Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 15011550
1501
CVE-2020-8243CISA KEVConflicting evidence

Ivanti Pulse Connect Secure Code Execution Vulnerability

Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.392.1
Coverage
73%
1502
CVE-2021-30860CISA KEVConflicting evidence

Apple Multiple Products Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
74.491.9
Coverage
73%
1503
CVE-2019-2215CISA KEVConflicting evidence

Android Kernel Use-After-Free Vulnerability

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

AndroidAndroid Kernel

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
68.591.5
Coverage
73%
1504
CVE-2021-31207CISA KEVKnown ransomware

Microsoft Exchange Server Security Feature Bypass Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
76.291.5
Coverage
85%
1505
CVE-2016-3235CISA KEVConflicting evidence

Microsoft Office OLE DLL Side Loading Vulnerability

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.791.4
Coverage
73%
1506
CVE-2020-0938CISA KEVConflicting evidence

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.691.1
Coverage
73%
1507

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
75.891.0
Coverage
85%
1508
CVE-2018-15811CISA KEVConflicting evidence

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

DotNetNuke (DNN)DotNetNuke (DNN)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
69.791.0
Coverage
73%
1509
CVE-2018-18325CISA KEVConflicting evidence

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

DotNetNuke (DNN)DotNetNuke (DNN)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
69.791.0
Coverage
73%
1510
CVE-2020-16009CISA KEVConflicting evidence

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
70.990.9
Coverage
73%
1511

Apache HTTP Server Privilege Escalation Vulnerability

Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.

ApacheHTTP Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
74.190.6
Coverage
85%
1512
CVE-2021-30633CISA KEVConflicting evidence

Google Chromium Indexed DB API Use-After-Free Vulnerability

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Indexed DB API

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
68.490.4
Coverage
73%
1513

Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
74.990.4
Coverage
85%
1514
CVE-2019-17026CISA KEVConflicting evidence

Mozilla Firefox And Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.

MozillaFirefox and Thunderbird

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
70.290.2
Coverage
73%
1515
CVE-2020-8193CISA KEVConflicting evidence

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.390.1
Coverage
73%
1516
CVE-2021-36942CISA KEVKnown ransomwareConflicting evidence

Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
68.890.0
Coverage
73%
1517
CVE-2017-11774CISA KEVConflicting evidence

Microsoft Office Outlook Security Feature Bypass Vulnerability

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

MicrosoftOffice

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.590.0
Coverage
73%
1518
CVE-2020-11652CISA KEVConflicting evidence

SaltStack Salt Path Traversal Vulnerability

SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.

SaltStackSalt

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
68.689.8
Coverage
73%
1519
CVE-2019-8394CISA KEVConflicting evidence

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

ZohoManageEngine

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
66.089.8
Coverage
73%
1520

rConfig OS Command Injection Vulnerability

rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.

rConfigrConfig

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
74.189.6
Coverage
85%
1521
CVE-2021-34448CISA KEVConflicting evidence

Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
68.189.3
Coverage
73%
1522
CVE-2019-15752CISA KEVConflicting evidence

Docker Desktop Community Edition Privilege Escalation Vulnerability

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

DockerDesktop Community Edition

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
70.489.1
Coverage
73%
1523

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.689.1
Coverage
85%
1524
CVE-2020-17144CISA KEVConflicting evidence

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.

MicrosoftExchange Server

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
67.189.1
Coverage
73%
1525
CVE-2021-38003CISA KEVConflicting evidence

Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
69.089.0
Coverage
73%
1526

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.589.0
Coverage
85%
1527
CVE-2021-30807CISA KEVConflicting evidence

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.

AppleMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
70.289.0
Coverage
73%
1528

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

AmcrestCameras and Network Video Recorder (NVR)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.988.9
Coverage
85%
1529
CVE-2017-6327CISA KEVConflicting evidence

Symantec Messaging Gateway Remote Code Execution Vulnerability

Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform privilege escalating actions.

SymantecSymantec Messaging Gateway

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
68.188.9
Coverage
73%
1530
CVE-2021-37975CISA KEVConflicting evidence

Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
68.888.8
Coverage
73%
1531
CVE-2020-3580CISA KEVKnown ransomwareConflicting evidence

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

CiscoAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
65.088.7
Coverage
73%
1532
CVE-2019-1367CISA KEVKnown ransomware

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.388.5
Coverage
85%
1533
CVE-2010-5326CISA KEVConflicting evidence

SAP NetWeaver Remote Code Execution Vulnerability

SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request.

SAPNetWeaver

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
73.488.4
Coverage
73%
1534

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

MicrosoftWin32k

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.588.0
Coverage
85%
1535
CVE-2020-4006CISA KEVConflicting evidence

Multiple VMware Products Command Injection Vulnerability

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

VMwareMultiple Products

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
72.387.5
Coverage
73%
1536
CVE-2016-3976CISA KEVConflicting evidence

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.

SAPNetWeaver

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
66.287.4
Coverage
73%
1537
CVE-2019-9978CISA KEVConflicting evidence

WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability

WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.

WordPressSocial Warfare Plugin

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
67.987.4
Coverage
73%
1538
CVE-2020-1464CISA KEVConflicting evidence

Microsoft Windows Spoofing Vulnerability

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
58.187.3
Coverage
73%
1539
CVE-2021-21166CISA KEVConflicting evidence

Google Chromium Race Condition Vulnerability

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
67.387.3
Coverage
73%
1540
CVE-2021-31956CISA KEVConflicting evidence

Microsoft Windows NTFS Privilege Escalation Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
68.587.3
Coverage
73%
1541

Microsoft Defender Remote Code Execution Vulnerability

Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.

MicrosoftDefender

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
70.687.1
Coverage
85%
1542
CVE-2020-10181CISA KEVConflicting evidence

Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.

SumavisionEnhanced Multimedia Router (EMR)

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
66.387.0
Coverage
73%
1543
CVE-2019-18187CISA KEVConflicting evidence

Trend Micro OfficeScan Directory Traversal Vulnerability

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.

Trend MicroOfficeScan

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
62.587.0
Coverage
73%
1544

ImageMagick Arbitrary File Deletion Vulnerability

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

ImageMagickImageMagick

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.186.9
Coverage
85%
1545
CVE-2020-1380CISA KEVConflicting evidence

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

MicrosoftInternet Explorer

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
68.886.8
Coverage
73%
1546
CVE-2019-19356CISA KEVConflicting evidence

Netis WF2419 Devices Remote Code Execution Vulnerability

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

NetisWF2419 Devices

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
69.386.8
Coverage
73%
1547
CVE-2020-8599CISA KEVConflicting evidence

Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.

Trend MicroApex One and OfficeScan

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
71.386.8
Coverage
73%
1548
CVE-2021-31955CISA KEVConflicting evidence

Microsoft Windows Kernel Information Disclosure Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.

MicrosoftWindows

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2021-11-17
Priority interval
63.386.8
Coverage
73%
1549
CVE-2017-16651CISA KEVConflicting evidence

Roundcube Webmail File Disclosure Vulnerability

Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.

RoundcubeRoundcube Webmail

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
63.786.7
Coverage
73%
1550
CVE-2021-22899CISA KEVConflicting evidence

Ivanti Pulse Connect Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

IvantiPulse Connect Secure

Required actionApply updates per vendor instructions.

Added
2021-11-03
Due
2022-05-03
Priority interval
65.786.5
Coverage
73%