Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 12511300
1251

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

CiscoIOS, XR, and XE Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
63.578.8
Coverage
85%
1252
CVE-2017-6627CISA KEVConflicting evidence

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
57.478.7
Coverage
73%
1253

Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges

MicrosoftGraphics Device Interface (GDI)

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
61.578.0
Coverage
85%
1254
CVE-2016-8562CISA KEVConflicting evidence

Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.

SiemensSIMATIC CP

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
52.677.6
Coverage
73%
1255
CVE-2017-12319CISA KEVConflicting evidence

Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

CiscoIOS XE Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
59.477.4
Coverage
73%
1256
CVE-2018-0179CISA KEVConflicting evidence

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
59.277.2
Coverage
73%
1257
CVE-2018-0180CISA KEVConflicting evidence

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
59.277.2
Coverage
73%
1258

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.

Treck TCP/IP stackIPv6

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
60.677.1
Coverage
85%
1259
CVE-2013-1675CISA KEVConflicting evidence

Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

MozillaFirefox

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
55.976.4
Coverage
73%
1260

Oracle Java SE Integrity Check Vulnerability

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

OracleJava SE

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
59.875.6
Coverage
85%
1261

Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

CiscoIOS Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-17
Priority interval
60.175.1
Coverage
85%
1262

Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

CiscoIOS software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
58.274.2
Coverage
85%
1263

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

CiscoIOS and IOS XE Software

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
58.274.2
Coverage
85%
1264
CVE-2017-12238CISA KEVConflicting evidence

Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

CiscoCatalyst 6800 Series Switches

Required actionApply updates per vendor instructions.

Added
2022-03-03
Due
2022-03-24
Priority interval
51.174.1
Coverage
73%
1265
CVE-2017-8570CISA KEVConflicting evidence

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-02-25
Due
2022-08-25
Priority interval
78.597.2
Coverage
73%
1266
CVE-2014-6352CISA KEVConflicting evidence

Microsoft Windows Code Injection Vulnerability

Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-02-25
Due
2022-08-25
Priority interval
77.195.9
Coverage
73%
1267
CVE-2017-0222CISA KEVConflicting evidence

Microsoft Internet Explorer Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-02-25
Due
2022-08-25
Priority interval
69.987.9
Coverage
73%
1268
CVE-2022-24682CISA KEVKnown ransomwareConflicting evidence

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

SynacorZimbra Collaborate Suite (ZCS)

Required actionApply updates per vendor instructions.

Added
2022-02-25
Due
2022-03-11
Priority interval
61.981.4
Coverage
73%
1269
CVE-2022-23131CISA KEVConflicting evidence

Zabbix Frontend Authentication Bypass Vulnerability

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

ZabbixFrontend

Required actionApply updates per vendor instructions.

Added
2022-02-22
Due
2022-03-08
Priority interval
72.399.1
Coverage
73%
1270
CVE-2022-23134CISA KEVConflicting evidence

Zabbix Frontend Improper Access Control Vulnerability

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

ZabbixFrontend

Required actionApply updates per vendor instructions.

Added
2022-02-22
Due
2022-03-08
Priority interval
67.786.7
Coverage
73%
1271
CVE-2022-24086CISA KEVConflicting evidence

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

AdobeCommerce and Magento Open Source

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-03-01
Priority interval
84.499.9
Coverage
73%
1272
CVE-2017-9841CISA KEVConflicting evidence

PHPUnit Command Injection Vulnerability

PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

PHPUnitPHPUnit

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
78.799.5
Coverage
73%
1273
CVE-2018-15982CISA KEVKnown ransomwareConflicting evidence

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-02-15
Due
2022-08-15
Priority interval
77.698.1
Coverage
73%
1274
CVE-2013-3906CISA KEVConflicting evidence

Microsoft Graphics Component Memory Corruption Vulnerability

Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.

MicrosoftGraphics Component

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
77.996.7
Coverage
73%
1275
CVE-2014-1761CISA KEVConflicting evidence

Microsoft Word Memory Corruption Vulnerability

Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.

MicrosoftWord

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
77.195.9
Coverage
73%
1276
CVE-2018-20250CISA KEVKnown ransomwareConflicting evidence

WinRAR Absolute Path Traversal Vulnerability

WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution

RARLABWinRAR

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
76.694.1
Coverage
73%
1277
CVE-2018-8174CISA KEVKnown ransomware

Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
77.592.7
Coverage
85%
1278
CVE-2019-0752CISA KEVKnown ransomware

Microsoft Internet Explorer Type Confusion Vulnerability

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-08-15
Priority interval
76.892.1
Coverage
85%
1279
CVE-2022-0609CISA KEVConflicting evidence

Google Chromium Animation Use-After-Free Vulnerability

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Animation

Required actionApply updates per vendor instructions.

Added
2022-02-15
Due
2022-03-01
Priority interval
66.786.7
Coverage
73%
1280
CVE-2022-22620CISA KEVConflicting evidence

Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleiOS, iPadOS, and macOS

Required actionApply updates per vendor instructions.

Added
2022-02-11
Due
2022-02-25
Priority interval
65.185.1
Coverage
73%
1281
CVE-2015-1635CISA KEVConflicting evidence

Microsoft HTTP.sys Remote Code Execution Vulnerability

Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.

MicrosoftHTTP.sys

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
84.5100.0
Coverage
73%
1282
CVE-2020-0796CISA KEVKnown ransomwareConflicting evidence

Microsoft SMBv3 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

MicrosoftSMBv3

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
78.7100.0
Coverage
73%
1283
CVE-2018-1000861CISA KEVConflicting evidence

Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

A code execution vulnerability exists in the Stapler web framework used by Jenkins

JenkinsJenkins Stapler Web Framework

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
84.399.8
Coverage
73%
1284
CVE-2015-2051CISA KEVConflicting evidence

D-Link DIR-645 Router Remote Code Execution Vulnerability

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

D-LinkDIR-645 Router

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2022-02-10
Due
2022-08-10
Priority interval
81.799.7
Coverage
73%
1285
CVE-2017-9791CISA KEVConflicting evidence

Apache Struts 1 Improper Input Validation Vulnerability

The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

ApacheStruts 1

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
78.699.4
Coverage
73%
1286
CVE-2016-3088CISA KEVConflicting evidence

Apache ActiveMQ Improper Input Validation Vulnerability

The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request

ApacheActiveMQ

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
78.699.4
Coverage
73%
1287
CVE-2017-0144CISA KEVKnown ransomware

Microsoft SMBv1 Remote Code Execution Vulnerability

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

MicrosoftSMBv1

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
81.998.2
Coverage
85%
1288

Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability

Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
81.097.2
Coverage
85%
1289
CVE-2017-0145CISA KEVKnown ransomware

Microsoft SMBv1 Remote Code Execution Vulnerability

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

MicrosoftSMBv1

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
81.097.2
Coverage
85%
1290
CVE-2017-0262CISA KEVConflicting evidence

Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
77.596.2
Coverage
73%
1291
CVE-2017-10271CISA KEVKnown ransomwareConflicting evidence

Oracle Corporation WebLogic Server Remote Code Execution Vulnerability

Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.

OracleWebLogic Server

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
72.593.7
Coverage
73%
1292
CVE-2014-4404CISA KEVConflicting evidence

Apple OS X Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.

AppleOS X

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
73.592.3
Coverage
73%
1293
CVE-2021-36934CISA KEVConflicting evidence

Microsoft Windows SAM Local Privilege Escalation Vulnerability

If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-02-24
Priority interval
67.990.9
Coverage
73%
1294

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
64.380.8
Coverage
85%
1295

Apple OS X Authentication Bypass Vulnerability

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.

AppleOS X

Required actionApply updates per vendor instructions.

Added
2022-02-10
Due
2022-08-10
Priority interval
64.380.8
Coverage
85%
1296

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-02-04
Due
2022-02-18
Priority interval
72.489.4
Coverage
85%
1297
CVE-2014-6271CISA KEVConflicting evidence

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

GNUBourne-Again Shell (Bash)

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
84.5100.0
Coverage
73%
1298
CVE-2014-7169CISA KEVConflicting evidence

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.

GNUBourne-Again Shell (Bash)

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
84.5100.0
Coverage
73%
1299
CVE-2021-20038CISA KEVKnown ransomwareConflicting evidence

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

SonicWallSMA 100 Appliances

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-02-11
Priority interval
78.799.5
Coverage
73%
1300
CVE-2017-5689CISA KEVConflicting evidence

Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

IntelActive Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
83.799.2
Coverage
73%