Exploited, but EPSS says unlikely, page 5
As of , 444 of the 1,734 vulnerabilities on CISA's list of exploited vulnerabilities, 26%, have an EPSS score under 0.10.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 401 | CVE-2020-9859Code Execution | Apple Multiple Products | Patch soon | 0.01 | ||
| 402 | CVE-2026-54420UNIX Symbolic Link (Symlink) Following | LiteSpeed cPanel Plugin | Patch soon | 0.01 | ||
| 403 | CVE-2024-50302Use of Uninitialized Resource | Linux Kernel | Patch soon | 0.01 | ||
| 404 | CVE-2021-25371Unspecified | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 405 | CVE-2021-25372Improper Boundary Check | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 406 | CVE-2021-0920Race Condition | Android Kernel | Patch soon | 0.01 | ||
| 407 | CVE-2023-33106Use of Out-of-Range Pointer Offset | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 408 | CVE-2024-4610Use-After-Free | Arm Mali GPU Kernel Driver | Patch soon | 0.01 | ||
| 409 | CVE-2023-33107Integer Overflow | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 410 | CVE-2026-5281Use-After-Free | Google Dawn | Patch soon | 0.01 | ||
| 411 | CVE-2025-1976Code Injection | Broadcom Brocade Fabric OS | Patch soon | 0.01 | ||
| 412 | CVE-2024-43093Privilege Escalation | Android Framework | Patch soon | 0.01 | ||
| 413 | CVE-2019-8526Use-After-Free | Apple macOS | Patch soon | 0.01 | ||
| 414 | CVE-2021-39793Out-of-Bounds Write | Google Pixel | Patch soon | 0.01 | ||
| 415 | CVE-2026-66384Improper Limitation of a Pathname to a Restricted Directory | JFrog Artifactory | Patch soon | 0.01 | ||
| 416 | CVE-2024-43047Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 417 | CVE-2024-29748Privilege Escalation | Android Pixel | Patch soon | 0.01 | ||
| 418 | CVE-2023-33063Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 419 | CVE-2026-7473Incomplete Comparison with Missing Factors | Arista Extensible Operating System | Patch soon | 0.01 | ||
| 420 | CVE-2021-25487Out-of-Bounds Read | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 421 | CVE-2025-48928Exposure of Core Dump File to an Unauthorized Control Sphere | TeleMessage TM SGNL | Patch soon | 0.01 | ||
| 422 | CVE-2026-34926(On-Premise) Directory Traversal | Trend Micro Apex One | Patch soon | 0.01 | ||
| 423 | CVE-2025-48543Use-After-Free | Android Runtime | Patch soon | 0.01 | ||
| 424 | CVE-2026-42897Exchange Server Cross-Site Scripting | Microsoft Microsoft | Patch soon | 0.01 | ||
| 425 | CVE-2021-25489Improper Input Validation | Samsung Mobile Devices | Patch soon | 0.01 | ||
| 426 | CVE-2021-1906Detection of Error Condition Without Action | Qualcomm Multiple Chipsets | Patch soon | 0.01 | ||
| 427 | CVE-2024-29745Information Disclosure | Android Pixel | Patch soon | 0.00 | ||
| 428 | CVE-2022-48618Memory Corruption | Apple Multiple Products | Patch soon | 0.00 | ||
| 429 | CVE-2025-21480Incorrect Authorization | Qualcomm Multiple Chipsets | Patch soon | 0.00 | ||
| 430 | CVE-2026-41091Link Following | Microsoft Defender | Patch soon | 0.00 | ||
| 431 | CVE-2025-47729Hidden Functionality | TeleMessage TM SGNL | Patch soon | 0.00 | ||
| 432 | CVE-2025-43520Classic Buffer Overflow | Apple Multiple Products | Patch soon | 0.00 | ||
| 433 | CVE-2022-22071Use-After-Free | Qualcomm Multiple Chipsets | Patch soon | 0.00 | ||
| 434 | CVE-2021-25394Race Condition | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 435 | CVE-2026-81963Link Following | Microsoft Windows | Patch soon | 0.00 | ||
| 436 | CVE-2022-22265Use-After-Free | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 437 | CVE-2021-25395Race Condition | Samsung Mobile Devices | Patch soon | 0.00 | ||
| 438 | CVE-2025-43510Improper Locking | Apple Multiple Products | Patch soon | 0.00 | ||
| 439 | CVE-2026-56155Insufficient Granularity of Access Control | Microsoft Active Directory Federation Services | Patch soon | 0.00 | ||
| 440 | CVE-2026-68820Use-After-Free | Microsoft Windows Ancillary Function Driver for WinSock | Patch soon | 0.00 | ||
| 441 | CVE-2026-3502Download of Code Without Integrity Check | TrueConf Client | Patch soon | 0.00 | ||
| 442 | CVE-2025-48572Privilege Escalation | Android Framework | Patch soon | 0.00 | ||
| 443 | CVE-2025-48633Information Disclosure | Android Framework | Patch soon | 0.00 | ||
| 444 | CVE-2023-21237Information Disclosure | Android Pixel | Patch soon | 0.00 |