Data sources
Every row is built from authoritative, public security feeds, refreshed automatically.
Every row is built from authoritative, public security feeds, refreshed automatically.
CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15 vulnerabilities, led by Citrix NetScaler, Cisco IOS XE, Fortinet FortiOS, and Progress MOVEit Transfer. Every one is in the live CISA KEV table above with current EPSS and ransomware flags; each row here links to its detail page.
| CVE | Vendor and product | Vulnerability type |
|---|---|---|
| CVE-2023-3519 | Citrix NetScaler ADC and Gateway | Code injection (remote code execution) |
| CVE-2023-4966 | Citrix NetScaler ADC and Gateway (Citrix Bleed) | Sensitive information disclosure |
| CVE-2023-20198 | Cisco IOS XE Web UI | Privilege escalation |
| CVE-2023-20273 | Cisco IOS XE Web UI | Command injection |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | Heap buffer overflow (remote code execution) |
| CVE-2023-34362 | Progress MOVEit Transfer | SQL injection |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | Broken access control |
| CVE-2021-44228 | Apache Log4j2 (Log4Shell) | Remote code execution |
| CVE-2023-2868 | Barracuda Email Security Gateway | Improper input validation (command injection) |
| CVE-2022-47966 | Zoho ManageEngine (multiple products) | Remote code execution |
| CVE-2023-27350 | PaperCut MF and NG | Improper access control (remote code execution) |
| CVE-2020-1472 | Microsoft Netlogon (Zerologon) | Privilege escalation |
| CVE-2023-42793 | JetBrains TeamCity | Authentication bypass (remote code execution) |
| CVE-2023-23397 | Microsoft Outlook | Privilege escalation |
| CVE-2023-49103 | ownCloud graphapi | Information disclosure |
Two entries are Microsoft products, Zerologon and the Outlook flaw; for those see the Microsoft patch tracker. Browse the full exploited history for a vendor: Citrix, Cisco, Fortinet, Apache, Ivanti, Palo Alto Networks, VMware, or the full vendor index.
This is the whole actively-exploited non-Microsoft catalog. Senserva matches it against the third-party software, devices, and apps it finds in your Microsoft 365, Intune, Defender, and Entra ID estate, then ranks what is exposed by CISA KEV and EPSS, so you patch the few that matter first.
Senserva cross-references this catalog with the software and devices it inventories, so you see which exploited CVEs you are actually exposed to.
CVE and patch managementThird-party exposure sits with configuration, logs, and Conditional Access in one model, so real risk rises to the top.
The unified security modelBring your own AI. It reads the connected model and produces validated fixes you review before anything changes.
AI remediationExposed, exploited CVEs map straight to the frameworks an auditor asks about, from the same model.
Compliance evidenceCISA's Known Exploited Vulnerabilities (KEV) catalog is the U.S. government's authoritative list of CVEs confirmed to be exploited in the wild. Because exploitation is proven, KEV entries are the vulnerabilities to patch first, ahead of anything scored only by severity.
EPSS (Exploit Prediction Scoring System) from FIRST.org estimates the probability that a CVE will be exploited in the next 30 days. This tracker ranks the exploited vulnerabilities by EPSS so the most likely-to-be-attacked rise to the top.
Every actively exploited, third-party (non-Microsoft) vulnerability in CISA KEV: Apache, Cisco, Citrix, Fortinet, Ivanti, VMware, and the rest, with vendor, product, CVSS, ransomware use, and the vendor advisory that fixes each one. Microsoft vulnerabilities are on the separate Microsoft patch tracker.
Daily. The data refreshes from CISA KEV, NVD, and FIRST.org EPSS, cross-referenced with VulnCheck KEV and the ENISA EUVD, so newly exploited CVEs appear within a day of being cataloged.
Yes, free with no sign-in. You can search, sort, and export to CSV or JSON. Running Senserva adds the part a public list cannot: which of these exploited CVEs your own estate is actually exposed to, ranked, so you fix the right things first.
Yes. A free copy-paste AI prompt near the table is generated from the live data each day and carries the top exploited CVEs, with vendor, CVSS, EPSS, ransomware use, and CISA due dates, into Claude, ChatGPT, or Copilot for triage in your own words.
CISA and its international partners publish a yearly joint advisory naming the CVEs attackers exploited most. For 2023, advisory AA24-317A lists 15, led by Citrix NetScaler (CVE-2023-3519 and Citrix Bleed CVE-2023-4966), Cisco IOS XE (CVE-2023-20198), Fortinet FortiOS (CVE-2023-27997), and Progress MOVEit Transfer (CVE-2023-34362). All 15 are listed above and appear in the live table with current EPSS and ransomware flags.
CISA adds CVEs to the KEV catalog on a rolling basis, often several times a week, whenever exploitation is confirmed. This tracker refreshes daily, so new additions appear within a day of being cataloged. The most recent ones are on the exploited this week page.
Many do. CISA flags the KEV entries known to be used in ransomware campaigns, and those are marked in the Ransomware column here. A KEV listing already means exploitation is confirmed, so treat every entry, ransomware-flagged or not, as urgent and patch by the CISA due date shown in the table.
Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.
Reference: the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together, and where third-party patch vendors fit in.
Data notice: the trackers, feeds, and API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data and accepts no liability for actions taken based on it; verify against the primary source before acting. All use of this data is subject to the Senserva EULA.
This tracker follows exploited vulnerabilities beyond Microsoft's own products. To see where your own Microsoft 365 stands against today's threats, run a free, unlimited audit.
Three free audits, across every tenant you manage: 1 scan to find, 2 to review your fixes. It finds:
Includes our advanced Claude MCP: everything you need to run full audits.
Start my free auditWe use Google Analytics cookies to understand site traffic. No findings, scan data, or tenant data are sent. Privacy policy.