ENISA EU Known Exploited Vulnerabilities (EUVD)

Known exploited CVEs from the ENISA EU Vulnerability Database (EUVD) — updated daily.

Data sourced from ENISA EUVD. View the full EUVD database for more EU vulnerability intelligence.

View all exploited vulnerabilities (KEV + sightings) →

CVE IDPS-HPSeverityCVSSVendorProduct Date AddedKEVEPSSGitHubRWDescription
CVE-2026-1731-CRITICAL9.9BeyondTrustRemote Support (RS), Privileged Remote Access (PRA)2026/06/04KEV---Affected: BeyondTrust / Remote Support (RS), Privileged Remote Access (PRA) | Description: Critical pre-authentication RCE vulnerability. | CWEs: CWE-78 | Origin source: NCSC-FI | Notes: https://www.b
CVE-2026-41940HP1CRITICAL9.8WebProscPanel2026/05/08KEV90.9%--Affected: WebPros / cPanel | Description: cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unau
CVE-2024-42009-CRITICAL9.3RoundCubeWebmail2026/04/27KEV---Affected: RoundCube / Webmail | Description: A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a
CVE-2025-4427-MEDIUM5.3IvantiEndpoint Manager Mobile (EPMM)2026/04/08KEV---Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: Medium severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE
CVE-2025-55182-CRITICAL10.0MetaReact Server Components2026/04/08KEV---Affected: Meta / React Server Components | Description: Flaw in how React decodes payloads sent to React Server Function endpoints enabled unauthenticated remote code execution. Apps supporting React
CVE-2025-22457-CRITICAL9.0IvantiIvanti Connect Secure2026/04/08KEV---Affected: Ivanti / Ivanti Connect Secure | Description: Evidence of active exploitation in the wild against ICS 9.X (end of life) and 22.7R2.5 and earlier versions since April 2025. | Threat actors: u
CVE-2025-4428-HIGH7.2IvantiEndpoint Manager Mobile (EPMM)2026/04/08KEV---Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: High severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE-2
CVE-2025-53770-CRITICAL9.8MicrosoftSharePoint2026/04/08KEV---Affected: Microsoft / SharePoint | Description: Microsoft confirmation of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July
CVE-2026-20963HP1CRITICAL9.8MicrosoftMicrosoft SharePoint2026/03/12KEV8.1%--Affected: Microsoft / Microsoft SharePoint | Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | CWEs: CWE-502
CVE-2026-1281-CRITICAL9.8IvantiEndpoint Manager Mobile (EPMM)2026/01/29KEV---Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Threat actors
CVE-2026-1340HP1CRITICAL9.8IvantiEndpoint Manager Mobile (EPMM)2026/01/29KEV73.9%--Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Threat actors
CVE-2025-59718-CRITICAL9.8FortinetFortiOS,FortiProxy,FortiSwitchManager2026/01/27KEV---Affected: Fortinet / FortiOS,FortiProxy,FortiSwitchManager | Description: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS, FortiProxy, FortiSwitchManager allows an
CVE-2025-59719-CRITICAL9.8FortinetFortiweb2026/01/27KEV---Affected: Fortinet / Fortiweb | Description: An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb may allow an unauthenticated attacker to bypass the FortiCloud SSO l
CVE-2025-25231-HIGH7.5OmnissaOmnissa Workspace ONE UEM09/09/25KEV---Affected: Omnissa / Omnissa Workspace ONE UEM | Description: Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensit
CVE-2025-6543-CRITICAL9.2CitrixCitrix ADC and Citrix Gateway18/07/25KEV---Affected: Citrix / Citrix ADC and Citrix Gateway | Origin source: cnw
CVE-2010-0738-MEDIUM5.3Red HatJBoss Application Server14/07/25KEV---Affected: Red Hat / JBoss Application Server | Description: this management interface allows administrative operations to be performed without adequate access controls allowing a remote attacker to in
CVE-2017-12149-CRITICAL9.8Red HatJBoss Application Server14/07/25KEV---Affected: Red Hat / JBoss Application Server | Description: the servlet exposes an endpoint that allows you to invoke Java Management Extensions (JMX) operations without any authentication or access c
CVE-2011-4085-MEDIUM6.8Red HatJBoss Application Server14/07/25KEV---Affected: Red Hat / JBoss Application Server | Description: some management interfaces remain accessible and lack effective access control mechanisms | Origin source: CERT Italia | Notes: https://www.
CVE-2015-7501-CRITICAL9.8ApacheCommons Collections library14/07/25KEV---Affected: Apache / Commons Collections library | Description: the system accepts serialized objects without verifying their origin or reliability allowing an attacker to send specially crafted payload
CVE-2024-55591-CRITICAL9.8FortinetFortiOS/FortiProxy13/02/25KEV---Affected: Fortinet / FortiOS/FortiProxy | Description: authentication bypass using an alternate path or channel vulnerability | Exploitation type: ransomware | CWEs: CWE-288 | Origin source: cnw
CVE-2023-27997-CRITICAL9.8FortinetFortiOS and FortiProxy23/01/25KEV---Affected: Fortinet / FortiOS and FortiProxy | Exploitation type: ransomware | Origin source: cnw
CVE-2017-0144-HIGH8.8MicrosoftWindows (SMBv1 - EternalBlue)23/01/25KEV---Affected: Microsoft / Windows (SMBv1 - EternalBlue) | Exploitation type: ransomware | Origin source: cnw
CVE-2023-3519-CRITICAL9.8CitrixCitrix ADC and Citrix Gateway23/01/25KEV---Affected: Citrix / Citrix ADC and Citrix Gateway | Exploitation type: ransomware | Origin source: cnw
CVE-2023-48788-CRITICAL9.8FortinetFortiClientEMS23/01/25KEV---Affected: Fortinet / FortiClientEMS | Exploitation type: ransomware | Origin source: cnw
CVE-2023-46604-CRITICAL10.0ApacheActiveMQ23/01/25KEV---Affected: Apache / ActiveMQ | Exploitation type: ransomware | Origin source: cnw
CVE-2020-1472-MEDIUM5.5MicrosoftNetlogon (ZeroLogon)23/01/25KEV---Affected: Microsoft / Netlogon (ZeroLogon) | Exploitation type: ransomware | Origin source: cnw
CVE-2020-0787-HIGH7.8MicrosoftWindows BITS2623/01/25KEV---Affected: Microsoft / Windows BITS26 | Exploitation type: ransomware | Origin source: cnw
CVE-2023-22515-CRITICAL9.8AtlassianConfluence Server and Data Server23/01/25KEV---Affected: Atlassian / Confluence Server and Data Server | Exploitation type: ransomware | Origin source: cnw
CVE-2023-46747-CRITICAL9.8F5BIG-IP23/01/25KEV---Affected: F5 / BIG-IP | Exploitation type: ransomware | Origin source: cnw
CVE-2024-9380-HIGH7.2IvantiCSA (Cloud Services Appliance)17/01/25KEV---Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw
CVE-2024-8963-CRITICAL9.4IvantiCSA (Cloud Services Appliance)17/01/25KEV---Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw
CVE-2024-8190-HIGH7.2IvantiCSA (Cloud Services Appliance)17/01/25KEV---Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw