仅看 CVSS 严重度会漏掉的、真正被利用的漏洞。这里收录了 CVSS 低于 HIGH(6.9 以下)但 VPI 达到 70 以上的 CVE。
与 CVSS 严重度不同,VPI 是一个 0~100 的优先级分数,告诉你现在应该先处理什么。
计算方式为:影响度(CVSS×10)× 利用倍数(已列入 KEV 为 1.5 / 存在 PoC 为 1.2 / EPSS 前 10% 为 1.1 / 无信号为 1.0,仅采用最强的一个信号)+ 勒索软件加成(+5)。
每个分数的依据(影响度·利用信号·倍数)都会公开 — 只需将鼠标悬停在 VPI 徽章上即可查看。
这是发布时的初步估算值,倍数与阈值会随着数据积累而调整。
| CVE ID | 标题 | 严重程度 | 情报来源 | ||||
|---|---|---|---|---|---|---|---|
| On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tun | MEDIUM | 6.9v4.0 | 100 | 0.8% |
KEV |
| 2026. 06. 05. |
| CVE-2026-34926 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability. | MEDIUM | 6.7v3.1 | 100 | 12.7% | KEV KISA | 2026. 05. 21. |
| CVE-2024-12987 | A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade | MEDIUM | 6.9v4.0 | 100 | 98.1% | KEV | 2024. 12. 27. |
| CVE-2024-9474 | A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability. | MEDIUM | 6.9v4.0 | 100 | 94.8% | KEV KISA | 2024. 11. 18. |
| CVE-2022-41328 | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands. | MEDIUM | 6.7v3.1 | 100 | 12.3% | KEV | 2023. 03. 07. |
| CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field. | MEDIUM | 6.8v3.1 | 100 | 70.5% | KEV | 2022. 04. 18. |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | MEDIUM | 6.6v3.1 | 100 | 99.8% | KEV KISA | 2021. 05. 11. |
| CVE-2021-22204 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | MEDIUM | 6.8v3.1 | 100 | 100.0% | KEV | 2021. 04. 23. |
| CVE-2020-11023 | Potential XSS vulnerability in jQuery | — | 6.9v3.1 | 100 | 83.8% | KEV | 2020. 04. 29. |
| CVE-2020-3153 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations | MEDIUM | 6.5v3.1 | 100 | 28.3% | KEV | 2020. 02. 19. |
| CVE-2019-6693 | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set). | MEDIUM | 6.5v3.1 | 100 | 5.7% | KEV | 2019. 11. 21. |
| CVE-2018-2380 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs. | MEDIUM | 6.6v3.1 | 100 | 28.9% | KEV | 2018. 03. 01. |
| CVE-2016-3351 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | MEDIUM | 6.5v3.1 | 100 | 26.3% | KEV | 2016. 09. 14. |
| CVE-2013-3993 | IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls. | MEDIUM | 6.5v3.1 | 100 | 5.2% | KEV | 2014. 07. 07. |
| CVE-2009-3960 | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents. | MEDIUM | 6.5v3.1 | 100 | 90.0% | KEV | 2010. 02. 15. |
| CVE-2025-40602 | A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | MEDIUM | 6.6v3.1 | 99 | 1.9% | KEV | 2025. 12. 18. |
| CVE-2024-12686 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user. | MEDIUM | 6.6v3.1 | 99 | 13.8% | KEV | 2024. 12. 18. |
| CVE-2023-20109 | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could | MEDIUM | 6.6v3.1 | 99 | 2.3% | KEV | 2023. 09. 27. |
| CVE-2015-1769 | Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability." | MEDIUM | 6.6v3.1 | 99 | 4.3% | KEV KISA | 2015. 08. 15. |
| CVE-2026-20262 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful explo | MEDIUM | 6.5v3.1 | 97.50 | 7.7% | KEV | 2026. 06. 15. |