Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2023-43208 NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability CRITICAL 9.8 82.71% cvelistv5 2024-05-20
cve-2023-42793 JetBrains TeamCity Authentication Bypass Vulnerability CRITICAL N/A 99.99% cvelistv5 2023-10-04
cve-2023-39026 CVE-2023-39026 HIGH N/A 17.92% cvelistv5
cve-2023-38646 CVE-2023-38646 HIGH N/A 98.68% cvelistv5
cve-2023-37679 CVE-2023-37679 HIGH N/A 99.43% cvelistv5
cve-2023-36144 CVE-2023-36144 HIGH N/A 36.51% cvelistv5
cve-2023-3606 CVE-2023-3606 MEDIUM 6.5 7.08% cvelistv5
cve-2023-35844 CVE-2023-35844 HIGH 7.5 6.34% cvelistv5
cve-2023-35082 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability CRITICAL 10.0 100.00% cvelistv5 2024-01-18
cve-2023-35081 Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability HIGH 7.2 63.58% cvelistv5 2023-07-31
cve-2023-35078 Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability CRITICAL 10.0 100.00% cvelistv5 2023-07-25
cve-2023-34993 CVE-2023-34993 CRITICAL 9.6 18.15% cvelistv5
cve-2023-32235 CVE-2023-32235 HIGH 7.5 39.08% cvelistv5
cve-2023-32117 WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability CRITICAL 9.8 7.33% cvelistv5 2026-06-17
cve-2023-31478 CVE-2023-31478 HIGH 7.5 29.70% cvelistv5
cve-2023-31059 CVE-2023-31059 HIGH 7.5 5.57% cvelistv5
cve-2023-29298 Adobe ColdFusion Improper Access Control Vulnerability HIGH N/A 99.80% cvelistv5 2023-07-20
cve-2023-28771 Zyxel Multiple Firewalls OS Command Injection Vulnerability CRITICAL 9.8 99.28% cvelistv5 2023-05-31
cve-2023-28432 MinIO Information Disclosure Vulnerability HIGH 7.5 83.96% cvelistv5 2023-04-21
cve-2023-27640 CVE-2023-27640 HIGH 7.5 3.57% cvelistv5
cve-2023-27482 homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet. CRITICAL 10.0 72.17% cvelistv5 2026-06-17
cve-2023-26801 CVE-2023-26801 CRITICAL 9.8 69.66% cvelistv5
cve-2023-22518 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability CRITICAL 10.0 100.00% cvelistv5 2023-11-07
cve-2023-22515 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability CRITICAL 10.0 99.16% cvelistv5 2023-10-05
cve-2023-22478 CVE-2023-22478 HIGH 7.3 3.57% cvelistv5
cve-2023-20198 Cisco IOS XE Web UI Privilege Escalation Vulnerability CRITICAL 10.0 99.57% cvelistv5 2023-10-16
cve-2023-20073 CVE-2023-20073 MEDIUM 5.3 90.11% cvelistv5
cve-2023-1389 TP-Link Archer AX-21 Command Injection Vulnerability HIGH 8.8 100.00% cvelistv5 2023-05-01
cve-2022-4984 CVE-2022-4984 HIGH 8.7 0.45% cvelistv5
cve-2022-48164 CVE-2022-48164 HIGH 7.5 3.10% cvelistv5