Vulnary
(the landscape)

The critical picture, at a glance.

What’s landing, who’s most exposed, and how dangerous it really is right now.

Spiking now

what’s blowing up
CVE-2023-35078Critical· 9.8

CVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that lets unauthenticated attackers access restricted functions or data. It has a CVSS score of 9.8 and is known exploitation. CISA advises applying vendor-provided mitigations or discontinuing use of the product if mitigations are not available.

  • added to CISA KEV
  • 100% likely to be exploited
CVE-2025-53770Critical· 9.8

Microsoft SharePoint Server is vulnerable to a critical deserialization flaw that lets attackers run arbitrary code over the network. The flaw affects on‑premises SharePoint Server 2016 and 2019, and any public‑facing instances that are no longer supported. Microsoft is testing a fix, but users should apply the mitigations outlined by CISA and disconnect unsupported servers.

  • added to CISA KEV
  • 100% likely to be exploited
CVE-2024-23692Critical· 9.8

Rejetto HTTP File Server up to version 2.3m contains a critical template injection flaw that lets attackers run arbitrary commands on the server. The vulnerability is remote, requires no authentication or user interaction, and is no longer supported by the vendor.

  • added to CISA KEV
  • 99% likely to be exploited
CVE-2020-1938Critical· 9.8

Apache Tomcat’s default AJP connector can be exploited by attackers to read arbitrary files and execute code. The vulnerability allows remote code execution if the connector is reachable from untrusted networks. It is critical because it can compromise any Tomcat instance exposed to the internet.

  • added to CISA KEV
  • 99% likely to be exploited
CVE-2024-41713Critical· 9.1

A path‑traversal flaw in Mitel MiCollab’s NuPoint Unified Messaging component (up to version 9.8 SP1 FP2) lets an attacker read, change, or delete data without logging in. The bug is triggered by unsanitized input that can reach files outside the intended directory.

  • added to CISA KEV
  • 98% likely to be exploited
CVE-2022-41352Critical· 9.8

Zimbra Collaboration Suite versions 8.8.15 and 9.0 are vulnerable to a critical flaw that lets attackers upload arbitrary files via the amavis mail filter. The flaw uses a cpio extraction bug to place files in a public web directory, allowing attackers to access other users’ data. The issue is fixed by applying vendor‑supplied updates.

  • added to CISA KEV
  • 95% likely to be exploited
0
critical tracked
0.0
average CVSS
0
known-exploited
0
with public exploit

New criticals over time

last 30 days
Aug 14, 2026Sep 13, 2026

Most-affected vendors

oracle
150
microsoft
104
google
102
linux
66
ibm
50
adobe
41
mozilla
32
apache
30

How likely to be exploited

EPSS
2245
<1%
221
1–10%
24
10–50%
22
50%+

Known-exploited rate

in CISA KEV
2%39 of 2516 are known-exploited