Known exploited vulnerabilities classified as CWE-918
Entries22
Ransomware-linked10
Vendors14
By vendor
4
3
2
2
2
1
1
1
1
1
1
1
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-83548 | SonicWall SMA1000 Appliances | 2026-09-02 | 8.7% | Unknown |
| CVE-2026-49869 | Kestra Kestra OSS | 2026-09-02 | 2.0% | Unknown |
| CVE-2026-64849 | MLflow MLflow | 2026-08-19 | 9.8% | Unknown |
| CVE-2026-15409 | SonicWall SMA1000 Appliances | 2026-07-14 | 6.7% | Known |
| CVE-2026-20230 | Cisco Unified Communications Manager | 2026-06-25 | 88.2% | Unknown |
| CVE-2021-22054 | Omnissa Workspace One UEM | 2026-03-09 | 99.6% | Unknown |
| CVE-2021-22175 | GitLab GitLab | 2026-02-18 | 53.3% | Unknown |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite | 2026-02-17 | 84.4% | Unknown |
| CVE-2021-39935 | GitLab Community and Enterprise Editions | 2026-02-03 | 36.1% | Unknown |
| CVE-2025-61884 | Oracle E-Business Suite | 2025-10-20 | 95.8% | Known |
| CVE-2021-21311 | Adminer Adminer | 2025-09-29 | 98.4% | Unknown |
| CVE-2019-9621 | Synacor Zimbra Collaboration Suite (ZCS) | 2025-07-07 | 81.0% | Unknown |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | 2024-01-31 | 99.9% | Known |
| CVE-2023-41763 | Microsoft Skype for Business | 2023-10-10 | 90.3% | Unknown |
| CVE-2022-41040 | Microsoft Exchange Server | 2022-09-30 | 99.9% | Known |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | 2022-03-07 | 88.0% | Unknown |
| CVE-2021-21975 | VMware vRealize Operations Manager API | 2022-01-18 | 78.0% | Known |
| CVE-2021-40438 | Apache Apache | 2021-12-01 | 99.9% | Known |
| CVE-2021-34473 | Microsoft Exchange Server | 2021-11-03 | 99.9% | Known |
| CVE-2021-27103 | Accellion FTA | 2021-11-03 | 11.4% | Known |
| CVE-2021-26855 | Microsoft Exchange Server | 2021-11-03 | 99.9% | Known |
| CVE-2021-21985 | VMware vCenter Server | 2021-11-03 | 99.9% | Known |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
22 KEV entries are classified as CWE-918. CWE definition (MITRE)