Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 14511500
1451
CVE-2021-1675CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
78.196.8
Coverage
73%
1452
CVE-2021-40444CISA KEVKnown ransomwareConflicting evidence

Microsoft MSHTML Remote Code Execution Vulnerability

Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

MicrosoftMSHTML

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
76.796.7
Coverage
73%
1453
CVE-2021-42258CISA KEVKnown ransomwareConflicting evidence

BQE BillQuick Web Suite SQL Injection Vulnerability

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

BQEBillQuick Web Suite

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
74.196.6
Coverage
73%
1454
CVE-2017-9822CISA KEVKnown ransomwareConflicting evidence

DotNetNuke (DNN) Remote Code Execution Vulnerability

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

DotNetNuke (DNN)DotNetNuke (DNN)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.796.5
Coverage
73%
1455
CVE-2020-4427CISA KEVConflicting evidence

IBM Data Risk Manager Security Bypass Vulnerability

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

IBMData Risk Manager

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.296.2
Coverage
73%
1456
CVE-2018-4939CISA KEVConflicting evidence

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

AdobeColdFusion

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
80.495.9
Coverage
73%
1457
CVE-2021-21017CISA KEVConflicting evidence

Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

AdobeAcrobat and Reader

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
75.695.6
Coverage
73%
1458
CVE-2017-9805CISA KEVConflicting evidence

Apache Struts Deserialization of Untrusted Data Vulnerability

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

ApacheStruts

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.995.2
Coverage
73%
1459

Nagios XI Remote Code Execution Vulnerability

Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.

NagiosNagios XI

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.695.1
Coverage
85%
1460
CVE-2021-27104CISA KEVKnown ransomwareConflicting evidence

Accellion FTA OS Command Injection Vulnerability

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

AccellionFTA

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
79.595.0
Coverage
73%
1461
CVE-2016-0185CISA KEVConflicting evidence

Microsoft Windows Media Center Remote Code Execution Vulnerability

Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.295.0
Coverage
73%
1462
CVE-2021-26411CISA KEVKnown ransomwareConflicting evidence

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
70.795.0
Coverage
73%
1463
CVE-2019-11539CISA KEVKnown ransomwareConflicting evidence

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

IvantiPulse Connect Secure and Pulse Policy Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.194.9
Coverage
73%
1464
CVE-2020-6418CISA KEVConflicting evidence

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
74.894.8
Coverage
73%
1465
CVE-2020-29557CISA KEVConflicting evidence

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

D-LinkDIR-825 R1 Devices

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
79.294.7
Coverage
73%
1466
CVE-2020-26919CISA KEVConflicting evidence

Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability

Netgear JGS516PE devices contain a missing function level access control vulnerability.

NETGEARJGS516PE Devices

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.994.6
Coverage
73%
1467
CVE-2021-27065CISA KEVKnown ransomwareConflicting evidence

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.094.5
Coverage
73%
1468
CVE-2020-0601CISA KEVConflicting evidence

Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.494.2
Coverage
73%
1469
CVE-2020-1147CISA KEVConflicting evidence

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

Microsoft.NET Framework, SharePoint, Visual Studio

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.493.9
Coverage
73%
1470
CVE-2021-26857CISA KEVKnown ransomwareConflicting evidence

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.493.9
Coverage
73%
1471
CVE-2021-21220CISA KEVConflicting evidence

Google Chromium V8 Improper Input Validation Vulnerability

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
73.893.8
Coverage
73%
1472
CVE-2020-3452CISA KEVConflicting evidence

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.593.7
Coverage
73%
1473
CVE-2019-7481CISA KEVKnown ransomwareConflicting evidence

SonicWall SMA100 SQL Injection Vulnerability

SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.

SonicWallSMA100

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.593.7
Coverage
73%
1474
CVE-2018-0296CISA KEVConflicting evidence

Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

CiscoAdaptive Security Appliance (ASA)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.593.7
Coverage
73%
1475
CVE-2019-1653CISA KEVConflicting evidence

Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

CiscoSmall Business RV320 and RV325 Routers

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.593.7
Coverage
73%
1476
CVE-2021-22893CISA KEVKnown ransomwareConflicting evidence

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.593.7
Coverage
73%
1477
CVE-2014-1812CISA KEVKnown ransomware

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.193.6
Coverage
85%
1478
CVE-2019-17558CISA KEVConflicting evidence

Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.

ApacheSolr

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.493.6
Coverage
73%
1479
CVE-2020-12812CISA KEVKnown ransomwareConflicting evidence

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

FortinetFortiOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.893.5
Coverage
73%
1480
CVE-2020-11738CISA KEVConflicting evidence

WordPress Snap Creek Duplicator Plugin File Download Vulnerability

WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.

WordPressSnap Creek Duplicator Plugin

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.393.5
Coverage
73%
1481
CVE-2020-8655CISA KEVConflicting evidence

EyesOfNetwork Improper Privilege Management Vulnerability

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

EyesOfNetworkEyesOfNetwork

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
74.793.5
Coverage
73%
1482
CVE-2020-4428CISA KEVConflicting evidence

IBM Data Risk Manager Remote Code Execution Vulnerability

IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

IBMData Risk Manager

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
78.293.5
Coverage
73%
1483
CVE-2018-4878CISA KEVKnown ransomware

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

AdobeFlash Player

Required actionThe impacted product is end-of-life and should be disconnected if still in use.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.793.4
Coverage
85%
1484
CVE-2021-28550CISA KEVConflicting evidence

Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

AdobeAcrobat and Reader

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
71.493.4
Coverage
73%
1485
CVE-2021-26858CISA KEVKnown ransomwareConflicting evidence

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.993.4
Coverage
73%
1486
CVE-2019-20085CISA KEVConflicting evidence

TVT NVMS-1000 Directory Traversal Vulnerability

TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.

TVTNVMS-1000

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.193.4
Coverage
73%
1487
CVE-2020-15999CISA KEVConflicting evidence

Google Chrome FreeType Heap Buffer Overflow Vulnerability

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

GoogleChrome FreeType

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
65.093.2
Coverage
73%
1488
CVE-2020-1020CISA KEVConflicting evidence

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.193.1
Coverage
73%
1489
CVE-2021-30551CISA KEVConflicting evidence

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
73.193.1
Coverage
73%
1490
CVE-2021-30632CISA KEVConflicting evidence

Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
73.193.1
Coverage
73%
1491
CVE-2020-5849CISA KEVConflicting evidence

Unraid Authentication Bypass Vulnerability

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

UnraidUnraid

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.893.1
Coverage
73%
1492
CVE-2020-12271CISA KEVKnown ransomwareConflicting evidence

Sophos SFOS SQL Injection Vulnerability

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords).

SophosSFOS

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.793.0
Coverage
73%
1493

Microsoft MSHTML Remote Code Execution Vulnerability

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

MicrosoftMSHTML

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.692.8
Coverage
85%
1494
CVE-2020-8260CISA KEVConflicting evidence

Ivanti Pulse Connect Secure Code Execution Vulnerability

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.992.6
Coverage
73%
1495

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
77.492.6
Coverage
85%
1496

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
76.092.5
Coverage
85%
1497
CVE-2021-33742CISA KEVConflicting evidence

Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
72.492.4
Coverage
73%
1498
CVE-2021-1732CISA KEVKnown ransomwareConflicting evidence

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
69.292.2
Coverage
73%
1499
CVE-2021-21224CISA KEVConflicting evidence

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
72.292.2
Coverage
73%
1500
CVE-2021-20016CISA KEVKnown ransomwareConflicting evidence

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

SonicWallSSLVPN SMA100

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
71.492.2
Coverage
73%