Known exploited vulnerabilities classified as CWE-23
Entries9
Ransomware-linked4
Vendors7
By vendor
3
1
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-34926 | Trend Micro Apex One | 2026-05-21 | 0.5% | Unknown |
| CVE-2024-27199 | JetBrains TeamCity | 2026-04-20 | 99.9% | Known |
| CVE-2025-64446 | Fortinet FortiWeb | 2025-11-14 | 91.8% | Unknown |
| CVE-2022-37042 | Synacor Zimbra Collaboration Suite (ZCS) | 2022-08-11 | 91.8% | Known |
| CVE-2021-38163 | SAP NetWeaver | 2022-06-09 | 36.8% | Unknown |
| CVE-2020-5410 | VMware Tanzu Spring Cloud Configuration (Config) Server | 2022-03-25 | 95.5% | Unknown |
| CVE-2021-22017 | VMware vCenter Server | 2022-01-10 | 49.1% | Unknown |
| CVE-2021-22005 | VMware vCenter Server | 2021-11-03 | 99.9% | Known |
| CVE-2021-21972 | VMware vCenter Server | 2021-11-03 | 99.8% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
9 KEV entries are classified as CWE-23. CWE definition (MITRE)