Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 9511000
951
CVE-2018-19949CISA KEVKnown ransomwareConflicting evidence

QNAP NAS File Station Command Injection Vulnerability

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

QNAPNetwork Attached Storage (NAS)

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
68.689.4
Coverage
73%
952
CVE-2016-4656CISA KEVConflicting evidence

Apple iOS Memory Corruption Vulnerability

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

AppleiOS

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
69.288.0
Coverage
73%
953
CVE-2017-0149CISA KEVConflicting evidence

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
69.887.8
Coverage
73%
954
CVE-2017-0210CISA KEVConflicting evidence

Microsoft Internet Explorer Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
59.685.8
Coverage
73%
955
CVE-2016-4655CISA KEVConflicting evidence

Apple iOS Information Disclosure Vulnerability

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

AppleiOS

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
65.384.3
Coverage
73%
956
CVE-2016-6367CISA KEVConflicting evidence

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CiscoAdaptive Security Appliance (ASA)

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
66.584.0
Coverage
73%
957
CVE-2018-19943CISA KEVKnown ransomwareConflicting evidence

QNAP NAS File Station Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPNetwork Attached Storage (NAS)

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
57.283.4
Coverage
73%
958
CVE-2016-3298CISA KEVConflicting evidence

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
58.082.7
Coverage
73%
959
CVE-2016-3351CISA KEVKnown ransomwareConflicting evidence

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

MicrosoftInternet Explorer and Edge

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
56.881.5
Coverage
73%
960
CVE-2017-0005CISA KEVConflicting evidence

Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
63.981.1
Coverage
73%
961
CVE-2018-19953CISA KEVKnown ransomwareConflicting evidence

QNAP NAS File Station Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

QNAPNetwork Attached Storage (NAS)

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
60.580.0
Coverage
73%
962
CVE-2017-0022CISA KEVConflicting evidence

Microsoft XML Core Services Information Disclosure Vulnerability

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

MicrosoftXML Core Services

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
59.379.8
Coverage
73%
963

Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
62.178.6
Coverage
85%
964

Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-24
Due
2022-06-14
Priority interval
60.175.1
Coverage
85%
965
CVE-2019-11708CISA KEVConflicting evidence

Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
79.994.9
Coverage
73%
966
CVE-2019-13720CISA KEVConflicting evidence

Google Chrome WebAudio Use-After-Free Vulnerability

Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

GoogleChrome WebAudio

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
74.194.1
Coverage
73%
967
CVE-2019-18426CISA KEVConflicting evidence

WhatsApp Cross-Site Scripting Vulnerability

A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.

Meta PlatformsWhatsApp

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
71.092.0
Coverage
73%
968
CVE-2018-5002CISA KEVConflicting evidence

Adobe Flash Player Stack-based Buffer Overflow Vulnerability

Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-05-23
Due
2022-06-13
Priority interval
69.690.1
Coverage
73%
969
CVE-2019-11707CISA KEVConflicting evidence

Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
71.189.3
Coverage
73%
970
CVE-2019-5786CISA KEVConflicting evidence

Google Chrome Blink Use-After-Free Vulnerability

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.

GoogleChrome Blink

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
66.486.9
Coverage
73%
971
CVE-2021-30883CISA KEVConflicting evidence

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
67.285.9
Coverage
73%
972
CVE-2019-7287CISA KEVConflicting evidence

Apple iOS Memory Corruption Vulnerability

Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.

AppleiOS

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
63.882.5
Coverage
73%
973
CVE-2019-7286CISA KEVConflicting evidence

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
64.982.4
Coverage
73%
974

WebKitGTK Memory Corruption Vulnerability

WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.

WebKitGTKWebKitGTK

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
64.579.5
Coverage
85%
975

Microsoft Windows Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
62.278.7
Coverage
85%
976
CVE-2019-1385CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
59.078.3
Coverage
73%
977

Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

CiscoIOS XR

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
62.978.1
Coverage
85%
978

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
61.578.0
Coverage
85%
979
CVE-2020-0638CISA KEVKnown ransomwareConflicting evidence

Microsoft Update Notification Manager Privilege Escalation Vulnerability

Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftUpdate Notification Manager

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
54.977.9
Coverage
73%
980
CVE-2019-0880CISA KEVConflicting evidence

Microsoft Windows Privilege Escalation Vulnerability

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
54.677.6
Coverage
73%
981
CVE-2019-1130CISA KEVKnown ransomware

Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
61.077.5
Coverage
85%
982
CVE-2019-0703CISA KEVConflicting evidence

Microsoft Windows SMB Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
56.277.5
Coverage
73%
983
CVE-2019-0676CISA KEVConflicting evidence

Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
56.276.7
Coverage
73%
984

Android Kernel Use-After-Free Vulnerability

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

AndroidKernel

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
60.076.5
Coverage
85%
985

Android Kernel Race Condition Vulnerability

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

AndroidKernel

Required actionApply updates per vendor instructions.

Added
2022-05-23
Due
2022-06-13
Priority interval
57.874.1
Coverage
85%
986
CVE-2022-30525CISA KEVConflicting evidence

Zyxel Multiple Firewalls OS Command Injection Vulnerability

A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

ZyxelMultiple Firewalls

Required actionApply updates per vendor instructions.

Added
2022-05-16
Due
2022-06-06
Priority interval
84.5100.0
Coverage
73%
987
CVE-2022-22947CISA KEVConflicting evidence

VMware Spring Cloud Gateway Code Injection Vulnerability

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

VMwareSpring Cloud Gateway

Required actionApply updates per vendor instructions.

Added
2022-05-16
Due
2022-06-06
Priority interval
76.899.8
Coverage
73%
988
CVE-2022-1388CISA KEVKnown ransomwareConflicting evidence

F5 BIG-IP Missing Authentication Vulnerability

F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.

F5BIG-IP

Required actionApply updates per vendor instructions.

Added
2022-05-10
Due
2022-05-31
Priority interval
78.799.5
Coverage
73%
989

Microsoft Internet Explorer Use-After-Free Vulnerability

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-05-04
Due
2022-05-25
Priority interval
80.596.7
Coverage
85%
990
CVE-2014-0160CISA KEVConflicting evidence

OpenSSL Information Disclosure Vulnerability

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

OpenSSLOpenSSL

Required actionApply updates per vendor instructions.

Added
2022-05-04
Due
2022-05-25
Priority interval
72.593.7
Coverage
73%
991

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-05-04
Due
2022-05-25
Priority interval
76.793.2
Coverage
85%
992

Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2022-05-04
Due
2022-05-25
Priority interval
70.586.8
Coverage
85%
993
CVE-2021-1789CISA KEVConflicting evidence

Apple Multiple Products Type Confusion Vulnerability

A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2022-05-04
Due
2022-05-25
Priority interval
64.684.6
Coverage
73%
994
CVE-2022-29464CISA KEVKnown ransomwareConflicting evidence

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

WSO2Multiple Products

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
84.5100.0
Coverage
73%
995
CVE-2019-1003029CISA KEVConflicting evidence

Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

JenkinsScript Security Plugin

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
73.496.9
Coverage
73%
996

Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

LinuxKernel

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
76.993.4
Coverage
85%
997
CVE-2022-26904CISA KEVConflicting evidence

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
57.378.8
Coverage
73%
998
CVE-2021-40450CISA KEVConflicting evidence

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
54.377.3
Coverage
73%
999
CVE-2021-41357CISA KEVConflicting evidence

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
54.377.3
Coverage
73%
1000
CVE-2022-21919CISA KEVConflicting evidence

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-04-25
Due
2022-05-16
Priority interval
60.775.9
Coverage
73%