Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2026-18577 ↗ | N-able N-central — N-able N-central Authentication Bypass Using an Alternate P... | N-able | Aug 3, 2026 |
| High | CVE-2026-20316 ↗ | Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Manageme... | Cisco | Jul 29, 2026 |
| High | CVE-2026-16812 ↗ | Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Comma... | Arista | Jul 27, 2026 |
| High | CVE-2025-68686 ↗ | Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Un... | Fortinet | Jul 27, 2026 |
| High | CVE-2026-50522 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Jul 22, 2026 |
| High | CVE-2026-16232 ↗ | Check Point SmartConsole — Check Point SmartConsole Improper Authentication Vu... | Check Point | Jul 22, 2026 |
| High | CVE-2021-27137 ↗ | DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability | DD-WRT | Jul 21, 2026 |
| High | CVE-2026-0770 ↗ | Langflow Langflow — Langflow Inclusion of Functionality from Untrusted Control... | Langflow | Jul 21, 2026 |
| High | CVE-2026-63030 ↗ | WordPress Core — WordPress Core Interpretation Conflict Vulnerability | WordPress | Jul 21, 2026 |
| High | CVE-2026-60137 ↗ | WordPress Core — WordPress Core SQL Injection Vulnerability | WordPress | Jul 21, 2026 |
| High | CVE-2026-39808 ↗ | Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerabili... | Fortinet | Jul 16, 2026 |
| High | CVE-2026-25089 ↗ | Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerabili... | Fortinet | Jul 16, 2026 |
| High | CVE-2026-58644 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Jul 16, 2026 |
| High | CVE-2023-4346 ↗ | KNX Association KNX Protocol Connection Authorization Option 1 — KNX Associati... | KNX Association | Jul 15, 2026 |
| High | CVE-2026-46817 ↗ | Oracle E-Business Suite — Oracle E-Business Suite Improper Privilege Managemen... | Oracle | Jul 15, 2026 |
| Critical | CVE-2026-15410 ↗ | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Code Injection Vul... | SonicWall | Jul 14, 2026 |
| Critical | CVE-2026-15409 ↗ | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Reques... | SonicWall | Jul 14, 2026 |
| High | CVE-2026-56164 ↗ | Microsoft SharePoint Server — Microsoft SharePoint Server Missing Authenticati... | Microsoft | Jul 14, 2026 |
| High | CVE-2026-56155 ↗ | Microsoft Active Directory Federation Services — Microsoft Active Directory Fe... | Microsoft | Jul 14, 2026 |
| High | CVE-2008-4128 ↗ | Cisco IOS — Cisco IOS Cross-Site Request Forgery Vulnerability | Cisco | Jul 13, 2026 |
| High | CVE-2026-48939 ↗ | iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type V... | iCagenda | Jul 10, 2026 |
| High | CVE-2026-56291 ↗ | Balbooa Forms — Balbooa Forms Unrestricted Upload of File with Dangerous Type... | Balbooa | Jul 10, 2026 |
| High | CVE-2026-48282 ↗ | Adobe ColdFusion — Adobe ColdFusion Path Traversal Vulnerability | Adobe | Jul 7, 2026 |
| High | CVE-2026-56290 ↗ | Joomlack Page Builder — Joomlack Page Builder Improper Access Control Vulnerab... | Joomlack | Jul 7, 2026 |
| High | CVE-2026-55255 ↗ | Langflow Langflow — Langflow Authorization Bypass Through User-Controlled Key... | Langflow | Jul 7, 2026 |
| High | CVE-2026-48908 ↗ | JoomShaper SP Page Builder — JoomShaper SP Page Builder Unrestricted Upload of... | JoomShaper | Jul 7, 2026 |
| High | CVE-2026-45659 Explained | Microsoft SharePoint Server — Microsoft SharePoint Server Deserialization of U... | Microsoft | Jul 1, 2026 |
| High | CVE-2026-48558 Explained | SimpleHelp SimpleHelp — SimpleHelp Authentication Bypass Vulnerability | SimpleHelp | Jun 29, 2026 |
| High | CVE-2026-20230 Explained | Cisco Unified Communications Manager — Cisco Unified Communications Manager Se... | Cisco | Jun 25, 2026 |
| Critical | CVE-2026-12569 Explained | PTC Windchill and FlexPLM — PTC Windchill and FlexPLM Improper Input Validatio... | PTC | Jun 25, 2026 |
| High | CVE-2026-34908 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Access Control Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2026-34909 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Path Traversal Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2026-34910 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Input Validation Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2025-67038 ↗ | Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability | Lantronix | Jun 23, 2026 |
| High | CVE-2026-20253 Explained | Splunk Enterprise — Splunk Enterprise Missing Authentication for Critical Func... | Splunk | Jun 18, 2026 |
| High | CVE-2026-48907 ↗ | Widget Factory Joomla Content Editor — Widget Factory Joomla Content Editor Im... | Widget Factory | Jun 16, 2026 |
| High | CVE-2026-20262 Explained | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Directory or Pat... | Cisco | Jun 15, 2026 |
| High | CVE-2026-54420 ↗ | LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink)... | LiteSpeed | Jun 15, 2026 |
| Critical | CVE-2026-35273 Explained | Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise People... | Oracle | Jun 12, 2026 |
| High | CVE-2026-10520 Explained | Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability | Ivanti | Jun 11, 2026 |
| High | CVE-2026-20245 Explained | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Improper Encodin... | Cisco | Jun 9, 2026 |
| High | CVE-2026-7473 Explained | Arista Extensible Operating System — Arista Extensible Operating System Incomp... | Arista | Jun 9, 2026 |
| High | CVE-2026-11645 Explained | Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerabi... | Jun 9, 2026 | |
| Critical | CVE-2026-50751 Explained | Check Point Security Gateway — Check Point Security Gateway Improper Authentic... | Check Point | Jun 8, 2026 |
| High | CVE-2026-42271 Explained | BerriAI LiteLLM — BerriAI LiteLLM Command Injection Vulnerability | BerriAI | Jun 8, 2026 |
| High | CVE-2026-28318 Explained | SolarWinds Serv-U — SolarWinds Serv-U Uncontrolled Resource Consumption Vulner... | SolarWinds | Jun 5, 2026 |
| High | CVE-2026-45247 ↗ | Mirasvit Mirasvit Full Page Cache Warmer — Mirasvit Full Page Cache Warmer Des... | Mirasvit | Jun 3, 2026 |
| High | CVE-2025-48595 Explained | Android Framework — Android Framework Integer Overflow Vulnerability | Android | Jun 2, 2026 |
| High | CVE-2022-0492 Explained | Linux Kernel — Linux Kernel Improper Authentication Vulnerability | Linux | Jun 2, 2026 |
| High | CVE-2024-21182 Explained | Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability | Oracle | Jun 1, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.