Exploited, but EPSS says unlikely, page 4
As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 301 | CVE-2018-4344Memory Corruption | Apple Multiple Products | Patch soon | 0.02 | ||
| 302 | CVE-2022-21919User Profile Service Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 303 | CVE-2022-26486Use-After-Free | Mozilla Firefox | Patch soon | 0.02 | ||
| 304 | CVE-2025-53521Stack-Based Buffer Overflow | F5 BIG-IP | Patch soon | 0.02 | ||
| 305 | CVE-2026-3909Out-of-Bounds Write | Google Skia | Patch soon | 0.02 | ||
| 306 | CVE-2025-32706Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 307 | CVE-2025-3928Unspecified | Commvault Web Server | Patch soon | 0.02 | ||
| 308 | CVE-2025-24993NTFS Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 309 | CVE-2025-21391Storage Link Following | Microsoft Windows | Patch soon | 0.02 | ||
| 310 | CVE-2019-0880Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 311 | CVE-2020-9818Out-of-Bounds Write | Apple iOS, iPadOS, and watchOS | Patch soon | 0.02 | ||
| 312 | CVE-2021-1782Race Condition | Apple Multiple Products | Patch soon | 0.02 | ||
| 313 | CVE-2026-34621Prototype Pollution | Adobe Acrobat and Reader | Patch soon | 0.02 | ||
| 314 | CVE-2025-21043Out-of-Bounds Write | Samsung Mobile Devices | Patch soon | 0.02 | ||
| 315 | CVE-2025-32709Ancillary Function Driver for WinSock Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 316 | CVE-2017-6663IOS Software and Cisco IOS XE Software Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.02 | ||
| 317 | CVE-2017-12232for Cisco Integrated Services Routers Denial-of-Service | Cisco IOS software | Patch soon | 0.02 | ||
| 318 | CVE-2020-9819Memory Corruption | Apple iOS, iPadOS, and watchOS | Patch soon | 0.02 | ||
| 319 | CVE-2026-45247Deserialization of Untrusted Data | Mirasvit Mirasvit Full Page Cache Warmer | Patch soon | 0.02 | ||
| 320 | CVE-2025-24984NTFS Information Disclosure | Microsoft Windows | Patch soon | 0.02 | ||
| 321 | CVE-2025-24991NTFS Out-Of-Bounds Read | Microsoft Windows | Patch soon | 0.02 | ||
| 322 | CVE-2025-0111File Read | Palo Alto Networks PAN-OS | Patch soon | 0.02 | ||
| 323 | CVE-2023-6448Insecure Default Password | Unitronics Vision PLC and HMI | Patch soon | 0.02 | ||
| 324 | CVE-2017-12238VPLS Denial-of-Service | Cisco Catalyst 6800 Series Switches | Patch soon | 0.02 | ||
| 325 | CVE-2026-28318Uncontrolled Resource Consumption | SolarWinds Serv-U | Patch soon | 0.02 | ||
| 326 | CVE-2023-41974Use-After-Free | Apple iOS and iPadOS | Patch soon | 0.02 | ||
| 327 | CVE-2025-30400DWM Core Library Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 328 | CVE-2020-2506QNAP Helpdesk Improper Access Control | QNAP Systems Helpdesk | Patch soon | 0.02 | ||
| 329 | CVE-2025-59689Command Injection | Libraesva Email Security Gateway | Patch soon | 0.02 | ||
| 330 | CVE-2025-8875Insecure Deserialization | N-able N-Central | Patch soon | 0.02 | ||
| 331 | CVE-2025-27920Directory Traversal | Srimax Output Messenger | Patch soon | 0.02 | ||
| 332 | CVE-2019-0797Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 333 | CVE-2026-34909Path Traversal | Ubiquiti UniFi OS | Patch soon | 0.02 | ||
| 334 | CVE-2024-7694Unrestricted Upload of File with Dangerous Type | TeamT5 ThreatSonar Anti-Ransomware | Patch soon | 0.02 | ||
| 335 | CVE-2025-15556Download of Code Without Integrity Check | Notepad++ Notepad++ | Patch soon | 0.02 | ||
| 336 | CVE-2025-21590Improper Isolation or Compartmentalization | Juniper Junos OS | Patch soon | 0.02 | ||
| 337 | CVE-2025-22226Information Disclosure | VMware ESXi, Workstation, and Fusion | Patch soon | 0.02 | ||
| 338 | CVE-2026-72530Code Injection | TrueConf Server | Patch soon | 0.02 | ||
| 339 | CVE-2025-48595Integer Overflow | Android Framework | Patch soon | 0.02 | ||
| 340 | CVE-2025-48700Cross-site Scripting | Synacor Zimbra Collaboration Suite (ZCS) | Patch soon | 0.02 | ||
| 341 | CVE-2026-33634Embedded Malicious Code | Aquasecurity Trivy | Patch soon | 0.02 | ||
| 342 | CVE-2024-21287Incorrect Authorization | Oracle Agile Product Lifecycle Management (PLM) | Patch soon | 0.02 | ||
| 343 | CVE-2024-39891Information Disclosure | Twilio Authy | Patch soon | 0.02 | ||
| 344 | CVE-2023-28229Privilege Escalation | Microsoft Windows CNG Key Isolation Service | Patch soon | 0.02 | ||
| 345 | CVE-2022-41033Privilege Escalation | Microsoft Windows COM+ Event System Service | Patch soon | 0.02 | ||
| 346 | CVE-2026-33824Double Free | Microsoft Internet Key Exchange (IKE) Service Extensions | Patch soon | 0.02 | ||
| 347 | CVE-2025-31277Buffer Overflow | Apple Multiple Products | Patch soon | 0.02 | ||
| 348 | CVE-2025-24989Improper Access Control | Microsoft Power Pages | Patch soon | 0.02 | ||
| 349 | CVE-2024-38107Power Dependency Coordinator Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 350 | CVE-2020-11261Multiple Chipsets Improper Input Validation | Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | Patch soon | 0.02 | ||
| 351 | CVE-2026-67277Missing Authentication for Critical Function | MikroTik RouterOS | Patch soon | 0.02 | ||
| 352 | CVE-2026-21514Word Reliance on Untrusted Inputs in a Security Decision | Microsoft Office | Patch soon | 0.02 | ||
| 353 | CVE-2025-22224TOCTOU Race Condition | VMware ESXi and Workstation | Patch soon | 0.02 | ||
| 354 | CVE-2025-21418Ancillary Function Driver for WinSock Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 355 | CVE-2025-21334Hyper-V NT Kernel Integration VSP Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 356 | CVE-2019-8720Memory Corruption | WebKitGTK WebKitGTK | Patch soon | 0.02 | ||
| 357 | CVE-2021-40450Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 358 | CVE-2021-41357Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 359 | CVE-2021-1905Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.02 | ||
| 360 | CVE-2024-23225Memory Corruption | Apple Multiple Products | Patch soon | 0.01 | ||
| 361 | CVE-2013-2597Stack-based Buffer Overflow | Code Aurora ACDB Audio Driver | Patch soon | 0.02 | ||
| 362 | CVE-2021-36742Multiple Products Improper Input Validation | Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security | Patch soon | 0.01 | ||
| 363 | CVE-2023-20963Privilege Escalation | Android Framework | Patch soon | 0.01 | ||
| 364 | CVE-2026-20700Multiple Buffer Overflow | Apple Multiple Products | Patch soon | 0.01 | ||
| 365 | CVE-2025-32701Common Log File System (CLFS) Driver Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 366 | CVE-2025-24983Win32k Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 367 | CVE-2025-21335Hyper-V NT Kernel Integration VSP Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 368 | CVE-2024-23296Memory Corruption | Apple Multiple Products | Patch soon | 0.01 | ||
| 369 | CVE-2023-41990Code Execution | Apple Multiple Products | Patch soon | 0.01 | ||
| 370 | CVE-2019-1214Privilege Common Log File System (CLFS) Escalation | Microsoft Windows | Patch soon | 0.01 | ||
| 371 | CVE-2020-0069Insufficient Input Validation | MediaTek Multiple Chipsets | Patch soon | 0.01 | ||
| 372 | CVE-2025-35939External Control of Assumed-Immutable Web Parameter | Craft CMS Craft CMS | Patch soon | 0.01 | ||
| 373 | CVE-2024-53150Out-of-Bounds Read | Linux Kernel | Patch soon | 0.01 | ||
| 374 | CVE-2023-4346Overly Restrictive Account Lockout Mechanism | KNX Association KNX Protocol Connection Authorization Option 1 | Patch soon | 0.01 | ||
| 375 | CVE-2025-38352Time-of-Check Time-of-Use (TOCTOU) Race Condition | Linux Kernel | Patch soon | 0.01 | ||
| 376 | CVE-2024-49035Improper Access Control | Microsoft Partner Center | Patch soon | 0.01 | ||
| 377 | CVE-2026-45498Denial of Service | Microsoft Defender | Patch soon | 0.01 | ||
| 378 | CVE-2026-21385Memory Corruption | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 379 | CVE-2025-59374Embedded Malicious Code | ASUS Live Update | Patch soon | 0.01 | ||
| 380 | CVE-2023-26083Mali GPU Kernel Driver Information Disclosure | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.01 | ||
| 381 | CVE-2025-43200Unspecified | Apple Multiple Products | Patch soon | 0.01 | ||
| 382 | CVE-2023-36851SRX Series Missing Authentication for Critical Function | Juniper Junos OS | Patch soon | 0.01 | ||
| 383 | CVE-2022-22674Out-of-Bounds Read | Apple macOS | Patch soon | 0.01 | ||
| 384 | CVE-2023-42824Kernel Privilege Escalation | Apple iOS and iPadOS | Patch soon | 0.01 | ||
| 385 | CVE-2023-4211Use-After-Free | Arm Mali GPU Kernel Driver | Patch soon | 0.01 | ||
| 386 | CVE-2022-22706Mali GPU Kernel Driver Unspecified | Arm Mali Graphics Processing Unit (GPU) | Patch soon | 0.01 | ||
| 387 | CVE-2021-25369Improper Access Control | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 388 | CVE-2022-42827Out-of-Bounds Write | Apple iOS and iPadOS | Patch soon | 0.01 | ||
| 389 | CVE-2026-3910Improper Restriction of Operations Within the Bounds of a Memory Buffer | Google Chromium V8 | Patch soon | 0.01 | ||
| 390 | CVE-2025-27038Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 391 | CVE-2021-23874Improper Privilege Management | McAfee McAfee Total Protection (MTP) | Patch soon | 0.01 | ||
| 392 | CVE-2026-8452Improper Restriction of Operations within the Bounds of a Memory Buffer | Citrix NetScaler ADC and NetScaler Gateway | Patch soon | 0.01 | ||
| 393 | CVE-2026-20349Heap Inspection | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Patch soon | 0.01 | ||
| 394 | CVE-2026-48172Privilege Escalation | LiteSpeed cPanel Plugin | Patch soon | 0.01 | ||
| 395 | CVE-2021-1048Use-After-Free | Android Kernel | Patch soon | 0.01 | ||
| 396 | CVE-2026-8398Embedded Malicious Code | Daemon Daemon Tools Lite | Patch soon | 0.01 | ||
| 397 | CVE-2021-25370Memory Corruption | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 398 | CVE-2021-44168Arbitrary File Download | Fortinet FortiOS | Patch soon | 0.01 | ||
| 399 | CVE-2026-59822Improper Authentication | BerriAI LiteLLM | Patch soon | 0.01 | ||
| 400 | CVE-2025-21479Incorrect Authorization | Qualcomm Multiple Chipsets | Patch soon | 0.01 |