Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2025-13465 lodash: prototype pollution in _.unset and _.omit functions HIGH 8.2 1.85% cvelistv5 2026-09-04
cve-2025-12383 Race Condition allows Bypass of Trust Restrictions CRITICAL 9.4 0.28% cvelistv5 2025-11-18
cve-2024-7254 protobuf: StackOverflow vulnerability in Protocol Buffers HIGH 7.5 2.77% cvelistv5 2026-09-04
cve-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE) HIGH 8.8 3.26% cvelistv5 2026-08-10
cve-2024-47554 SUSE CVE CVE-2024-47554 MEDIUM 5.3 1.31% cvelistv5 2026-08-30
cve-2024-39908 rexml: DoS vulnerability in REXML MEDIUM 4.3 1.49% cvelistv5 2026-08-05
cve-2024-37997 A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a stack based overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process. HIGH 7.8 0.17% cvelistv5 2025-08-27
cve-2024-29371 jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression HIGH 7.5 0.26% cvelistv5 2026-09-04
cve-2024-28168 fop: Improper Restriction of XML External Entity Reference ('XXE') HIGH 7.5 1.04% cvelistv5 2026-01-12
cve-2023-40577 SUSE CVE CVE-2023-40577 HIGH 7.5 0.63% cvelistv5 2026-06-06
cve-2023-35116 jackson-databind: denial of service via cylic dependencies MEDIUM 4.7 0.35% cvelistv5 2026-06-28
cve-2022-25315 expat: Integer overflow in storeRawNames() CRITICAL 9.8 4.82% cvelistv5 2026-08-06
cve-2021-3629 undertow: potential security issue in flow control over HTTP/2 may lead to DOS MEDIUM 5.9 1.33% cvelistv5 2026-08-20
cve-2021-3283 HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3. UNKNOWN N/A 1.45% cvelistv5 2024-08-03
cve-2021-28170 jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate HIGH 7.5 2.13% cvelistv5 2026-08-20
cve-2020-9547 SUSE CVE CVE-2020-9547 CRITICAL 9.8 18.38% cvelistv5 2026-09-18
cve-2020-8908 guava: local information disclosure via temporary directory created with unsafe permissions LOW 3.3 0.98% cvelistv5 2026-08-04
cve-2014-3643 jersey: XXE via parameter entities UNKNOWN N/A 2.18% cvelistv5 2026-01-28
edb-50637 EDB-50637 HIGH N/A N/A ndaal_kev 2026-07-13
edb-50321 EDB-50321 HIGH N/A N/A ndaal_kev 2026-07-13
edb-49327 EDB-49327 HIGH N/A N/A ndaal_kev 2026-07-13
edb-45025 EDB-45025 HIGH N/A N/A ndaal_kev 2026-07-13
edb-44760 EDB-44760 HIGH N/A N/A ndaal_kev 2026-07-13
edb-43143 EDB-43143 HIGH N/A N/A ndaal_kev 2026-07-13
edb-41471 EDB-41471 HIGH N/A N/A ndaal_kev 2026-07-13
edb-28713 EDB-28713 HIGH N/A N/A ndaal_kev 2026-07-13
cve-2026-9698 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Ra... CRITICAL 9.8 0.82% cvelistv5 2026-09-03
cve-2026-9697 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// o... HIGH 7.4 0.55% cvelistv5 2026-09-10
cve-2026-9678 SUSE CVE CVE-2026-9678 MEDIUM 5.9 0.42% cvelistv5 2026-09-11
cve-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTI... HIGH 7.4 0.51% cvelistv5 2026-09-15