Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 10511100
1051
CVE-2013-2551CISA KEVKnown ransomware

Microsoft Internet Explorer Use-After-Free Vulnerability

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
79.295.5
Coverage
85%
1052
CVE-2016-7200CISA KEVConflicting evidence

Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftEdge

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
77.295.2
Coverage
73%
1053

Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
78.694.9
Coverage
85%
1054
CVE-2016-7201CISA KEVConflicting evidence

Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftEdge

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
76.994.9
Coverage
73%
1055

Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
78.193.3
Coverage
85%
1056

Microsoft Edge and Internet Explorer Type Confusion Vulnerability

Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.

MicrosoftEdge and Internet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
76.993.2
Coverage
85%
1057
CVE-2012-2539CISA KEVConflicting evidence

Microsoft Word Remote Code Execution Vulnerability

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

MicrosoftWord

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
74.192.8
Coverage
73%
1058

Microsoft Internet Explorer Memory Corruption Vulnerability

JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
75.391.6
Coverage
85%
1059
CVE-2017-0213CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
63.191.6
Coverage
73%
1060
CVE-2021-20028CISA KEVKnown ransomwareConflicting evidence

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

SonicWallSecure Remote Access (SRA)

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-28
Due
2022-04-18
Priority interval
69.790.5
Coverage
73%
1061
CVE-2016-0151CISA KEVKnown ransomware

Microsoft Windows CSRSS Security Feature Bypass Vulnerability

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

MicrosoftClient-Server Run-time Subsystem (CSRSS)

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
73.990.4
Coverage
85%
1062

Microsoft Office Uninitialized Memory Use Vulnerability

Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
73.890.1
Coverage
85%
1063
CVE-2021-26085CISA KEVKnown ransomware

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

AtlassianConfluence Server

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
72.588.2
Coverage
85%
1064
CVE-2013-3660CISA KEVConflicting evidence

Microsoft Win32k Privilege Escalation Vulnerability

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
69.887.1
Coverage
73%
1065

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
71.886.8
Coverage
85%
1066

Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.

MicrosoftAncillary Function Driver (afd.sys)

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
69.385.8
Coverage
85%
1067

Microsoft Windows Kernel Privilege Escalation Vulnerability

The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
67.984.4
Coverage
85%
1068
CVE-2012-2034CISA KEVConflicting evidence

Adobe Flash Player Memory Corruption Vulnerability

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-28
Due
2022-04-18
Priority interval
64.383.8
Coverage
73%
1069
CVE-2018-8440CISA KEVKnown ransomware

Microsoft Windows Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
66.683.1
Coverage
85%
1070

Microsoft Internet Explorer Information Disclosure Vulnerability

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
66.581.5
Coverage
85%
1071

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-21
Priority interval
63.980.4
Coverage
85%
1072
CVE-2021-34486CISA KEVConflicting evidence

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
57.080.0
Coverage
73%
1073
CVE-2021-38646CISA KEVKnown ransomwareConflicting evidence

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
61.278.7
Coverage
73%
1074
CVE-2018-8405CISA KEVKnown ransomware

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

MicrosoftDirectX Graphics Kernel (DXGKRNL)

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
61.778.2
Coverage
85%
1075
CVE-2018-8406CISA KEVKnown ransomware

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

MicrosoftDirectX Graphics Kernel (DXGKRNL)

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
61.778.2
Coverage
85%
1076
CVE-2019-7483CISA KEVConflicting evidence

SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

SonicWallSMA100

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
56.577.7
Coverage
73%
1077

Oracle Fusion Middleware Unspecified Vulnerability

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

OracleFusion Middleware

Required actionApply updates per vendor instructions.

Added
2022-03-28
Due
2022-04-18
Priority interval
55.171.1
Coverage
85%
1078
CVE-2019-16920CISA KEVConflicting evidence

D-Link Multiple Routers Command Injection Vulnerability

Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

D-LinkMultiple Routers

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.5100.0
Coverage
73%
1079
CVE-2020-9054CISA KEVConflicting evidence

Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

ZyxelMultiple Network-Attached Storage (NAS) Devices

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.5100.0
Coverage
73%
1080
CVE-2019-15107CISA KEVKnown ransomwareConflicting evidence

Webmin Command Injection Vulnerability

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

WebminWebmin

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.5100.0
Coverage
73%
1081
CVE-2014-6287CISA KEVConflicting evidence

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

RejettoHTTP File Server (HFS)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.499.9
Coverage
73%
1082
CVE-2017-3881CISA KEVConflicting evidence

Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

CiscoIOS and IOS XE

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.499.9
Coverage
73%
1083
CVE-2020-7247CISA KEVConflicting evidence

OpenSMTPD Remote Code Execution Vulnerability

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

OpenBSDOpenSMTPD

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.499.9
Coverage
73%
1084
CVE-2016-1555CISA KEVConflicting evidence

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

NETGEARWireless Access Point (WAP) Devices

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.399.8
Coverage
73%
1085
CVE-2021-42237CISA KEVKnown ransomwareConflicting evidence

Sitecore XP Remote Command Execution Vulnerability

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

SitecoreXP

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.399.8
Coverage
73%
1086
CVE-2020-25223CISA KEVConflicting evidence

Sophos SG UTM Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

SophosSG UTM

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
84.299.7
Coverage
73%
1087
CVE-2012-1823CISA KEVConflicting evidence

PHP-CGI Query String Parameter Vulnerability

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

PHPPHP

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.799.5
Coverage
73%
1088
CVE-2013-2251CISA KEVConflicting evidence

Apache Struts Improper Input Validation Vulnerability

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

ApacheStruts

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
83.299.5
Coverage
73%
1089
CVE-2015-1427CISA KEVConflicting evidence

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

ElasticElasticsearch

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.799.5
Coverage
73%
1090
CVE-2010-2861CISA KEVKnown ransomwareConflicting evidence

Adobe ColdFusion Directory Traversal Vulnerability

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.799.5
Coverage
73%
1091
CVE-2019-11043CISA KEVKnown ransomwareConflicting evidence

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

PHPFastCGI Process Manager (FPM)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.799.4
Coverage
73%
1092
CVE-2018-11138CISA KEVKnown ransomwareConflicting evidence

Quest KACE System Management Appliance Remote Command Execution Vulnerability

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

QuestKACE System Management Appliance

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
83.799.2
Coverage
73%
1093
CVE-2019-10068CISA KEVConflicting evidence

Kentico Xperience Deserialization of Untrusted Data Vulnerability

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

KenticoXperience

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.399.1
Coverage
73%
1094
CVE-2018-1273CISA KEVKnown ransomwareConflicting evidence

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

VMware TanzuSpring Data Commons

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.399.1
Coverage
73%
1095
CVE-2009-1151CISA KEVConflicting evidence

phpMyAdmin Remote Code Execution Vulnerability

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

phpMyAdminphpMyAdmin

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.399.0
Coverage
73%
1096
CVE-2019-12989CISA KEVConflicting evidence

Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

CitrixSD-WAN and NetScaler

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.298.9
Coverage
73%
1097
CVE-2018-14839CISA KEVConflicting evidence

LG N1A1 NAS Remote Command Execution Vulnerability

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

LGN1A1 NAS

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
77.798.4
Coverage
73%
1098
CVE-2016-10174CISA KEVConflicting evidence

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

NETGEARWNR2000v5 Router

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
82.898.3
Coverage
73%
1099
CVE-2022-26143CISA KEVConflicting evidence

MiCollab, MiVoice Business Express Access Control Vulnerability

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

MitelMiCollab, MiVoice Business Express

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.298.2
Coverage
73%
1100
CVE-2015-1187CISA KEVConflicting evidence

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

D-Link and TRENDnetMultiple Devices

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
82.798.2
Coverage
73%