• Home  
  • Exploit Likelihood Watchlist

Exploit Likelihood Watchlist

Once you have patched everything in the CISA Known Exploited Vulnerabilities catalog, the usual advice is to sort what is left by exploitation probability and work down from the top. That advice is everywhere. The list itself is not — so this page publishes it, and refreshes it daily.

Every row below is a recent vulnerability that the Exploit Prediction Scoring System rates as highly likely to be attacked in the next 30 days, and that CISA has not added to its catalog yet.

Read this first. EPSS is a statistical forecast, not a report of observed attacks. A high score means a model expects exploitation — it is not evidence that anyone has been breached, and it does not mean CISA has reviewed or endorsed this list. Confirmed exploitation is what the KEV catalog tracks; this page is deliberately the other thing: what may be about to get there.
42On the watchlist
9Above 90% probability
1674Already in CISA KEV
2459CVEs above the EPSS threshold

Severity and likelihood are different questions. CVE-2025-53771 carries a CVSS base score of 6.5 (medium) — the kind most triage queues park for later — while EPSS puts its chance of being exploited in the next 30 days at 99.9%. It is the one entry here that a severity-only process would drop today.

Exploit probability CVE CVSS Vendor What it is Published Our coverage
99.9% CVE-2025-53771 6.5 Medium under-rated microsoft Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 2025-07-20
99.5% CVE-2025-1974 9.8 Critical A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can… 2025-03-25
99.3% CVE-2025-29927 9.1 Critical vercel Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js applicatio… 2025-03-21
98.4% CVE-2025-4123 7.6 High grafana A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitr… 2025-05-22
93.2% CVE-2026-43284 8.8 High linux In the Linux kernel, the following vulnerability has been resolved:

xfrm: esp: avoid in-place decrypt on shared skb frags

MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FR…

2026-05-08
92.9% CVE-2026-43500 7.8 High linux In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present

The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE
handler in rxrpc_ver…

2026-05-11
91.2% CVE-2025-59528 10.0 Critical flowiseai Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connect… 2025-09-22
90.6% CVE-2025-34037 10.0 Critical An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed … 2025-06-24
90.0% CVE-2025-1094 8.1 High Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage… 2025-02-13
86.8% CVE-2025-49844 9.9 Critical redis Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potent… 2025-10-03
86.2% CVE-2025-24799
85.4% CVE-2025-32429
83.7% CVE-2025-47916
83.5% CVE-2025-1098
80.9% CVE-2025-21298
80.9% CVE-2025-27636
79.6% CVE-2026-41089
78.8% CVE-2025-66516
78.5% CVE-2025-0107
77.9% CVE-2025-2294
77.8% CVE-2025-32969
77.7% CVE-2025-6514
77.5% CVE-2025-48827
77.3% CVE-2025-4901
77.2% CVE-2025-26794
77.1% CVE-2025-54254
75.7% CVE-2025-3102
75.3% CVE-2025-1044
75.1% CVE-2025-29891
75.0% CVE-2025-4009
74.9% CVE-2025-6965
74.8% CVE-2025-30208
74.8% CVE-2025-11749
74.3% CVE-2025-13486
73.4% CVE-2026-2041
73.1% CVE-2026-22200
73.1% CVE-2025-6389
72.9% CVE-2026-2043
72.7% CVE-2025-34299
72.5% CVE-2026-21858
72.3% CVE-2025-8943
72.2% CVE-2025-2777

Sources: EPSS scores from FIRST.org, catalog membership from CISA KEV, descriptions and CVSS from NVD. Showing CVEs published in 2025 or later with an EPSS score above 70%, excluding anything already in KEV. Older vulnerabilities are left out on purpose: a high EPSS on a ten-year-old CVE reflects years of exploitation, not a forecast. Last updated 22 August 2026, 05:55 UTC.

About AI Post Daily

Independent coverage of artificial intelligence, machine learning, cybersecurity, and the technology shaping our future.

Contact: Get in touch

Known Exploited Vulnerabilities Tracker·AI Attack Tracker — updated daily

Security Guides

We use cookies to personalize content and ads, and to analyze traffic. By using this site, you agree to our Privacy Policy.