Once you have patched everything in the CISA Known Exploited Vulnerabilities catalog, the usual advice is to sort what is left by exploitation probability and work down from the top. That advice is everywhere. The list itself is not — so this page publishes it, and refreshes it daily.
Every row below is a recent vulnerability that the Exploit Prediction Scoring System rates as highly likely to be attacked in the next 30 days, and that CISA has not added to its catalog yet.
Severity and likelihood are different questions. CVE-2025-53771 carries a CVSS base score of 6.5 (medium) — the kind most triage queues park for later — while EPSS puts its chance of being exploited in the next 30 days at 99.9%. It is the one entry here that a severity-only process would drop today.
| Exploit probability | CVE | CVSS | Vendor | What it is | Published | Our coverage |
|---|---|---|---|---|---|---|
| 99.9% | CVE-2025-53771 | 6.5 Medium under-rated | microsoft | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 2025-07-20 | — |
| 99.5% | CVE-2025-1974 | 9.8 Critical | — | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can… | 2025-03-25 | — |
| 99.3% | CVE-2025-29927 | 9.1 Critical | vercel | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js applicatio… | 2025-03-21 | — |
| 98.4% | CVE-2025-4123 | 7.6 High | grafana | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitr… | 2025-05-22 | — |
| 93.2% | CVE-2026-43284 | 8.8 High | linux | In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP |
2026-05-08 | — |
| 92.9% | CVE-2026-43500 | 7.8 High | linux | In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE |
2026-05-11 | — |
| 91.2% | CVE-2025-59528 | 10.0 Critical | flowiseai | Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connect… | 2025-09-22 | — |
| 90.6% | CVE-2025-34037 | 10.0 Critical | — | An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed … | 2025-06-24 | — |
| 90.0% | CVE-2025-1094 | 8.1 High | — | Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage… | 2025-02-13 | — |
| 86.8% | CVE-2025-49844 | 9.9 Critical | redis | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potent… | 2025-10-03 | — |
| 86.2% | CVE-2025-24799 | — | — | — | — | |
| 85.4% | CVE-2025-32429 | — | — | — | — | |
| 83.7% | CVE-2025-47916 | — | — | — | — | |
| 83.5% | CVE-2025-1098 | — | — | — | — | |
| 80.9% | CVE-2025-21298 | — | — | — | — | |
| 80.9% | CVE-2025-27636 | — | — | — | — | |
| 79.6% | CVE-2026-41089 | — | — | — | — | |
| 78.8% | CVE-2025-66516 | — | — | — | — | |
| 78.5% | CVE-2025-0107 | — | — | — | — | |
| 77.9% | CVE-2025-2294 | — | — | — | — | |
| 77.8% | CVE-2025-32969 | — | — | — | — | |
| 77.7% | CVE-2025-6514 | — | — | — | — | |
| 77.5% | CVE-2025-48827 | — | — | — | — | |
| 77.3% | CVE-2025-4901 | — | — | — | — | |
| 77.2% | CVE-2025-26794 | — | — | — | — | |
| 77.1% | CVE-2025-54254 | — | — | — | — | |
| 75.7% | CVE-2025-3102 | — | — | — | — | |
| 75.3% | CVE-2025-1044 | — | — | — | — | |
| 75.1% | CVE-2025-29891 | — | — | — | — | |
| 75.0% | CVE-2025-4009 | — | — | — | — | |
| 74.9% | CVE-2025-6965 | — | — | — | — | |
| 74.8% | CVE-2025-30208 | — | — | — | — | |
| 74.8% | CVE-2025-11749 | — | — | — | — | |
| 74.3% | CVE-2025-13486 | — | — | — | — | |
| 73.4% | CVE-2026-2041 | — | — | — | — | |
| 73.1% | CVE-2026-22200 | — | — | — | — | |
| 73.1% | CVE-2025-6389 | — | — | — | — | |
| 72.9% | CVE-2026-2043 | — | — | — | — | |
| 72.7% | CVE-2025-34299 | — | — | — | — | |
| 72.5% | CVE-2026-21858 | — | — | — | — | |
| 72.3% | CVE-2025-8943 | — | — | — | — | |
| 72.2% | CVE-2025-2777 | — | — | — | — |
Sources: EPSS scores from FIRST.org, catalog membership from CISA KEV, descriptions and CVSS from NVD. Showing CVEs published in 2025 or later with an EPSS score above 70%, excluding anything already in KEV. Older vulnerabilities are left out on purpose: a high EPSS on a ten-year-old CVE reflects years of exploitation, not a forecast. Last updated 22 August 2026, 05:55 UTC.

