Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 11511200
1151
CVE-2015-2546CISA KEVKnown ransomwareConflicting evidence

Microsoft Win32k Memory Corruption Vulnerability

The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
63.982.1
Coverage
73%
1152
CVE-2019-1253CISA KEVKnown ransomware

Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
64.881.3
Coverage
85%
1153

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
64.380.8
Coverage
85%
1154
CVE-2019-1064CISA KEVKnown ransomware

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
63.279.7
Coverage
85%
1155
CVE-2019-1069CISA KEVKnown ransomware

Microsoft Task Scheduler Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

MicrosoftTask Scheduler

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
62.979.4
Coverage
85%
1156
CVE-2019-0543CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
55.878.8
Coverage
73%
1157
CVE-2019-1315CISA KEVKnown ransomware

Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
61.778.2
Coverage
85%
1158
CVE-2019-1129CISA KEVKnown ransomware

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-15
Due
2022-04-05
Priority interval
60.777.2
Coverage
85%
1159
CVE-2013-0625CISA KEVConflicting evidence

Adobe ColdFusion Authentication Bypass Vulnerability

Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
76.498.9
Coverage
73%
1160

NETGEAR Multiple Routers Remote Code Execution Vulnerability

NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.

NETGEARMultiple Routers

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
82.098.2
Coverage
85%
1161
CVE-2019-11581CISA KEVConflicting evidence

Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

AtlassianJira Server and Data Center

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
81.697.9
Coverage
73%
1162
CVE-2017-6077CISA KEVConflicting evidence

NETGEAR DGN2200 Remote Code Execution Vulnerability

NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution.

NETGEARWireless Router DGN2200

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
81.096.5
Coverage
73%
1163
CVE-2009-3960CISA KEVKnown ransomwareConflicting evidence

Adobe BlazeDS Information Disclosure Vulnerability

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

AdobeBlazeDS

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
69.790.2
Coverage
73%
1164
CVE-2013-0629CISA KEVConflicting evidence

Adobe ColdFusion Directory Traversal Vulnerability

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
67.090.0
Coverage
73%
1165
CVE-2013-0631CISA KEVConflicting evidence

Adobe ColdFusion Information Disclosure Vulnerability

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
68.790.0
Coverage
73%
1166

VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

VMwarevCenter Server and Cloud Foundation

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-03-21
Priority interval
71.387.0
Coverage
85%
1167

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

MozillaFirefox

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-03-21
Priority interval
69.684.6
Coverage
85%
1168
CVE-2020-8218CISA KEVConflicting evidence

Pulse Connect Secure Code Injection Vulnerability

A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

Pulse SecurePulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-09-07
Priority interval
67.784.4
Coverage
73%
1169

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

MozillaFirefox

Required actionApply updates per vendor instructions.

Added
2022-03-07
Due
2022-03-21
Priority interval
67.182.1
Coverage
85%
1170
CVE-2015-5119CISA KEVConflicting evidence

Adobe Flash Player Use-After-Free Vulnerability

A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.499.9
Coverage
73%
1171
CVE-2012-4681CISA KEVKnown ransomwareConflicting evidence

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.

OracleJava SE

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
84.499.9
Coverage
73%
1172
CVE-2012-0507CISA KEVKnown ransomwareConflicting evidence

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleJava SE

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
84.399.8
Coverage
73%
1173
CVE-2011-3544CISA KEVConflicting evidence

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

OracleJava SE JDK and JRE

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
84.299.7
Coverage
73%
1174
CVE-2016-4117CISA KEVConflicting evidence

Adobe Flash Player Arbitrary Code Execution Vulnerability

An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.999.4
Coverage
73%
1175
CVE-2020-1938CISA KEVConflicting evidence

Apache Tomcat Improper Privilege Management Vulnerability

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

ApacheTomcat

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
78.799.4
Coverage
73%
1176
CVE-2013-0632CISA KEVConflicting evidence

Adobe ColdFusion Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
83.999.4
Coverage
73%
1177
CVE-2012-1723CISA KEVKnown ransomwareConflicting evidence

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.

OracleJava SE

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
83.999.4
Coverage
73%
1178

Adobe Flash Player Remote Code Execution Vulnerability

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
81.998.2
Coverage
85%
1179
CVE-2008-2992CISA KEVKnown ransomwareConflicting evidence

Adobe Reader and Acrobat Input Validation Vulnerability

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

AdobeAcrobat and Reader

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.398.1
Coverage
73%
1180
CVE-2015-3043CISA KEVConflicting evidence

Adobe Flash Player Memory Corruption Vulnerability

A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
77.497.9
Coverage
73%
1181
CVE-2013-3346CISA KEVConflicting evidence

Adobe Reader and Acrobat Memory Corruption Vulnerability

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

AdobeReader and Acrobat

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.797.7
Coverage
73%
1182
CVE-2010-3333CISA KEVConflicting evidence

Microsoft Office Stack-based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.497.2
Coverage
73%
1183
CVE-2019-1652CISA KEVConflicting evidence

Cisco Small Business Routers Improper Input Validation Vulnerability

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

CiscoSmall Business RV320 and RV325 Dual Gigabit WAN VPN Routers

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
77.697.1
Coverage
73%
1184
CVE-2010-0188CISA KEVKnown ransomwareConflicting evidence

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

AdobeReader and Acrobat

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.397.0
Coverage
73%
1185
CVE-2022-20699CISA KEVConflicting evidence

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
81.597.0
Coverage
73%
1186
CVE-2013-0640CISA KEVConflicting evidence

Adobe Reader and Acrobat Memory Corruption Vulnerability

An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.

AdobeReader and Acrobat

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.296.9
Coverage
73%
1187
CVE-2015-2545CISA KEVConflicting evidence

Microsoft Office Malformed EPS File Vulnerability

Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.196.8
Coverage
73%
1188
CVE-2009-3129CISA KEVConflicting evidence

Microsoft Excel Featheader Record Memory Corruption Vulnerability

Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.

MicrosoftExcel

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.096.8
Coverage
73%
1189
CVE-2014-4114CISA KEVConflicting evidence

Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
77.696.3
Coverage
73%
1190
CVE-2017-11826CISA KEVConflicting evidence

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
77.696.3
Coverage
73%
1191
CVE-2017-0261CISA KEVConflicting evidence

Microsoft Office Use-After-Free Vulnerability

Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
77.295.9
Coverage
73%
1192

Microsoft Internet Explorer Remote Code Execution Vulnerability

This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.795.9
Coverage
85%
1193

Microsoft Internet Explorer Use-After-Free Vulnerability

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.695.9
Coverage
85%
1194

Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
79.095.2
Coverage
85%
1195
CVE-2017-8540CISA KEVConflicting evidence

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

MicrosoftMalware Protection Engine

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
76.595.2
Coverage
73%
1196
CVE-2012-1535CISA KEVConflicting evidence

Adobe Flash Player Arbitrary Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
76.395.0
Coverage
73%
1197
CVE-2015-7645CISA KEVKnown ransomwareConflicting evidence

Adobe Flash Player Arbitrary Code Execution Vulnerability

Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-03-03
Due
2022-03-24
Priority interval
76.094.8
Coverage
73%
1198

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.894.3
Coverage
85%
1199
CVE-2011-1889CISA KEVConflicting evidence

Microsoft Forefront TMG Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

MicrosoftForefront Threat Management Gateway (TMG)

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
78.493.9
Coverage
73%
1200
CVE-2016-7193CISA KEVConflicting evidence

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
74.793.4
Coverage
73%