ENISA EU Known Exploited Vulnerabilities (EUVD)
Known exploited CVEs from the ENISA EU Vulnerability Database (EUVD) — updated daily.
Data sourced from ENISA EUVD. View the full EUVD database for more EU vulnerability intelligence.
View all exploited vulnerabilities (KEV + sightings) →
| CVE ID | PS-HP | Severity | CVSS | Vendor | Product | Date Added | KEV | EPSS | GitHub | RW | Description |
|---|---|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-1731 | - | CRITICAL | 9.9 | BeyondTrust | Remote Support (RS), Privileged Remote Access (PRA) | 2026/06/04 | KEV | - | - | - | Affected: BeyondTrust / Remote Support (RS), Privileged Remote Access (PRA) | Description: Critical pre-authentication RCE vulnerability. | CWEs: CWE-78 | Origin source: NCSC-FI | Notes: https://www.b |
| CVE-2026-41940 | HP1 | CRITICAL | 9.8 | WebPros | cPanel | 2026/05/08 | KEV | 90.9% | - | - | Affected: WebPros / cPanel | Description: cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unau |
| CVE-2024-42009 | - | CRITICAL | 9.3 | RoundCube | Webmail | 2026/04/27 | KEV | - | - | - | Affected: RoundCube / Webmail | Description: A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a |
| CVE-2025-4427 | - | MEDIUM | 5.3 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026/04/08 | KEV | - | - | - | Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: Medium severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE |
| CVE-2025-55182 | - | CRITICAL | 10.0 | Meta | React Server Components | 2026/04/08 | KEV | - | - | - | Affected: Meta / React Server Components | Description: Flaw in how React decodes payloads sent to React Server Function endpoints enabled unauthenticated remote code execution. Apps supporting React |
| CVE-2025-22457 | - | CRITICAL | 9.0 | Ivanti | Ivanti Connect Secure | 2026/04/08 | KEV | - | - | - | Affected: Ivanti / Ivanti Connect Secure | Description: Evidence of active exploitation in the wild against ICS 9.X (end of life) and 22.7R2.5 and earlier versions since April 2025. | Threat actors: u |
| CVE-2025-4428 | - | HIGH | 7.2 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026/04/08 | KEV | - | - | - | Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: High severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE-2 |
| CVE-2025-53770 | - | CRITICAL | 9.8 | Microsoft | SharePoint | 2026/04/08 | KEV | - | - | - | Affected: Microsoft / SharePoint | Description: Microsoft confirmation of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July |
| CVE-2026-20963 | HP1 | CRITICAL | 9.8 | Microsoft | Microsoft SharePoint | 2026/03/12 | KEV | 8.1% | - | - | Affected: Microsoft / Microsoft SharePoint | Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | CWEs: CWE-502 |
| CVE-2026-1281 | - | CRITICAL | 9.8 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026/01/29 | KEV | - | - | - | Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Threat actors |
| CVE-2026-1340 | HP1 | CRITICAL | 9.8 | Ivanti | Endpoint Manager Mobile (EPMM) | 2026/01/29 | KEV | 73.9% | - | - | Affected: Ivanti / Endpoint Manager Mobile (EPMM) | Description: A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Threat actors |
| CVE-2025-59718 | - | CRITICAL | 9.8 | Fortinet | FortiOS,FortiProxy,FortiSwitchManager | 2026/01/27 | KEV | - | - | - | Affected: Fortinet / FortiOS,FortiProxy,FortiSwitchManager | Description: A improper verification of cryptographic signature vulnerability in Fortinet FortiOS, FortiProxy, FortiSwitchManager allows an |
| CVE-2025-59719 | - | CRITICAL | 9.8 | Fortinet | Fortiweb | 2026/01/27 | KEV | - | - | - | Affected: Fortinet / Fortiweb | Description: An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb may allow an unauthenticated attacker to bypass the FortiCloud SSO l |
| CVE-2025-25231 | - | HIGH | 7.5 | Omnissa | Omnissa Workspace ONE UEM | 09/09/25 | KEV | - | - | - | Affected: Omnissa / Omnissa Workspace ONE UEM | Description: Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensit |
| CVE-2025-6543 | - | CRITICAL | 9.2 | Citrix | Citrix ADC and Citrix Gateway | 18/07/25 | KEV | - | - | - | Affected: Citrix / Citrix ADC and Citrix Gateway | Origin source: cnw |
| CVE-2010-0738 | - | MEDIUM | 5.3 | Red Hat | JBoss Application Server | 14/07/25 | KEV | - | - | - | Affected: Red Hat / JBoss Application Server | Description: this management interface allows administrative operations to be performed without adequate access controls allowing a remote attacker to in |
| CVE-2017-12149 | - | CRITICAL | 9.8 | Red Hat | JBoss Application Server | 14/07/25 | KEV | - | - | - | Affected: Red Hat / JBoss Application Server | Description: the servlet exposes an endpoint that allows you to invoke Java Management Extensions (JMX) operations without any authentication or access c |
| CVE-2011-4085 | - | MEDIUM | 6.8 | Red Hat | JBoss Application Server | 14/07/25 | KEV | - | - | - | Affected: Red Hat / JBoss Application Server | Description: some management interfaces remain accessible and lack effective access control mechanisms | Origin source: CERT Italia | Notes: https://www. |
| CVE-2015-7501 | - | CRITICAL | 9.8 | Apache | Commons Collections library | 14/07/25 | KEV | - | - | - | Affected: Apache / Commons Collections library | Description: the system accepts serialized objects without verifying their origin or reliability allowing an attacker to send specially crafted payload |
| CVE-2024-55591 | - | CRITICAL | 9.8 | Fortinet | FortiOS/FortiProxy | 13/02/25 | KEV | - | - | - | Affected: Fortinet / FortiOS/FortiProxy | Description: authentication bypass using an alternate path or channel vulnerability | Exploitation type: ransomware | CWEs: CWE-288 | Origin source: cnw |
| CVE-2023-27997 | - | CRITICAL | 9.8 | Fortinet | FortiOS and FortiProxy | 23/01/25 | KEV | - | - | - | Affected: Fortinet / FortiOS and FortiProxy | Exploitation type: ransomware | Origin source: cnw |
| CVE-2017-0144 | - | HIGH | 8.8 | Microsoft | Windows (SMBv1 - EternalBlue) | 23/01/25 | KEV | - | - | - | Affected: Microsoft / Windows (SMBv1 - EternalBlue) | Exploitation type: ransomware | Origin source: cnw |
| CVE-2023-3519 | - | CRITICAL | 9.8 | Citrix | Citrix ADC and Citrix Gateway | 23/01/25 | KEV | - | - | - | Affected: Citrix / Citrix ADC and Citrix Gateway | Exploitation type: ransomware | Origin source: cnw |
| CVE-2023-48788 | - | CRITICAL | 9.8 | Fortinet | FortiClientEMS | 23/01/25 | KEV | - | - | - | Affected: Fortinet / FortiClientEMS | Exploitation type: ransomware | Origin source: cnw |
| CVE-2023-46604 | - | CRITICAL | 10.0 | Apache | ActiveMQ | 23/01/25 | KEV | - | - | - | Affected: Apache / ActiveMQ | Exploitation type: ransomware | Origin source: cnw |
| CVE-2020-1472 | - | MEDIUM | 5.5 | Microsoft | Netlogon (ZeroLogon) | 23/01/25 | KEV | - | - | - | Affected: Microsoft / Netlogon (ZeroLogon) | Exploitation type: ransomware | Origin source: cnw |
| CVE-2020-0787 | - | HIGH | 7.8 | Microsoft | Windows BITS26 | 23/01/25 | KEV | - | - | - | Affected: Microsoft / Windows BITS26 | Exploitation type: ransomware | Origin source: cnw |
| CVE-2023-22515 | - | CRITICAL | 9.8 | Atlassian | Confluence Server and Data Server | 23/01/25 | KEV | - | - | - | Affected: Atlassian / Confluence Server and Data Server | Exploitation type: ransomware | Origin source: cnw |
| CVE-2023-46747 | - | CRITICAL | 9.8 | F5 | BIG-IP | 23/01/25 | KEV | - | - | - | Affected: F5 / BIG-IP | Exploitation type: ransomware | Origin source: cnw |
| CVE-2024-9380 | - | HIGH | 7.2 | Ivanti | CSA (Cloud Services Appliance) | 17/01/25 | KEV | - | - | - | Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw |
| CVE-2024-8963 | - | CRITICAL | 9.4 | Ivanti | CSA (Cloud Services Appliance) | 17/01/25 | KEV | - | - | - | Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw |
| CVE-2024-8190 | - | HIGH | 7.2 | Ivanti | CSA (Cloud Services Appliance) | 17/01/25 | KEV | - | - | - | Affected: Ivanti / CSA (Cloud Services Appliance) | Origin source: cnw |