Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 14011450
1401
CVE-2020-15505CISA KEVConflicting evidence

Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

IvantiMobileIron Multiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.799.5
Coverage
73%
1402
CVE-2019-16759CISA KEVConflicting evidence

vBulletin PHP Module Remote Code Execution Vulnerability

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

vBulletinvBulletin

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.799.5
Coverage
73%
1403
CVE-2021-38647CISA KEVKnown ransomwareConflicting evidence

Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

MicrosoftOpen Management Infrastructure (OMI)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
78.799.5
Coverage
73%
1404
CVE-2020-6287CISA KEVConflicting evidence

SAP NetWeaver Missing Authentication for Critical Function Vulnerability

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.

SAPNetWeaver

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
84.599.5
Coverage
73%
1405
CVE-2020-16846CISA KEVConflicting evidence

SaltStack Salt Shell Injection Vulnerability

SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.

SaltStackSalt

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.799.5
Coverage
73%
1406
CVE-2018-20062CISA KEVConflicting evidence

ThinkPHP "noneCms" Remote Code Execution Vulnerability

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

ThinkPHPnoneCms

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.799.5
Coverage
73%
1407
CVE-2020-14750CISA KEVConflicting evidence

Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

OracleWebLogic Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.799.4
Coverage
73%
1408
CVE-2021-40539CISA KEVKnown ransomwareConflicting evidence

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

ZohoManageEngine

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
78.699.4
Coverage
73%
1409
CVE-2020-2555CISA KEVConflicting evidence

Oracle Multiple Products Remote Code Execution Vulnerability

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

OracleMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.599.2
Coverage
73%
1410
CVE-2020-1350CISA KEVConflicting evidence

Microsoft Windows DNS Server Remote Code Execution Vulnerability

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
84.299.2
Coverage
73%
1411
CVE-2019-5544CISA KEVKnown ransomwareConflicting evidence

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

VMwareVMware ESXi and Horizon DaaS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.499.2
Coverage
73%
1412
CVE-2020-11651CISA KEVConflicting evidence

SaltStack Salt Authentication Bypass Vulnerability

SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

SaltStackSalt

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.499.1
Coverage
73%
1413
CVE-2015-4852CISA KEVConflicting evidence

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution.

OracleWebLogic Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.399.1
Coverage
73%
1414
CVE-2021-35211CISA KEVKnown ransomwareConflicting evidence

SolarWinds Serv-U Remote Code Execution Vulnerability

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

SolarWindsServ-U

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
81.699.1
Coverage
73%
1415
CVE-2020-17530CISA KEVConflicting evidence

Apache Struts Remote Code Execution Vulnerability

Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.

ApacheStruts

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.399.1
Coverage
73%
1416
CVE-2019-11580CISA KEVKnown ransomwareConflicting evidence

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

AtlassianCrowd and Crowd Data Center

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.399.0
Coverage
73%
1417
CVE-2020-29583CISA KEVConflicting evidence

Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability

Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.

ZyxelMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
83.599.0
Coverage
73%
1418
CVE-2016-4437CISA KEVConflicting evidence

Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

ApacheShiro

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.398.8
Coverage
73%
1419
CVE-2020-10148CISA KEVConflicting evidence

SolarWinds Orion Authentication Bypass Vulnerability

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

SolarWindsOrion

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.998.7
Coverage
73%
1420
CVE-2020-8657CISA KEVConflicting evidence

EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

EyesOfNetworkEyesOfNetwork

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.798.7
Coverage
73%
1421
CVE-2019-4716CISA KEVConflicting evidence

IBM Planning Analytics Remote Code Execution Vulnerability

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

IBMPlanning Analytics

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
83.198.6
Coverage
73%
1422
CVE-2021-31755CISA KEVConflicting evidence

Tenda AC11 Router Stack Buffer Overflow Vulnerability

Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.

TendaAC11 Router

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
83.098.5
Coverage
73%
1423
CVE-2020-3952CISA KEVConflicting evidence

VMware vCenter Server Information Disclosure Vulnerability

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.

VMwarevCenter Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.098.5
Coverage
73%
1424
CVE-2021-30116CISA KEVKnown ransomwareConflicting evidence

Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

KaseyaVirtual System/Server Administrator (VSA)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
77.398.5
Coverage
73%
1425
CVE-2020-3161CISA KEVConflicting evidence

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

CiscoCisco IP Phones

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.898.3
Coverage
73%
1426
CVE-2018-11776CISA KEVConflicting evidence

Apache Struts Remote Code Execution Vulnerability

Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.

ApacheStruts

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
80.298.2
Coverage
73%
1427

Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

MicrosoftMSCOMCTL.OCX

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.098.2
Coverage
85%
1428
CVE-2017-11882CISA KEVKnown ransomwareConflicting evidence

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.598.2
Coverage
73%
1429
CVE-2017-0199CISA KEVKnown ransomwareConflicting evidence

Microsoft Office and WordPad Remote Code Execution Vulnerability

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

MicrosoftOffice and WordPad

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.598.2
Coverage
73%
1430
CVE-2020-17496CISA KEVConflicting evidence

vBulletin PHP Module Remote Code Execution Vulnerability

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

vBulletinvBulletin

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.598.2
Coverage
73%
1431
CVE-2020-3992CISA KEVKnown ransomwareConflicting evidence

VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

VMwareESXi

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.798.2
Coverage
73%
1432
CVE-2021-27561CISA KEVConflicting evidence

Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

YealinkDevice Management

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
82.798.2
Coverage
73%
1433
CVE-2020-8644CISA KEVConflicting evidence

PlaySMS Server-Side Template Injection Vulnerability

PlaySMS contains a server-side template injection vulnerability that allows for remote code execution.

PlaySMSPlaySMS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.498.1
Coverage
73%
1434

ThinkPHP Remote Code Execution Vulnerability

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

ThinkPHPThinkPHP

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
81.798.0
Coverage
85%
1435
CVE-2015-1641CISA KEVConflicting evidence

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.297.9
Coverage
73%
1436
CVE-2020-14871CISA KEVConflicting evidence

Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.

OracleSolaris and Zettabyte File System (ZFS)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.997.9
Coverage
73%
1437
CVE-2020-10987CISA KEVConflicting evidence

Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.

TendaAC1900 Router AC15 Model

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.497.9
Coverage
73%
1438
CVE-2021-20021CISA KEVKnown ransomwareConflicting evidence

SonicWall Email Security Improper Privilege Management Vulnerability

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

SonicWallSonicWall Email Security

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
77.097.8
Coverage
73%
1439

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
81.597.8
Coverage
85%
1440
CVE-2018-6789CISA KEVKnown ransomwareConflicting evidence

Exim Buffer Overflow Vulnerability

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

EximExim

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.997.6
Coverage
73%
1441
CVE-2012-3152CISA KEVConflicting evidence

Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems.

OracleFusion Middleware

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.997.6
Coverage
73%
1442
CVE-2017-0143CISA KEVKnown ransomware

Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
81.397.6
Coverage
85%
1443
CVE-2018-0802CISA KEVConflicting evidence

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.897.6
Coverage
73%
1444
CVE-2020-0688CISA KEVKnown ransomware

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.097.5
Coverage
85%
1445
CVE-2021-34527CISA KEVKnown ransomware

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
82.097.5
Coverage
85%
1446

Sonatype Nexus Repository Remote Code Execution Vulnerability

Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.

SonatypeNexus Repository

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
81.997.4
Coverage
85%
1447
CVE-2020-14883CISA KEVConflicting evidence

Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

OracleWebLogic Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.897.3
Coverage
73%
1448

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

AtlassianConfluence Server and Data Center

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
81.797.2
Coverage
85%
1449
CVE-2017-8759CISA KEVConflicting evidence

Microsoft .NET Framework Remote Code Execution Vulnerability

Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

Microsoft.NET Framework

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.397.1
Coverage
73%
1450
CVE-2017-9248CISA KEVConflicting evidence

Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files.

ProgressASP.NET AJAX and Sitefinity

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.196.8
Coverage
73%