Known exploited vulnerabilities classified as CWE-798
Entries8
Ransomware-linked1
Vendors8
By vendor
1
1
1
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-22769 | Dell RecoverPoint for Virtual Machines (RP4VMs) | 2026-02-18 | 13.3% | Unknown |
| CVE-2025-14611 | Gladinet CentreStack and Triofox | 2025-12-15 | 53.3% | Unknown |
| CVE-2019-6693 | Fortinet FortiOS | 2025-06-25 | 5.8% | Known |
| CVE-2021-44207 | Acclaim Systems USAHERDS | 2024-12-23 | 17.5% | Unknown |
| CVE-2024-28987 | SolarWinds Web Help Desk | 2024-10-15 | 93.2% | Unknown |
| CVE-2024-3272 | D-Link Multiple NAS Devices | 2024-04-11 | 98.0% | Unknown |
| CVE-2022-26138 | Atlassian Confluence | 2022-07-29 | 98.2% | Unknown |
| CVE-2020-8657 | EyesOfNetwork EyesOfNetwork | 2021-11-03 | 91.8% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
8 KEV entries are classified as CWE-798. CWE definition (MITRE)