Exploited, but EPSS says unlikely, page 5

As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.

#VulnerabilityProductOur groupListedDeadlineEPSS
401CVE-2020-9859Code ExecutionApple Multiple ProductsPatch soon0.01
402CVE-2026-54420UNIX Symbolic Link (Symlink) FollowingLiteSpeed cPanel PluginPatch soon0.01
403CVE-2024-50302Use of Uninitialized ResourceLinux KernelPatch soon0.01
404CVE-2021-25371UnspecifiedSamsung Mobile DevicesPatch soon0.01
405CVE-2021-25372Improper Boundary CheckSamsung Mobile DevicesPatch soon0.01
406CVE-2021-0920Race ConditionAndroid KernelPatch soon0.01
407CVE-2023-33106Use of Out-of-Range Pointer OffsetQualcomm Multiple ChipsetsPatch soon0.01
408CVE-2024-4610Use-After-FreeArm Mali GPU Kernel DriverPatch soon0.01
409CVE-2023-33107Integer OverflowQualcomm Multiple ChipsetsPatch soon0.01
410CVE-2026-5281Use-After-FreeGoogle DawnPatch soon0.01
411CVE-2025-1976Code InjectionBroadcom Brocade Fabric OSPatch soon0.01
412CVE-2024-43093Privilege EscalationAndroid FrameworkPatch soon0.01
413CVE-2019-8526Use-After-FreeApple macOSPatch soon0.01
414CVE-2021-39793Out-of-Bounds WriteGoogle PixelPatch soon0.01
415CVE-2026-66384Improper Limitation of a Pathname to a Restricted DirectoryJFrog ArtifactoryPatch soon0.01
416CVE-2024-43047Use-After-FreeQualcomm Multiple ChipsetsPatch soon0.01
417CVE-2024-29748Privilege EscalationAndroid PixelPatch soon0.01
418CVE-2023-33063Use-After-FreeQualcomm Multiple ChipsetsPatch soon0.01
419CVE-2026-7473Incomplete Comparison with Missing FactorsArista Extensible Operating SystemPatch soon0.01
420CVE-2021-25487Out-of-Bounds ReadSamsung Mobile DevicesPatch soon0.01
421CVE-2025-48928Exposure of Core Dump File to an Unauthorized Control SphereTeleMessage TM SGNLPatch soon0.01
422CVE-2026-34926(On-Premise) Directory TraversalTrend Micro Apex OnePatch soon0.01
423CVE-2025-48543Use-After-FreeAndroid RuntimePatch soon0.01
424CVE-2026-42897Exchange Server Cross-Site ScriptingMicrosoft MicrosoftPatch soon0.01
425CVE-2021-25489Improper Input ValidationSamsung Mobile DevicesPatch soon0.01
426CVE-2021-1906Detection of Error Condition Without ActionQualcomm Multiple ChipsetsPatch soon0.01
427CVE-2024-29745Information DisclosureAndroid PixelPatch soon0.00
428CVE-2022-48618Memory CorruptionApple Multiple ProductsPatch soon0.00
429CVE-2025-21480Incorrect AuthorizationQualcomm Multiple ChipsetsPatch soon0.00
430CVE-2026-41091Link FollowingMicrosoft DefenderPatch soon0.00
431CVE-2025-47729Hidden FunctionalityTeleMessage TM SGNLPatch soon0.00
432CVE-2025-43520Classic Buffer OverflowApple Multiple ProductsPatch soon0.00
433CVE-2022-22071Use-After-FreeQualcomm Multiple ChipsetsPatch soon0.00
434CVE-2021-25394Race ConditionSamsung Mobile DevicesPatch soon0.00
435CVE-2026-81963Link FollowingMicrosoft WindowsPatch soon0.00
436CVE-2022-22265Use-After-FreeSamsung Mobile DevicesPatch soon0.00
437CVE-2021-25395Race ConditionSamsung Mobile DevicesPatch soon0.00
438CVE-2025-43510Improper LockingApple Multiple ProductsPatch soon0.00
439CVE-2026-56155Insufficient Granularity of Access ControlMicrosoft Active Directory Federation ServicesPatch soon0.00
440CVE-2026-68820Use-After-FreeMicrosoft Windows Ancillary Function Driver for WinSockPatch soon0.00
441CVE-2026-3502Download of Code Without Integrity CheckTrueConf ClientPatch soon0.00
442CVE-2025-48572Privilege EscalationAndroid FrameworkPatch soon0.00
443CVE-2025-48633Information DisclosureAndroid FrameworkPatch soon0.00
444CVE-2023-21237Information DisclosureAndroid PixelPatch soon0.00