Vulnerability Intelligence

Exploited CVEs

1.7K
CISA KEV catalog

Ransomware-linked

338
20% of KEV

Actor-attributed

41
named groups

EPSS-scored

1.7K
861 likely-exploited (≥0.5)

KEV overdue

1.7K
past CISA due date

🔧 Top affected products

Windows
172
Multiple Products
79
Chromium V8
39
Internet Explorer
36
Flash Player
33
Office
29
Kernel
29
Win32k
25
Exchange Server
17
ColdFusion
16
Zimbra Collaboration Suite (ZCS)
15
IOS and IOS XE Software
14
Mobile Devices
13
Acrobat and Reader
13

📅 Exploited CVEs by year

2002
1
2004
2
2005
1
2006
2
2007
3
2008
6
2009
15
2010
23
2011
9
2012
22
2013
38
2014
34
2015
44
2016
59
2017
86
2018
89
2019
118
2020
146
2021
214
2022
131
2023
164
2024
164
2025
184
2026
107

🤖 CWE weakness distribution

CWE-78
93
CWE-20
91
CWE-416
89
CWE-119
84
CWE-787
84
CWE-22
70
CWE-94
62
CWE-502
61
CWE-287
36
CWE-284
33
CWE-843
32
CWE-306
32
CWE-264
31
CWE-89
27

📈 EPSS probability bands

Likely (≥.5)
861
Elevated (.1–.5)
404
Moderate (.01–.1)
353
Low (<.01)
44

🔒 Ransomware-linked share

Other exploited
1.3K
Ransomware-known
338

📈 Exploit-probability coverage

1.7K of 1.7K KEV CVEs carry a FIRST EPSS score (100%). 861 score ≥0.5 (likely exploited within 30 days). Re-run EPSS enrichment to refresh.

☠ Most dangerous exploited CVEs (ransomware · actor · EPSS · recency weighted)

#CVEVendor / ProductDangerEPSSRansomwareActorsAdded
1CVE-2025-0282Ivanti Connect Secure, Policy Secur
110.3
100.0%KNOWNUNC / China-nexus2025-01-08
2CVE-2024-40711Veeam Backup & Replication
107.0
90.4%KNOWNAkira, Fog2024-10-17
3CVE-2024-4577PHP Group PHP
106.8
100.0%KNOWNmultiple2024-06-12
4CVE-2024-3400Palo Alto Networks PAN-OS
105.8
100.0%KNOWNmultiple2024-04-12
5CVE-2024-1709ConnectWise ScreenConnect
105.0
100.0%KNOWNmultiple ransomware2024-02-22
6CVE-2024-21412Microsoft Windows
103.9
95.4%KNOWNWater Hydra2024-02-13
7CVE-2023-46604Apache ActiveMQ
103.1
99.7%KNOWNmultiple2023-11-02
8CVE-2023-4966Citrix NetScaler ADC and NetScaler
102.9
100.0%KNOWNLockBit2023-10-18
9CVE-2023-22515Atlassian Confluence Data Center and S
102.5
99.2%KNOWNnation-state + criminal2023-10-05
10CVE-2024-21762Fortinet FortiOS
101.6
84.3%KNOWNmultiple2024-02-09
11CVE-2023-3519Citrix NetScaler ADC and NetScaler
101.3
99.7%KNOWNmultiple2023-07-19
12CVE-2023-34362Progress MOVEit Transfer
100.6
99.9%KNOWNClop (TA505/FIN11)2023-06-02
13CVE-2021-45046Apache Log4j2
100.0
100.0%KNOWNmultiple2023-05-01
14CVE-2023-27350PaperCut MF/NG
99.9
100.0%KNOWNClop, LockBit2023-04-21
15CVE-2023-0669Fortra GoAnywhere MFT
98.7
100.0%KNOWNClop (TA505)2023-02-10
16CVE-2022-41040Microsoft Exchange Server
96.5
100.0%KNOWNmultiple ransomware2022-09-30
17CVE-2022-41082Microsoft Exchange Server
96.5
100.0%KNOWNmultiple ransomware2022-09-30
18CVE-2022-26134Atlassian Confluence Server/Data Cente
95.0
100.0%KNOWNmultiple2022-06-02
19CVE-2022-1388F5 BIG-IP
95.0
100.0%KNOWNmultiple2022-05-10
20CVE-2020-0796Microsoft SMBv3
95.0
99.8%KNOWNmultiple2022-02-10
21CVE-2021-44228Apache Log4j2
95.0
100.0%KNOWNmultiple (APT + criminal)2021-12-10
22CVE-2017-5638Apache Struts
95.0
100.0%KNOWNmultiple2021-11-03
23CVE-2019-0708Microsoft Remote Desktop Services
95.0
100.0%KNOWNmultiple2021-11-03
24CVE-2017-11882Microsoft Office
95.0
99.9%KNOWNmultiple (commodity + APT)2021-11-03
25CVE-2018-13379Fortinet FortiOS
95.0
100.0%KNOWNmultiple ransomware2021-11-03

🛡 Vulnerability → Malware / Ransomware / Actor

Type a full CVE id (e.g. CVE-2023-34362) for the full dossier — EPSS, KEV due-date, attributed malware/actors, entity graph & OSINT pivots.

22 vulnerabilities (use the ⇩ CSV button to export the filtered view)

CVEVendor / ProductEPSSRansomwareMalware / RansomwareActorsAddedDue date
CVE-2025-5777Citrix NetScaler ADC and Gateway100.0%KNOWNransomware (KEV-flagged)2025-07-102025-07-11 ⚠
CVE-2023-4966Citrix NetScaler ADC and NetScaler Ga100.0%KNOWNLockBit, Medusa (Citrix Bleed)LockBit2023-10-182023-11-08 ⚠
CVE-2023-3519Citrix NetScaler ADC and NetScaler Ga99.7%KNOWNwebshells, ransomware (Citrix NetScaler)multiple2023-07-192023-08-09 ⚠
CVE-2021-22941Citrix ShareFile53.6%KNOWNransomware (KEV-flagged)2022-03-252022-04-15 ⚠
CVE-2019-11634Citrix Workspace Application and Rece8.0%KNOWNransomware (KEV-flagged)2021-11-032022-05-03 ⚠
CVE-2019-13608Citrix StoreFront Server30.0%KNOWNransomware (KEV-flagged)2021-11-032022-05-03 ⚠
CVE-2019-19781Citrix Application Delivery Controlle100.0%KNOWNREvil, Ragnarok, Maze, DoppelPaymer (Citrix ADC)multiple ransomware2021-11-032022-05-03 ⚠
CVE-2026-3055Citrix NetScaler84.5%2026-03-302026-04-02 ⚠
CVE-2025-7775Citrix NetScaler19.6%2025-08-262025-08-28 ⚠
CVE-2024-8068Citrix Session Recording1.4%2025-08-252025-09-15 ⚠
CVE-2024-8069Citrix Session Recording14.7%2025-08-252025-09-15 ⚠
CVE-2025-6543Citrix NetScaler ADC and Gateway10.1%2025-06-302025-07-21 ⚠
CVE-2023-6548Citrix NetScaler ADC and NetScaler Ga3.2%2024-01-172024-01-24 ⚠
CVE-2023-6549Citrix NetScaler ADC and NetScaler Ga57.6%2024-01-172024-02-07 ⚠
CVE-2023-24489Citrix Content Collaboration94.7%2023-08-162023-09-06 ⚠
CVE-2022-27518Citrix Application Delivery Controlle6.9%2022-12-132023-01-03 ⚠
CVE-2017-6316Citrix NetScaler SD-WAN Enterprise, C72.6%2022-03-252022-04-15 ⚠
CVE-2019-12989Citrix SD-WAN and NetScaler94.1%2022-03-252022-04-15 ⚠
CVE-2019-12991Citrix SD-WAN and NetScaler74.1%2022-03-252022-04-15 ⚠
CVE-2020-8193Citrix Application Delivery Controlle88.4%2021-11-032022-05-03 ⚠
CVE-2020-8195Citrix Application Delivery Controlle33.3%2021-11-032022-05-03 ⚠
CVE-2020-8196Citrix Application Delivery Controlle26.3%2021-11-032022-05-03 ⚠
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php