The US Cybersecurity and Infrastructure Security Agency has established today a public catalog of vulnerabilities known to be exploited in the wild and has issued a binding operational directive ordering US federal agencies to patch affected systems within specific timeframes and deadlines.
The catalog —available online here— currently lists 306 vulnerabilities, with some as old as 2010, that are still being exploited in the wild.
This includes vulnerabilities for products from Cisco, Google, Microsoft, Apple, Oracle, Adobe, Atlassian, IBM, and many other companies, small and large alike.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog