Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 13011350
1301
CVE-2014-1776CISA KEVConflicting evidence

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
83.398.8
Coverage
73%
1302
CVE-2020-5722CISA KEVConflicting evidence

Grandstream Networks UCM6200 Series SQL Injection Vulnerability

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

GrandstreamUCM6200

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
82.898.3
Coverage
73%
1303
CVE-2020-0787CISA KEVKnown ransomware

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-07-28
Priority interval
71.087.5
Coverage
85%
1304
CVE-2022-22587CISA KEVConflicting evidence

Apple Memory Corruption Vulnerability

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.

AppleiOS and macOS

Required actionApply updates per vendor instructions.

Added
2022-01-28
Due
2022-02-11
Priority interval
71.386.8
Coverage
73%
1305
CVE-2012-0391CISA KEVConflicting evidence

Apache Struts 2 Improper Input Validation Vulnerability

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

ApacheStruts 2

Required actionApply updates per vendor instructions.

Added
2022-01-21
Due
2022-07-21
Priority interval
80.696.8
Coverage
73%
1306
CVE-2018-8453CISA KEVKnown ransomware

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-01-21
Due
2022-07-21
Priority interval
74.791.2
Coverage
85%
1307

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

ApacheStruts 1

Required actionApply updates per vendor instructions.

Added
2022-01-21
Due
2022-07-21
Priority interval
73.589.3
Coverage
85%
1308
CVE-2021-35247CISA KEVConflicting evidence

SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

SolarWindsServ-U

Required actionApply updates per vendor instructions.

Added
2022-01-21
Due
2022-02-04
Priority interval
54.471.9
Coverage
73%
1309
CVE-2020-13927CISA KEVConflicting evidence

Apache Airflow's Experimental API Authentication Bypass

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

ApacheAirflow's Experimental API

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-07-18
Priority interval
78.799.5
Coverage
73%
1310
CVE-2021-40870CISA KEVConflicting evidence

Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

AviatrixAviatrix Controller

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
78.098.8
Coverage
73%
1311
CVE-2020-11978CISA KEVConflicting evidence

Apache Airflow Command Injection

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

ApacheAirflow

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-07-18
Priority interval
76.296.9
Coverage
73%
1312
CVE-2021-32648CISA KEVConflicting evidence

October CMS Improper Authentication

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

October CMSOctober CMS

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
75.096.8
Coverage
73%
1313
CVE-2021-22991CISA KEVConflicting evidence

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

F5BIG-IP Traffic Management Microkernel

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
72.695.1
Coverage
73%
1314

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NagiosNagios XI

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
79.394.8
Coverage
85%
1315

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NagiosNagios XI

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
78.994.4
Coverage
85%
1316

Oracle Business Intelligence Enterprise Edition Path Transversal

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

OracleIntelligence Enterprise Edition

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-07-18
Priority interval
78.594.2
Coverage
85%
1317
CVE-2021-21315CISA KEVConflicting evidence

System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

Npm packageSystem Information Library for Node.JS

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
70.593.5
Coverage
73%
1318
CVE-2021-33766CISA KEVConflicting evidence

Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
72.293.5
Coverage
73%
1319

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NagiosNagios XI

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
77.092.5
Coverage
85%
1320
CVE-2021-21975CISA KEVKnown ransomwareConflicting evidence

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

VMwarevRealize Operations Manager API

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-02-01
Priority interval
70.291.4
Coverage
73%
1321
CVE-2020-13671CISA KEVConflicting evidence

Drupal core Un-restricted Upload of File

Improper sanitization in the extension file names is present in Drupal core.

DrupalDrupal core

Required actionApply updates per vendor instructions.

Added
2022-01-18
Due
2022-07-18
Priority interval
60.481.1
Coverage
73%
1322
CVE-2019-10149CISA KEVConflicting evidence

Exim Mail Transfer Agent (MTA) Improper Input Validation

Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

EximMail Transfer Agent (MTA)

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
82.5100.0
Coverage
73%
1323
CVE-2015-7450CISA KEVConflicting evidence

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands

IBMWebSphere Application Server and Server Hypervisor Edition

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
84.399.8
Coverage
73%
1324
CVE-2019-7609CISA KEVConflicting evidence

Kibana Arbitrary Code Execution

Kibana contain an arbitrary code execution flaw in the Timelion visualizer.

ElasticKibana

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
84.099.5
Coverage
73%
1325
CVE-2019-9670CISA KEVConflicting evidence

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

SynacorZimbra Collaboration Suite (ZCS)

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
78.799.5
Coverage
73%
1326
CVE-2019-2725CISA KEVKnown ransomwareConflicting evidence

Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

OracleWebLogic Server

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
78.799.5
Coverage
73%
1327
CVE-2021-36260CISA KEVConflicting evidence

Hikvision Improper Input Validation

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

HikvisionSecurity cameras web server

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-01-24
Priority interval
83.299.5
Coverage
73%
1328
CVE-2017-1000486CISA KEVConflicting evidence

Primetek Primefaces Remote Code Execution Vulnerability

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

PrimetekPrimefaces Application

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
78.298.9
Coverage
73%
1329
CVE-2018-13382CISA KEVKnown ransomwareConflicting evidence

Fortinet FortiOS and FortiProxy Improper Authorization

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

FortinetFortiOS and FortiProxy

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
70.695.8
Coverage
73%
1330
CVE-2021-27860CISA KEVConflicting evidence

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

FatPipeWARP, IPVPN, and MPVPN software

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-01-24
Priority interval
74.692.1
Coverage
73%
1331
CVE-2019-1458CISA KEVKnown ransomware

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
75.291.7
Coverage
85%
1332
CVE-2013-3900CISA KEVConflicting evidence

Microsoft WinVerifyTrust function Remote Code Execution

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

MicrosoftWinVerifyTrust function

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
67.190.4
Coverage
73%
1333
CVE-2019-1579CISA KEVKnown ransomwareConflicting evidence

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.

Palo Alto NetworksPAN-OS

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
69.587.8
Coverage
73%
1334

Google Chrome Media Use-After-Free Vulnerability

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

GoogleChrome Media

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
68.584.8
Coverage
85%
1335
CVE-2018-13383CISA KEVKnown ransomwareConflicting evidence

Fortinet FortiOS and FortiProxy Out-of-bounds Write

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

FortinetFortiOS and FortiProxy

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-07-10
Priority interval
62.482.9
Coverage
73%
1336

VMware vCenter Server Improper Access Control

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

VMwarevCenter Server

Required actionApply updates per vendor instructions.

Added
2022-01-10
Due
2022-01-24
Priority interval
66.582.3
Coverage
85%
1337
CVE-2021-4102CISA KEVConflicting evidence

Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-12-15
Due
2021-12-29
Priority interval
62.682.6
Coverage
73%
1338
CVE-2021-43890CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows AppX Installer Spoofing Vulnerability

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-12-15
Due
2021-12-29
Priority interval
61.479.2
Coverage
73%
1339
CVE-2021-44228CISA KEVKnown ransomwareConflicting evidence

Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.

ApacheLog4j2

Required actionFor all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

Added
2021-12-10
Due
2021-12-24
Priority interval
83.2100.0
Coverage
73%
1340
CVE-2021-44515CISA KEVConflicting evidence

Zoho Desktop Central Authentication Bypass Vulnerability

Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

ZohoDesktop Central

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2021-12-24
Priority interval
84.5100.0
Coverage
73%
1341
CVE-2021-35394CISA KEVConflicting evidence

Realtek Jungle SDK Remote Code Execution Vulnerability

RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.

RealtekJungle Software Development Kit (SDK)

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2021-12-24
Priority interval
84.5100.0
Coverage
73%
1342
CVE-2017-12149CISA KEVKnown ransomwareConflicting evidence

Red Hat JBoss Application Server Remote Code Execution Vulnerability

The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data.

Red HatJBoss Application Server

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
77.898.5
Coverage
73%
1343
CVE-2020-17463CISA KEVConflicting evidence

Fuel CMS SQL Injection Vulnerability

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

Fuel CMSFuel CMS

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
77.798.5
Coverage
73%
1344
CVE-2019-10758CISA KEVConflicting evidence

MongoDB mongo-express Remote Code Execution Vulnerability

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

MongoDBmongo-express

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
80.998.2
Coverage
73%
1345
CVE-2019-7238CISA KEVConflicting evidence

Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.

SonatypeNexus Repository Manager

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
76.297.0
Coverage
73%
1346
CVE-2019-0193CISA KEVConflicting evidence

Apache Solr DataImportHandler Code Injection Vulnerability

The optional Apache Solr module DataImportHandler contains a code injection vulnerability.

ApacheSolr

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
76.395.8
Coverage
73%
1347
CVE-2020-8816CISA KEVConflicting evidence

Pi-Hole AdminLTE Remote Code Execution Vulnerability

Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

Pi-holeAdminLTE

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
73.995.4
Coverage
73%
1348
CVE-2010-1871CISA KEVConflicting evidence

Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

Red HatJBoss Seam 2

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
75.395.3
Coverage
73%
1349
CVE-2017-17562CISA KEVConflicting evidence

Embedthis GoAhead Remote Code Execution Vulnerability

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked.

EmbedthisGoAhead

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
76.694.9
Coverage
73%
1350

Linux Kernel Improper Privilege Management Vulnerability

Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.

LinuxKernel

Required actionApply updates per vendor instructions.

Added
2021-12-10
Due
2022-06-10
Priority interval
72.488.9
Coverage
85%