Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 751800
751

Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

FortraCobalt Strike

Required actionApply updates per vendor instructions.

Added
2023-03-30
Due
2023-04-20
Priority interval
67.882.8
Coverage
85%
752

Linux Kernel Use-After-Free Vulnerability

Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user.

LinuxKernel

Required actionApply updates per vendor instructions.

Added
2023-03-30
Due
2023-04-20
Priority interval
61.378.6
Coverage
85%
753
CVE-2022-22706CISA KEVConflicting evidence

Arm Mali GPU Kernel Driver Unspecified Vulnerability

Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.

ArmMali Graphics Processing Unit (GPU)

Required actionApply updates per vendor instructions.

Added
2023-03-30
Due
2023-04-20
Priority interval
53.776.7
Coverage
73%
754
CVE-2023-26360CISA KEVConflicting evidence

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2023-03-15
Due
2023-04-05
Priority interval
81.299.2
Coverage
73%
755

Microsoft Office Outlook Privilege Escalation Vulnerability

Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2023-03-14
Due
2023-04-04
Priority interval
84.299.2
Coverage
85%
756
CVE-2023-24880CISA KEVKnown ransomware

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2023-03-14
Due
2023-04-04
Priority interval
68.783.7
Coverage
85%
757
CVE-2022-41328CISA KEVConflicting evidence

Fortinet FortiOS Path Traversal Vulnerability

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

FortinetFortiOS

Required actionApply updates per vendor instructions.

Added
2023-03-14
Due
2023-04-04
Priority interval
63.879.8
Coverage
73%
758
CVE-2021-39144CISA KEVConflicting evidence

XStream Remote Code Execution Vulnerability

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

XStreamXStream

Required actionApply updates per vendor instructions.

Added
2023-03-10
Due
2023-03-31
Priority interval
74.896.1
Coverage
73%
759
CVE-2020-5741CISA KEVConflicting evidence

Plex Media Server Remote Code Execution Vulnerability

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

PlexMedia Server

Required actionApply updates per vendor instructions.

Added
2023-03-10
Due
2023-03-31
Priority interval
73.390.1
Coverage
73%
760

Teclib GLPI Remote Code Execution Vulnerability

Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.

TeclibGLPI

Required actionApply updates per vendor instructions.

Added
2023-03-07
Due
2023-03-28
Priority interval
84.599.5
Coverage
85%
761

Apache Spark Command Injection Vulnerability

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

ApacheSpark

Required actionApply updates per vendor instructions.

Added
2023-03-07
Due
2023-03-28
Priority interval
81.396.3
Coverage
85%
762
CVE-2022-28810CISA KEVConflicting evidence

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

ZohoManageEngine

Required actionApply updates per vendor instructions.

Added
2023-03-07
Due
2023-03-28
Priority interval
73.889.5
Coverage
73%
763
CVE-2022-36537CISA KEVKnown ransomware

ZK Framework AuUploader Unspecified Vulnerability

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

ZK FrameworkAuUploader

Required actionApply updates per vendor instructions.

Added
2023-02-27
Due
2023-03-20
Priority interval
78.393.3
Coverage
85%
764
CVE-2022-47986CISA KEVKnown ransomware

IBM Aspera Faspex Code Execution Vulnerability

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.

IBMAspera Faspex

Required actionApply updates per vendor instructions.

Added
2023-02-21
Due
2023-03-14
Priority interval
84.599.5
Coverage
85%
765
CVE-2022-41223CISA KEVKnown ransomware

Mitel MiVoice Connect Code Injection Vulnerability

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

MitelMiVoice Connect

Required actionApply updates per vendor instructions.

Added
2023-02-21
Due
2023-03-14
Priority interval
63.578.5
Coverage
85%
766
CVE-2022-40765CISA KEVKnown ransomware

Mitel MiVoice Connect Command Injection Vulnerability

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

MitelMiVoice Connect

Required actionApply updates per vendor instructions.

Added
2023-02-21
Due
2023-03-14
Priority interval
63.578.5
Coverage
85%
767

Cacti Command Injection Vulnerability

Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.

CactiCacti

Required actionApply updates per vendor instructions.

Added
2023-02-16
Due
2023-03-09
Priority interval
84.599.5
Coverage
85%
768

Apple Multiple Products WebKit Type Confusion Vulnerability

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2023-02-14
Due
2023-03-07
Priority interval
68.283.2
Coverage
85%
769
CVE-2023-23376CISA KEVKnown ransomware

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2023-02-14
Due
2023-03-07
Priority interval
66.181.1
Coverage
85%
770

Microsoft Office Publisher Security Feature Bypass Vulnerability

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2023-02-14
Due
2023-03-07
Priority interval
65.280.2
Coverage
85%
771

Microsoft Windows Graphic Component Privilege Escalation Vulnerability

Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2023-02-14
Due
2023-03-07
Priority interval
64.279.2
Coverage
85%
772
CVE-2022-24990CISA KEVKnown ransomwareConflicting evidence

TerraMaster OS Remote Command Execution Vulnerability

TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.

TerraMasterTerraMaster OS

Required actionApply updates per vendor instructions.

Added
2023-02-10
Due
2023-03-03
Priority interval
77.197.8
Coverage
73%
773
CVE-2023-0669CISA KEVKnown ransomware

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.

FortraGoAnywhere MFT

Required actionApply updates per vendor instructions.

Added
2023-02-10
Due
2023-03-03
Priority interval
78.093.0
Coverage
85%
774
CVE-2015-2291CISA KEVKnown ransomware

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

IntelEthernet Diagnostics Driver for Windows

Required actionApply updates per vendor instructions.

Added
2023-02-10
Due
2023-03-03
Priority interval
64.080.5
Coverage
85%
775
CVE-2022-21587CISA KEVKnown ransomware

Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.

OracleE-Business Suite

Required actionApply updates per vendor instructions.

Added
2023-02-02
Due
2023-02-23
Priority interval
84.399.3
Coverage
85%
776

Multiple SugarCRM Products Remote Code Execution Vulnerability

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

SugarCRMMultiple Products

Required actionApply updates per vendor instructions.

Added
2023-02-02
Due
2023-02-23
Priority interval
79.994.9
Coverage
85%
777
CVE-2017-11357CISA KEVKnown ransomwareConflicting evidence

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

TelerikUser Interface (UI) for ASP.NET AJAX

Required actionApply updates per vendor instructions.

Added
2023-01-26
Due
2023-02-16
Priority interval
76.296.9
Coverage
73%
778
CVE-2022-47966CISA KEVKnown ransomware

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

ZohoManageEngine

Required actionApply updates per vendor instructions.

Added
2023-01-23
Due
2023-02-13
Priority interval
84.599.5
Coverage
85%
779

CWP Control Web Panel OS Command Injection Vulnerability

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

CWPControl Web Panel

Required actionApply updates per vendor instructions.

Added
2023-01-17
Due
2023-02-07
Priority interval
84.599.5
Coverage
85%
780
CVE-2022-41080CISA KEVKnown ransomwareConflicting evidence

Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2023-01-10
Due
2023-01-31
Priority interval
79.697.1
Coverage
73%
781

Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2023-01-10
Due
2023-01-31
Priority interval
74.989.9
Coverage
85%
782
CVE-2018-18809CISA KEVConflicting evidence

TIBCO JasperReports Library Directory Traversal Vulnerability

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

TIBCOJasperReports

Required actionApply updates per vendor instructions.

Added
2022-12-29
Due
2023-01-19
Priority interval
67.897.5
Coverage
73%
783
CVE-2018-5430CISA KEVConflicting evidence

TIBCO JasperReports Server Information Disclosure Vulnerability

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

TIBCOJasperReports

Required actionApply updates per vendor instructions.

Added
2022-12-29
Due
2023-01-19
Priority interval
64.091.0
Coverage
73%
784

Apple iOS Type Confusion Vulnerability

Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.

AppleiOS

Required actionApply updates per vendor instructions.

Added
2022-12-14
Due
2023-01-04
Priority interval
67.882.8
Coverage
85%
785
CVE-2022-42475CISA KEVKnown ransomware

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.

FortinetFortiOS

Required actionApply updates per vendor instructions.

Added
2022-12-13
Due
2023-01-03
Priority interval
84.499.4
Coverage
85%
786
CVE-2022-44698CISA KEVKnown ransomware

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

MicrosoftDefender

Required actionApply updates per vendor instructions.

Added
2022-12-13
Due
2023-01-03
Priority interval
70.985.9
Coverage
85%
787

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator.

CitrixApplication Delivery Controller (ADC) and Gateway

Required actionApply updates per vendor instructions.

Added
2022-12-13
Due
2023-01-03
Priority interval
69.884.8
Coverage
85%
788
CVE-2022-26501CISA KEVKnown ransomwareConflicting evidence

Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

VeeamBackup & Replication

Required actionApply updates per vendor instructions.

Added
2022-12-13
Due
2023-01-03
Priority interval
68.684.1
Coverage
73%
789
CVE-2022-26500CISA KEVKnown ransomwareConflicting evidence

Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

VeeamBackup & Replication

Required actionApply updates per vendor instructions.

Added
2022-12-13
Due
2023-01-03
Priority interval
61.181.9
Coverage
73%
790

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2022-12-05
Due
2022-12-26
Priority interval
70.085.0
Coverage
85%
791
CVE-2021-35587CISA KEVConflicting evidence

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.

OracleFusion Middleware

Required actionApply updates per vendor instructions.

Added
2022-11-28
Due
2022-12-19
Priority interval
78.499.1
Coverage
73%
792

Google Chromium GPU Heap Buffer Overflow Vulnerability

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium GPU

Required actionApply updates per vendor instructions.

Added
2022-11-28
Due
2022-12-19
Priority interval
75.390.3
Coverage
85%
793

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-11-14
Due
2022-12-09
Priority interval
56.771.7
Coverage
85%
794

Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-12-09
Priority interval
71.986.9
Coverage
85%
795

Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-12-09
Priority interval
63.078.0
Coverage
85%
796
CVE-2022-41073CISA KEVKnown ransomware

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-12-09
Priority interval
62.677.6
Coverage
85%
797
CVE-2021-25337CISA KEVConflicting evidence

Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370.

SamsungMobile Devices

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-11-29
Priority interval
54.476.1
Coverage
73%
798
CVE-2021-25369CISA KEVConflicting evidence

Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370.

SamsungMobile Devices

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-11-29
Priority interval
47.472.6
Coverage
73%
799
CVE-2021-25370CISA KEVConflicting evidence

Samsung Mobile Devices Memory Corruption Vulnerability

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369.

SamsungMobile Devices

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-11-29
Priority interval
52.972.1
Coverage
73%
800
CVE-2022-41091CISA KEVKnown ransomware

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-11-08
Due
2022-12-09
Priority interval
56.371.3
Coverage
85%