Known exploited vulnerabilities classified as CWE-917
Entries5
Ransomware-linked3
Vendors3
By vendor
2
2
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2021-45046 | Apache Log4j2 | 2023-05-01 | 99.9% | Known |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | 2022-06-02 | 99.9% | Known |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | 2021-11-03 | 99.9% | Known |
| CVE-2020-17530 | Apache Struts | 2021-11-03 | 95.9% | Unknown |
| CVE-2020-10199 | Sonatype Nexus Repository | 2021-11-03 | 99.0% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
5 KEV entries are classified as CWE-917. CWE definition (MITRE)