Трекер CVE.Что закрывать первым?
Мы объединяем CVSS, CISA KEV и EPSS в единую оценку срочности. Выберите стек, отфильтруйте то, что касается вас, следите и получайте уведомления об изменениях.
Оценка срочности · 0–100
- CVSS
- 40
- Техническая тяжесть
- KEV
- 30
- Эксплуатация в реальных атаках
- EPSS
- 30
- Вероятность за 30 дней
80 и выше: срочно · 60–79: на этой неделе · 40–59: в плане · ниже 40: наблюдать
Отслеживание стека · без регистрации
Какие технологии вы используете?
Выберите их, и мы сразу отберём из живой базы CVE, которые вас касаются.
Часто выбирают
Результаты появятся здесь, когда вы выберете технологию.
18 технологий · сопоставление по записям производитель/продукт
Вы видите все CVE. Добавьте свой стек, чтобы оставить только те, что касаются вас.
25 из 10 000+ записей
Срочность = вес CVSS + активная эксплуатация + вероятность эксплуатации (0–100).
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2021-44228Готовый эксплойт | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Критическая10,0 | KEV | 100,0 % | 10 дек. 2021 г. |
100Срочно | CVE-2019-11510Готовый эксплойт | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Критическая10,0 | KEV | 100,0 % | 8 мая 2019 г. |
100Срочно | CVE-2024-3400Готовый эксплойт | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Критическая10,0 | KEV | 100,0 % | 12 апр. 2024 г. |
100Срочно | CVE-2024-1709Готовый эксплойт | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Критическая10,0 | KEV | 100,0 % | 21 февр. 2024 г. |
100Срочно | CVE-2026-10520Готовый эксплойт | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Критическая10,0 | KEV | 99,9 % | 9 июн. 2026 г. |
100Срочно | CVE-2022-24816Готовый эксплойт | Improper Control of Generation of Code in jai-extgeosolutionsgroup · jai-ext · CWE-94 | Критическая10,0 | KEV | 99,9 % | 13 апр. 2022 г. |
100Срочно | CVE-2020-0796Готовый эксплойт | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Критическая10,0 | KEV | 99,8 % | 12 мар. 2020 г. |
100Срочно | CVE-2025-55182Готовый эксплойт | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Критическая10,0 | KEV | 99,8 % | 3 дек. 2025 г. |
100Срочно | CVE-2025-32432Готовый эксплойт | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Критическая10,0 | KEV | 99,8 % | 25 апр. 2025 г. |
100Срочно | CVE-2021-22205Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Критическая10,0 | KEV | 99,7 % | 23 апр. 2021 г. |
100Срочно | CVE-2023-20198Готовый эксплойт | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Критическая10,0 | KEV | 99,6 % | 16 окт. 2023 г. |
100Срочно | CVE-2024-4040Готовый эксплойт | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Критическая10,0 | KEV | 99,5 % | 22 апр. 2024 г. |
100Срочно | CVE-2022-0543Готовый эксплойт | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Критическая10,0 | KEV | 99,4 % | 18 февр. 2022 г. |
100Срочно | CVE-2025-32433Готовый эксплойт | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Критическая10,0 | KEV | 98,8 % | 16 апр. 2025 г. |
99Срочно | CVE-2022-26134Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 3 июн. 2022 г. |
99Срочно | CVE-2022-29464Готовый эксплойт | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Критическая9,8 | KEV | 100,0 % | 18 апр. 2022 г. |
99Срочно | CVE-2021-1498Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 100,0 % | 6 мая 2021 г. |
99Срочно | CVE-2015-1635Готовый эксплойт | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Критическая9,8 | KEV | 100,0 % | 14 апр. 2015 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2023-1671Готовый эксплойт | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Критическая9,8 | KEV | 100,0 % | 4 апр. 2023 г. |
99Срочно | CVE-2021-21985Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Критическая9,8 | KEV | 100,0 % | 26 мая 2021 г. |
99Срочно | CVE-2021-22005Готовый эксплойт | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 100,0 % | 23 сент. 2021 г. |
99Срочно | CVE-2023-22518Готовый эксплойт | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Критическая9,8 | KEV | 100,0 % | 31 окт. 2023 г. |
99Срочно | CVE-2023-27350Готовый эксплойт | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Критическая9,8 | KEV | 100,0 % | 20 апр. 2023 г. |
99Срочно | CVE-2021-26084Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 30 авг. 2021 г. |
- CVE-2021-44228100Срочно
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %apache · log4j10 дек. 2021 г.
- CVE-2019-11510100Срочно
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · connect secure8 мая 2019 г.
- CVE-2024-3400100Срочно
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %paloaltonetworks · pan-os12 апр. 2024 г.
- CVE-2024-1709100Срочно
Authentication bypass using an alternate path or channel
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %connectwise · screenconnect21 февр. 2024 г.
- CVE-2026-10520100Срочно
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · standalone sentry9 июн. 2026 г.
- CVE-2022-24816100Срочно
Improper Control of Generation of Code in jai-ext
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %geosolutionsgroup · jai-ext13 апр. 2022 г.
- CVE-2020-0796100Срочно
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 190312 мар. 2020 г.
- CVE-2025-55182100Срочно
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %facebook · react3 дек. 2025 г.
- CVE-2025-32432100Срочно
Craft CMS Allows Remote Code Execution
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %craftcms · craft cms25 апр. 2025 г.
- CVE-2021-22205100Срочно
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %gitlab · gitlab23 апр. 2021 г.
- CVE-2023-20198100Срочно
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %cisco · ios xe16 окт. 2023 г.
- CVE-2024-4040100Срочно
Unauthenticated arbitrary file read and remote code execution in CrushFTP
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %crushftp · crushftp22 апр. 2024 г.
- CVE-2022-0543100Срочно
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %redis · redis18 февр. 2022 г.
- CVE-2025-32433100Срочно
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 99 %erlang · erlang\/otp16 апр. 2025 г.
- CVE-2022-2613499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center3 июн. 2022 г.
- CVE-2022-2946499Срочно
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %wso2 · api manager18 апр. 2022 г.
- CVE-2021-149899Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2015-163599Срочно
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 714 апр. 2015 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2023-167199Срочно
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · web appliance4 апр. 2023 г.
- CVE-2021-2198599Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · vcenter server26 мая 2021 г.
- CVE-2021-2200599Срочно
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation23 сент. 2021 г.
- CVE-2023-2251899Срочно
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center31 окт. 2023 г.
- CVE-2023-2735099Срочно
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %papercut · papercut mf20 апр. 2023 г.
- CVE-2021-2608499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center30 авг. 2021 г.
Хотите прислать CVE или анализ?
Поделитесь способом обнаружения, затронутыми версиями или сведениями об устранении. Наша команда всё проверит, а ваш вклад мы опубликуем с указанием вашего имени.