The Human-in-the-Loop CVE Meter — machines fetch and score, a human decides what actually deserves a panic
Nothing written up yet. The machine is watching 1695 confirmed-exploited vulnerabilities in the meantime.
Confirmed exploited in the wild, newest first. Nobody has written these up — they are the raw machine output. Each row opens that vendor's own advisory where NVD lists one, and its NVD entry where it does not. How the score works →
ownCloud Improper Authentication Vulnerability
2026-08-27 · CVE-2023-49105 · ownCloud · EPSS 43.2% · CVSS 9.8
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
2026-08-26 · CVE-2021-23758 · Ajax.NET Professional · EPSS 83.6% · CVSS 9.8
Microsoft SQL Server Remote Code Execution Vulnerability
2026-08-26 · CVE-2019-1068 · Microsoft SQL Server · EPSS 52.8% · CVSS 8.8
Gitea Code Injection Vulnerability
2026-08-25 · CVE-2026-60004 · Gitea · EPSS 86.8% · CVSS 9.8
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
2026-08-24 · CVE-2026-21962 · Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in · EPSS 42.0% · CVSS 10
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
2026-08-18 · CVE-2026-33824 · Microsoft Internet Key Exchange (IKE) Service Extensions · EPSS 72.7% · CVSS 9.8
Broadcom VMware vCenter Path Traversal Vulnerability
2026-08-18 · CVE-2026-59310 · Broadcom VMware vCenter · EPSS 45.9% · CVSS 9.8
Microsoft SharePoint Weak Authentication Vulnerability
2026-08-18 · CVE-2026-55040 · Microsoft SharePoint · EPSS 39.7% · CVSS 9.1
Metabase SQL Injection Vulnerability
2026-08-11 · CVE-2026-72898 · Metabase · EPSS 82.3% · CVSS 10
Progress LoadMaster Command Injection Vulnerability
2026-08-07 · CVE-2026-8037 · Progress LoadMaster · EPSS 99.6% · CVSS 9.8
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
2026-08-05 · CVE-2026-63077 · JetBrains TeamCity · EPSS 87.7% · CVSS 9.8
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
2026-08-04 · CVE-2026-34486 · Apache Tomcat · EPSS 98.6% · CVSS 7.5
IBM Langflow Code Injection Vulnerability
2026-08-04 · CVE-2026-9198 · IBM Langflow · EPSS 45.2% · CVSS 9.8
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
2026-08-04 · CVE-2026-18556 · N-able N-central · EPSS 40.2% · CVSS 8.2
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
2026-08-03 · CVE-2026-18577 · N-able N-central · EPSS 54.1% · CVSS 8.2
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
2026-07-22 · CVE-2026-50522 · Microsoft SharePoint · EPSS 84.6% · CVSS 9.8
Check Point SmartConsole Improper Authentication Vulnerability
2026-07-22 · CVE-2026-16232 · Check Point SmartConsole · EPSS 72.1% · CVSS 9.3
WordPress Core Interpretation Conflict Vulnerability
2026-07-21 · CVE-2026-63030 · WordPress Core · EPSS 97.3% · CVSS 9.8
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
2026-07-21 · CVE-2026-0770 · Langflow · EPSS 63.4% · CVSS 9.8
WordPress Core SQL Injection Vulnerability
2026-07-21 · CVE-2026-60137 · WordPress Core · EPSS 78.3% · CVSS 5.9