16256Command Injection | SIMalliance Toolbox Browser | Patch soon | 0.05 | ||
| 206 | CVE-2021-30661WebKit Storage Use-After-Free | Apple Multiple Products | Patch soon | 0.04 | ||
| 207 | CVE-2021-31979Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 208 | CVE-2021-36741Multiple Products Improper Input Validation | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security | Patch soon | 0.05 | ||
| 209 | CVE-2021-38000Improper Input Validation | Google Chromium Intents | Patch soon | 0.05 | ||
| 210 | CVE-2025-2749Path Traversal | Kentico Kentico Xperience | Patch soon | 0.04 | ||
| 211 | CVE-2023-43000Use-After-Free | Apple Multiple Products | Patch soon | 0.04 | ||
| 212 | CVE-2026-21533Improper Privilege Management | Microsoft Windows | Patch soon | 0.04 | ||
| 213 | CVE-2025-27915Cross-site Scripting | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.04 | ||
| 214 | CVE-2025-55177Incorrect Authorization | Meta Platforms WhatsApp | Patch soon | 0.04 | ||
| 215 | CVE-2025-48384Link Following | Git Git | Patch soon | 0.04 | ||
| 216 | CVE-2021-20035OS Command Injection | SonicWall SMA100 Appliances | Patch soon | 0.04 | ||
| 217 | CVE-2024-53197Out-of-Bounds Access | Linux Kernel | Patch soon | 0.04 | ||
| 218 | CVE-2025-24985Fast FAT File System Driver Integer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| 219 | CVE-2024-20953Deserialization | Oracle Agile Product Lifecycle Management (PLM) | Patch soon | 0.04 | ||
| 220 | CVE-2024-39717Dangerous File Type Upload | Versa Director | Patch soon | 0.04 | ||
| 221 | CVE-2024-20399Command Injection | Cisco NX-OS | Patch soon | 0.04 | ||
| 222 | CVE-2024-30040MSHTML Platform Security Feature Bypass | Microsoft Windows | Patch soon | 0.04 | ||
| 223 | CVE-2023-41179Remote Code Execution | Trend Micro Apex One and Worry-Free Business Security | Patch soon | 0.04 | ||
| 224 | CVE-2023-32049Defender SmartScreen Security Feature Bypass | Microsoft Windows | Patch soon | 0.04 | ||
| 225 | CVE-2015-1769Mount Manager Privilege Escalation | Microsoft Windows | Patch soon | 0.04 | ||
| 226 | CVE-2018-8611Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.04 | ||
| 227 | CVE-2019-7483Directory Traversal | SonicWall SMA100 | Patch soon | 0.04 | ||
| 228 | CVE-2018-0161Resource Management Errors | Cisco IOS Software | Patch soon | 0.04 | ||
| 229 | CVE-2021-30869Type Confusion | Apple iOS, iPadOS, and macOS | Patch soon | 0.04 | ||
| 230 | CVE-2026-85880Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| 231 | CVE-2025-24201WebKit Out-of-Bounds Write | Apple Multiple Products | Patch soon | 0.04 | ||
| 232 | CVE-2024-9537Unspecified | ScienceLogic SL1 | Patch soon | 0.04 | ||
| 233 | CVE-2024-0519Out-of-Bounds Memory Access | Google Chromium V8 | Patch soon | 0.04 | ||
| 234 | CVE-2023-0266Use-After-Free | Linux Kernel | Patch soon | 0.04 | ||
| 235 | CVE-2021-31010Sandbox Bypass | Apple iOS, macOS, watchOS | Patch soon | 0.04 | ||
| 236 | CVE-2016-85621543-1 Improper Privilege Management | Siemens SIMATIC CP | Patch soon | 0.04 | ||
| 237 | CVE-2016-3643Privilege Escalation | SolarWinds Virtualization Manager | Patch soon | 0.04 | ||
| 238 | CVE-2020-3566Software DVMRP Memory Exhaustion | Cisco IOS XR | Patch soon | 0.04 | ||
| 239 | CVE-2021-30665WebKit Memory Corruption | Apple Multiple Products | Patch soon | 0.04 | ||
| 240 | CVE-2025-66644OS Command Injection | Array Networks ArrayOS AG | Patch soon | 0.03 | ||
| 241 | CVE-2024-8068Improper Privilege Management | Citrix Session Recording | Patch soon | 0.03 | ||
| 242 | CVE-2025-8876Command Injection | N-able N-Central | Patch soon | 0.03 | ||
| 243 | CVE-2025-3935Improper Authentication | ConnectWise ScreenConnect | Patch soon | 0.04 | ||
| 244 | CVE-2025-42599Stack-Based Buffer Overflow | Qualitia Active! Mail | Patch soon | 0.03 | ||
| 245 | CVE-2024-53104Out-of-Bounds Write | Linux Kernel | Patch soon | 0.03 | ||
| 246 | CVE-2023-45727Improper Restriction of XML External Entity (XXE) Reference | North Grid Proself | Patch soon | 0.04 | ||
| 247 | CVE-2022-40139Improper Validation | Trend Micro Apex One and Apex One as a Service | Patch soon | 0.03 | ||
| 248 | CVE-2022-32894Out-of-Bounds Write | Apple iOS and macOS | Patch soon | 0.03 | ||
| 249 | CVE-2009-2055Border Gateway Protocol (BGP) Denial-of-Service | Cisco IOS XR | Patch soon | 0.03 | ||
| 250 | CVE-2018-0167Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| 251 | CVE-2018-0175Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| 252 | CVE-2021-35247Improper Input Validation | SolarWinds Serv-U | Patch soon | 0.03 | ||
| 253 | CVE-2020-3569Software DVMRP Memory Exhaustion | Cisco IOS XR | Patch soon | 0.03 | ||
| 254 | CVE-2021-30663WebKit Integer Overflow | Apple Multiple Products | Patch soon | 0.04 | ||
| 255 | CVE-2026-87491Out of Bounds Write | Google Chromium V8 | Patch soon | 0.03 | ||
| 256 | CVE-2022-48503Unspecified | Apple Multiple Products | Patch soon | 0.03 | ||
| 257 | CVE-2023-6548Code Injection | Citrix NetScaler ADC and NetScaler Gateway | Patch soon | 0.03 | ||
| 258 | CVE-2023-36584Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch soon | 0.03 | ||
| 259 | CVE-2022-41125CNG Key Isolation Service Privilege Escalation | Microsoft Windows | Patch soon | 0.03 | ||
| 260 | CVE-2013-2596Integer Overflow | Linux Kernel | Patch soon | 0.03 | ||
| 261 | CVE-2011-4723Cleartext Storage of a Password | D-Link DIR-300 Router | Patch soon | 0.03 | ||
| 262 | CVE-2020-9907Memory Corruption | Apple Multiple Products | Patch soon | 0.03 | ||
| 263 | CVE-2018-8589Privilege Escalation | Microsoft Win32k | Patch soon | 0.03 | ||
| 264 | CVE-2017-0001Privilege Escalation | Microsoft Graphics Device Interface (GDI) | Patch soon | 0.03 | ||
| 265 | CVE-2020-0041Out-of-Bounds Write | Android Android Kernel | Patch soon | 0.03 | ||
| 266 | CVE-2020-6819Use-After-Free | Mozilla Firefox and Thunderbird | Patch soon | 0.03 | ||
| 267 | CVE-2021-27562Out-of-Bounds Write | Arm Trusted Firmware | Patch soon | 0.03 | ||
| 268 | CVE-2024-7262Path Traversal | Kingsoft WPS Office | Patch soon | 0.03 | ||
| 269 | CVE-2024-32896Privilege Escalation | Android Pixel | Patch soon | 0.03 | ||
| 270 | CVE-2023-38606Kernel Unspecified | Apple Multiple Products | Patch soon | 0.03 | ||
| 271 | CVE-2021-29256Mali GPU Kernel Driver Use-After-Free | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.03 | ||
| 272 | CVE-2021-25337Improper Access Control | Samsung Mobile Devices | Patch soon | 0.03 | ||
| 273 | CVE-2021-30983Buffer Overflow | Apple iOS and iPadOS | Patch soon | 0.03 | ||
| 274 | CVE-2021-30666WebKit Buffer Overflow | Apple iOS | Patch soon | 0.03 | ||
| 275 | CVE-2021-31199Privilege Escalation | Microsoft Enhanced Cryptographic Provider | Patch soon | 0.03 | ||
| 276 | CVE-2021-38649Privilege Escalation | Microsoft Open Management Infrastructure (OMI) | Patch soon | 0.03 | ||
| 277 | CVE-2025-40602SMA1000 Missing Authorization | SonicWall SMA1000 appliance | Patch soon | 0.03 | ||
| 278 | CVE-2025-61932Improper Verification of Source of a Communication Channel | Motex LANSCOPE Endpoint Manager | Patch soon | 0.03 | ||
| 279 | CVE-2025-59230Improper Access Control | Microsoft Windows | Patch soon | 0.03 | ||
| 280 | CVE-2024-38226Protection Mechanism Failure | Microsoft Publisher | Patch soon | 0.03 | ||
| 281 | CVE-2024-36971Remote Code Execution | Android Kernel | Patch soon | 0.03 | ||
| 282 | CVE-2023-29492Insecure Deserialization | Novi Survey Novi Survey | Patch soon | 0.03 | ||
| 283 | CVE-2022-42948User Interface Remote Code Execution | Fortra Cobalt Strike | Patch soon | 0.03 | ||
| 284 | CVE-2019-6223Group Facetime | Apple iOS and macOS | Patch soon | 0.03 | ||
| 285 | CVE-2020-16013Incorrect Implementation Vulnerabililty | Google Chromium V8 | Patch soon | 0.03 | ||
| 286 | CVE-2020-16017Use-After-Free | Google Chrome | Patch soon | 0.03 | ||
| 287 | CVE-2020-24557Multiple Products Improper Access Control | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security | Patch soon | 0.03 | ||
| 288 | CVE-2021-38645Privilege Escalation | Microsoft Open Management Infrastructure (OMI) | Patch soon | 0.03 | ||
| 289 | CVE-2026-6973Improper Input Validation | Ivanti Endpoint Manager Mobile (EPMM) | Patch soon | 0.03 | ||
| 290 | CVE-2025-32975Improper Authentication | Quest KACE Systems Management Appliance (SMA) | Patch soon | 0.02 | ||
| 291 | CVE-2025-62221Use After Free | Microsoft Windows | Patch soon | 0.03 | ||
| 292 | CVE-2023-20109Group Encrypted Transport VPN Out-of-Bounds Write | Cisco IOS and IOS XE | Patch soon | 0.02 | ||
| 293 | CVE-2023-35674Privilege Escalation | Android Framework | Patch soon | 0.03 | ||
| 294 | CVE-2023-21492Insertion of Sensitive Information Into Log File | Samsung Mobile Devices | Patch soon | 0.03 | ||
| 295 | CVE-2022-41049Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch soon | 0.02 | ||
| 296 | CVE-2022-0028Reflected Amplification Denial-of-Service | Palo Alto Networks PAN-OS | Patch soon | 0.03 | ||
| 297 | CVE-2021-31201Privilege Escalation | Microsoft Enhanced Cryptographic Provider | Patch soon | 0.03 | ||
| 298 | CVE-2026-11645Out-of-Bounds Read and Write | Google Chromium V8 | Patch soon | 0.02 | ||
| 299 | CVE-2026-21519Type Confusion | Microsoft Windows | Patch soon | 0.02 | ||
| 300 | CVE-2025-30154reviewdog/action-setup GitHub Action Embedded Malicious Code | reviewdog action-setup GitHub Action | Patch soon | 0.02 |