Vendor score = sum of Active CVE scores · Each CVE: 10 pts base, boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3
Vendor Risk Ranking
Ranked by cumulative score from Active CVEs in the selected period · AV:Network only · Click vendor name for CVE details
114 vendors
Recently Active CVEs
Newest 100 CVEs with confirmed active exploitation, sorted by published date · NEW = directly Active · POC→ACT = was POC in Vulnrichment SSVC, now confirmed Active
| Status | CVE ID | Vendor | Product | Score |
|---|---|---|---|---|
| NEW | CVE-2026-12569 | PTC | FlexPLM | 40.6 |
| NEW | CVE-2026-20262 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NEW | CVE-2026-54420 | LiteSpeed Technologies | cPanel Plugin | 22.0 |
| NEW | CVE-2026-35273 | Oracle | PeopleSoft Enterprise PeopleTools | 40.6 |
| NEW | CVE-2026-20253 | Splunk | Splunk Enterprise | 40.6 |
| NEW | CVE-2026-10520 | Ivanti | Sentry | 40.6 |
| NEW | CVE-2026-11645 | Chrome | 31.2 | |
| NEW | CVE-2026-50751 | checkpoint | Quantum Security Gateway | 40.6 |
| NEW | CVE-2026-7473 | Arista Networks | EOS | 40.6 |
| NEW | CVE-2026-48907 | joomlacontenteditor.net | Joomla Content Editor (JCE) extension for Joomla | 40.6 |
| NEW | CVE-2026-28318 | SolarWinds | Serv-U | 40.6 |
| NEW | CVE-2026-20230 | Cisco | Cisco Unified Communications Manager | 31.2 |
| NEW | CVE-2026-48027 | nrwl | nx-console | 40.6 |
| NEW | CVE-2026-45247 | Mirasvit | Full Page Cache Warmer for Magento 2 | 40.6 |
| NEW | CVE-2026-34908 | Ubiquiti Inc | EFG | 40.6 |
| NEW | CVE-2026-34909 | Ubiquiti Inc | EFG | 40.6 |
| NEW | CVE-2026-34910 | Ubiquiti Inc | EFG | 40.6 |
| NEW | CVE-2026-48172 | LiteSpeed Technologies | cPanel Plugin | 40.6 |
| NEW | CVE-2026-9082 | Drupal | Drupal core | 40.6 |
| NEW | CVE-2026-8398 | AVB Disc Soft | DAEMON Tools Lite | 40.6 |
| NEW | CVE-2026-42897 | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | 31.2 |
| NEW | CVE-2026-20182 | Cisco | Cisco Catalyst SD-WAN Controller | 40.6 |
| NEW | CVE-2026-0257 | Palo Alto Networks | Cloud NGFW | 31.2 |
| NEW | CVE-2026-45321 | @tanstack | arktype-adapter | 31.2 |
| NEW | CVE-2026-42208 | BerriAI | litellm | 40.6 |
| NEW | CVE-2026-42271 | BerriAI | litellm | 26.4 |
| NEW | CVE-2026-6973 | Ivanti | Endpoint Manager Mobile | 24.0 |
| NEW | CVE-2026-0300 | Palo Alto Networks | Cloud NGFW | 40.6 |
| NEW | CVE-2026-41940 | WebPros | cPanel | 40.6 |
| NEW | CVE-2026-32201 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NEW | CVE-2026-32202 | Microsoft | Windows 10 Version 1607 | 31.2 |
| NEW | CVE-2026-39987 | marimo-team | marimo | 40.6 |
| NEW | CVE-2026-34197 | Apache Software Foundation | Apache ActiveMQ | 26.4 |
| NEW | CVE-2026-35616 | Fortinet | FortiClientEMS | 40.6 |
| NEW | CVE-2026-5281 | Chrome | 31.2 | |
| NEW | CVE-2026-3055 | Citrix | NetScaler ADC | 40.6 |
| NEW | CVE-2026-33634 | BerriAI | litellm | 26.4 |
| NEW | CVE-2026-33017 | langflow-ai | langflow | 40.6 |
| NEW | CVE-2026-3909 | Chrome | 31.2 | |
| NEW | CVE-2026-3910 | Chrome | 31.2 | |
| NEW | CVE-2026-20131 | Cisco | Cisco Secure Firewall Management Center (FMC) | 40.6 |
| NEW | CVE-2026-20122 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NEW | CVE-2026-20127 | Cisco | Cisco Catalyst SD-WAN Manager | 40.6 |
| NEW | CVE-2026-20133 | Cisco | Cisco Catalyst SD-WAN Manager | 26.4 |
| NEW | CVE-2026-22719 | VMware | Telco Cloud Infrastructure | 26.0 |
| NEW | CVE-2026-22769 | Dell | RecoverPoint for Virtual Machines | 40.6 |
| NEW | CVE-2026-2441 | Chrome | 31.2 | |
| NEW | CVE-2026-25108 | Soliton Systems K.K. | FileZen | 26.4 |
| NEW | CVE-2026-21510 | Microsoft | Windows 10 Version 1607 | 31.2 |
| NEW | CVE-2026-21513 | Microsoft | Windows 10 Version 1607 | 31.2 |
| NEW | CVE-2026-1603 | Ivanti | Endpoint Manager | 40.6 |
| NEW | CVE-2026-21643 | Fortinet | FortiClientEMS | 40.6 |
| NEW | CVE-2026-1731 | BeyondTrust | Remote Support(RS) & Privileged Remote Access(PRA) | 40.6 |
| NEW | CVE-2025-15556 | notepad-plus-plus | notepad-plus-plus | 26.0 |
| NEW | CVE-2026-1281 | Ivanti | Endpoint Manager Mobile | 40.6 |
| NEW | CVE-2026-1340 | Ivanti | Endpoint Manager Mobile | 40.6 |
| NEW | CVE-2025-40536 | SolarWinds | Web Help Desk | 26.0 |
| NEW | CVE-2025-40551 | SolarWinds | Web Help Desk | 40.6 |
| NEW | CVE-2026-24858 | Fortinet | FortiAnalyzer | 40.6 |
| NEW | CVE-2026-24423 | SmarterTools | SmarterMail | 40.6 |
| NEW | CVE-2026-23760 | SmarterTools | SmarterMail | 40.6 |
| NEW | CVE-2026-20045 | Cisco | Cisco Unified Communications Manager | 40.6 |
| NEW | CVE-2026-24061 | GNU | inetutils | 40.6 |
| NEW | CVE-2026-20963 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | 40.6 |
| NEW | CVE-2025-66376 | Zimbra | Collaboration | 31.2 |
| NEW | CVE-2025-52691 | SmarterTools | SmarterMail | 40.6 |
| NEW | CVE-2025-14733 | WatchGuard | Fireware OS | 40.6 |
| NEW | CVE-2025-14847 | MongoDB Inc. | MongoDB Server | 40.6 |
| NEW | CVE-2025-68613 | n8n-io | n8n | 26.4 |
| NEW | CVE-2025-40602 | SonicWall | SMA1000 | 20.0 |
| NEW | CVE-2025-68461 | Roundcube | Webmail | 40.6 |
| NEW | CVE-2025-20393 | Cisco | Cisco Secure Email | 40.6 |
| NEW | CVE-2025-43529 | Apple | iOS and iPadOS | 31.2 |
| NEW | CVE-2025-59374 | ASUS | live update | 40.6 |
| NEW | CVE-2025-37164 | Hewlett Packard Enterprise (HPE) | HPE OneView | 40.6 |
| NEW | CVE-2025-14174 | Chrome | 31.2 | |
| NEW | CVE-2025-14611 | Gladinet | CentreStack and TrioFox | 26.0 |
| NEW | CVE-2025-8110 | gogs | gogs | 26.4 |
| NEW | CVE-2025-59718 | Fortinet | FortiOS | 40.6 |
| NEW | CVE-2025-34291 | Langflow | Langflow | 31.2 |
| NEW | CVE-2025-66644 | Array Networks | ArrayOS AG | 24.0 |
| NEW | CVE-2025-55182 | Meta | react-server-dom-parcel | 40.6 |
| NEW | CVE-2025-58360 | geoserver | geoserver | 40.6 |
| NEW | CVE-2025-58034 | Fortinet | FortiWeb | 24.0 |
| NEW | CVE-2025-13223 | Chrome | 31.2 | |
| NEW | CVE-2025-64446 | Fortinet | FortiWeb | 40.6 |
| NEW | CVE-2025-12480 | TrioFox | TrioFox | 40.6 |
| NEW | CVE-2025-64328 | FreePBX | filestore | 24.0 |
| NEW | CVE-2023-43000 | Apple | iOS and iPadOS | 31.2 |
| NEW | CVE-2025-61757 | Oracle | Identity Manager | 40.6 |
| NEW | CVE-2025-61932 | MOTEX Inc. | Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) | 40.6 |
| NEW | CVE-2025-53521 | F5 | BIG-IP | 40.6 |
| NEW | CVE-2025-59287 | Microsoft | Windows Server 2012 | 40.6 |
| NEW | CVE-2025-61884 | Oracle | Oracle Configurator | 40.6 |
| NEW | CVE-2025-11371 | Gladinet | CentreStack and TrioFox | 40.6 |
| NEW | CVE-2025-61882 | Oracle | Oracle Concurrent Processing | 40.6 |
| NEW | CVE-2025-20333 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 26.4 |
| NEW | CVE-2025-20362 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 40.6 |
| NEW | CVE-2025-10585 | Chrome | 31.2 | |
| NEW | CVE-2025-20352 | Cisco | Cisco IOS XE Catalyst SD-WAN | 26.4 |
Monthly Risk Score TrendJun 2023 – Jun 2026
Rolling 36-month cumulative score — CVEs older than 3 years expire · hover for breakdown
Ivanti
Cisco
Microsoft
Fortinet
Palo Alto Networks
Adobe
Apache Software Foundation
Oracle
SolarWinds
Citrix
Apple
Juniper Networks
SonicWall
Progress Software Corporation
Atlassian