Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 11011150
1101

Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code.

AdobeReader and Acrobat

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.797.9
Coverage
85%
1102
CVE-2013-4810CISA KEVConflicting evidence

HP Multiple Products Remote Code Execution Vulnerability

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

Hewlett Packard (HP)ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
82.397.8
Coverage
73%
1103

Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.597.7
Coverage
85%
1104

Apache Kylin OS Command Injection Vulnerability

Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.

ApacheKylin

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.797.2
Coverage
85%
1105
CVE-2017-0146CISA KEVKnown ransomware

Microsoft Windows SMB Remote Code Execution Vulnerability

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.097.2
Coverage
85%
1106
CVE-2022-26318CISA KEVConflicting evidence

WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

WatchGuardFirebox and XTM Appliances

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
76.497.2
Coverage
73%
1107
CVE-2019-1003030CISA KEVConflicting evidence

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

JenkinsMatrix Project Plugin

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
73.697.1
Coverage
73%
1108
CVE-2017-6316CISA KEVConflicting evidence

Citrix Multiple Products Remote Code Execution Vulnerability

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

CitrixNetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
81.597.0
Coverage
73%
1109
CVE-2005-2773CISA KEVConflicting evidence

HP OpenView Network Node Manager Remote Code Execution Vulnerability

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

Hewlett Packard (HP)OpenView Network Node Manager

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
76.096.7
Coverage
73%
1110
CVE-2010-4344CISA KEVConflicting evidence

Exim Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

EximExim

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
80.296.5
Coverage
73%
1111

Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

MicrosoftKerberos Key Distribution Center (KDC)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
80.796.2
Coverage
85%
1112

Microsoft Windows Shell Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
79.295.5
Coverage
85%
1113
CVE-2017-12617CISA KEVConflicting evidence

Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheTomcat

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
77.095.2
Coverage
73%
1114
CVE-2017-12615CISA KEVKnown ransomwareConflicting evidence

Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

ApacheTomcat

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
77.095.2
Coverage
73%
1115
CVE-2018-0125CISA KEVConflicting evidence

Cisco VPN Routers Remote Code Execution Vulnerability

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

CiscoVPN Routers

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
79.494.9
Coverage
73%
1116

Citrix SD-WAN and NetScaler Command Injection Vulnerability

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

CitrixSD-WAN and NetScaler

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
79.294.7
Coverage
85%
1117
CVE-2021-22941CISA KEVKnown ransomwareConflicting evidence

Citrix ShareFile Improper Access Control Vulnerability

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CitrixShareFile

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
79.194.6
Coverage
73%
1118

NETGEAR DGN2200 Devices OS Command Injection Vulnerability

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

NETGEARDGN2200 Devices

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
79.094.5
Coverage
85%
1119
CVE-2015-4068CISA KEVConflicting evidence

Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

ArcserveUnified Data Protection (UDP)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
78.794.5
Coverage
73%
1120
CVE-2019-6340CISA KEVConflicting evidence

Drupal Core Remote Code Execution Vulnerability

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

DrupalCore

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
76.294.4
Coverage
73%
1121
CVE-2014-3120CISA KEVConflicting evidence

Elasticsearch Remote Code Execution Vulnerability

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

ElasticElasticsearch

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
75.894.1
Coverage
73%
1122
CVE-2016-11021CISA KEVConflicting evidence

D-Link DCS-930L Devices OS Command Injection Vulnerability

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

D-LinkDCS-930L Devices

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
74.694.1
Coverage
73%
1123
CVE-2018-6961CISA KEVConflicting evidence

VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

VMwareSD-WAN Edge

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
75.693.8
Coverage
73%
1124
CVE-2020-5410CISA KEVConflicting evidence

VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

VMware TanzuSpring Cloud Configuration (Config) Server

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
72.193.3
Coverage
73%
1125
CVE-2016-0752CISA KEVConflicting evidence

Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

RailsRuby on Rails

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
72.093.3
Coverage
73%
1126

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

TP-LinkMultiple Archer Devices

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
77.192.8
Coverage
85%
1127
CVE-2019-2616CISA KEVConflicting evidence

Oracle BI Publisher Unauthorized Access Vulnerability

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

OracleBI Publisher (Formerly XML Publisher)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
75.292.2
Coverage
73%
1128

Microsoft Scripting Engine Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

MicrosoftInternet Explorer Scripting Engine

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
74.589.7
Coverage
85%
1129
CVE-2016-4171CISA KEVConflicting evidence

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
68.488.9
Coverage
73%
1130
CVE-2018-0147CISA KEVConflicting evidence

Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

CiscoSecure Access Control System (ACS)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
73.188.6
Coverage
73%
1131
CVE-2014-0130CISA KEVConflicting evidence

Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

RailsRuby on Rails

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
65.488.4
Coverage
73%
1132

Microsoft GDI Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

MicrosoftGraphics Device Interface (GDI)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
71.387.6
Coverage
85%
1133
CVE-2022-21999CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
64.487.4
Coverage
73%
1134

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

CiscoPrime Data Center Network Manager (DCNM)

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
71.587.2
Coverage
85%
1135

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
70.786.9
Coverage
85%
1136
CVE-2020-9377CISA KEVConflicting evidence

D-Link DIR-610 Devices Remote Command Execution

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

D-LinkDIR-610 Devices

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-25
Due
2022-04-15
Priority interval
65.586.2
Coverage
73%
1137
CVE-2020-2021CISA KEVKnown ransomwareConflicting evidence

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.

Palo Alto NetworksPAN-OS

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
67.484.2
Coverage
73%
1138
CVE-2020-1631CISA KEVConflicting evidence

Juniper Junos OS Path Traversal Vulnerability

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

JuniperJunos OS

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
61.383.8
Coverage
73%
1139
CVE-2010-4345CISA KEVConflicting evidence

Exim Privilege Escalation Vulnerability

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

EximExim

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
65.782.9
Coverage
73%
1140
CVE-2020-2506CISA KEVConflicting evidence

QNAP Helpdesk Improper Access Control Vulnerability

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

QNAP SystemsHelpdesk

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
61.182.3
Coverage
73%
1141
CVE-2013-5223CISA KEVConflicting evidence

D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

D-LinkDSL-2760U

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
60.380.1
Coverage
73%
1142
CVE-2010-3035CISA KEVConflicting evidence

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoIOS XR

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
57.278.5
Coverage
73%
1143
CVE-2009-2055CISA KEVConflicting evidence

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CiscoIOS XR

Required actionApply updates per vendor instructions.

Added
2022-03-25
Due
2022-04-15
Priority interval
54.473.4
Coverage
73%
1144
CVE-2018-8120CISA KEVKnown ransomware

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
74.790.2
Coverage
85%
1145
CVE-2020-5135CISA KEVConflicting evidence

SonicWall SonicOS Buffer Overflow Vulnerability

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall.

SonicWallSonicOS

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
69.189.9
Coverage
73%
1146
CVE-2017-0101CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
72.289.7
Coverage
73%
1147
CVE-2019-0841CISA KEVKnown ransomware

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
70.987.4
Coverage
85%
1148
CVE-2019-1405CISA KEVKnown ransomware

Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
68.985.4
Coverage
85%
1149
CVE-2016-3309CISA KEVKnown ransomware

Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
67.183.6
Coverage
85%
1150
CVE-2019-1322CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
60.383.3
Coverage
73%