Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,622 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2014-4123 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Privilege Escalation... | Microsoft | May 25, 2022 |
| High | CVE-2014-8439 ↗ | Adobe Flash Player — Adobe Flash Player Dereferenced Pointer Vulnerability | Adobe | May 25, 2022 |
| High | CVE-2014-4148 ↗ | Microsoft Windows — Microsoft Windows Remote Code Execution Vulnerability | Microsoft | May 25, 2022 |
| High | CVE-2015-1671 ↗ | Microsoft Windows — Microsoft Windows Remote Code Execution Vulnerability | Microsoft | May 25, 2022 |
| High | CVE-2015-6175 ↗ | Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerabilit... | Microsoft | May 25, 2022 |
| High | CVE-2015-8651 ↗ | Adobe Flash Player — Adobe Flash Player Integer Overflow Vulnerability | Adobe | May 25, 2022 |
| High | CVE-2015-4495 ↗ | Mozilla Firefox — Mozilla Firefox Security Feature Bypass Vulnerability | Mozilla | May 25, 2022 |
| High | CVE-2015-1769 ↗ | Microsoft Windows — Microsoft Windows Mount Manager Privilege Escalation Vulne... | Microsoft | May 25, 2022 |
| High | CVE-2015-2425 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vu... | Microsoft | May 25, 2022 |
| High | CVE-2015-2360 ↗ | Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | May 25, 2022 |
| High | CVE-2015-0071 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer ASLR Bypass Vulnerab... | Microsoft | May 25, 2022 |
| High | CVE-2015-0016 ↗ | Microsoft Windows — Microsoft Windows TS WebProxy Directory Traversal Vulnerab... | Microsoft | May 25, 2022 |
| High | CVE-2015-0310 ↗ | Adobe Flash Player — Adobe Flash Player ASLR Bypass Vulnerability | Adobe | May 25, 2022 |
| Critical | CVE-2016-0034 ↗ | Microsoft Silverlight — Microsoft Silverlight Runtime Remote Code Execution Vu... | Microsoft | May 25, 2022 |
| High | CVE-2016-0984 ↗ | Adobe Flash Player and AIR — Adobe Flash Player and AIR Use-After-Free Vulnera... | Adobe | May 25, 2022 |
| High | CVE-2016-1010 ↗ | Adobe Flash Player and AIR — Adobe Flash Player and AIR Integer Overflow Vulne... | Adobe | May 25, 2022 |
| High | CVE-2016-7256 ↗ | Microsoft Windows — Microsoft Windows Open Type Font Remote Code Execution Vul... | Microsoft | May 25, 2022 |
| High | CVE-2016-3393 ↗ | Microsoft Windows — Microsoft Windows Graphics Device Interface (GDI) Remote C... | Microsoft | May 25, 2022 |
| High | CVE-2019-3010 ↗ | Oracle Solaris — Oracle Solaris Privilege Escalation Vulnerability | Oracle | May 25, 2022 |
| High | CVE-2016-3298 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Messaging API Inform... | Microsoft | May 24, 2022 |
| High | CVE-2016-6367 ↗ | Cisco Adaptive Security Appliance (ASA) — Cisco Adaptive Security Appliance (A... | Cisco | May 24, 2022 |
| High | CVE-2016-6366 ↗ | Cisco Adaptive Security Appliance (ASA) — Cisco Adaptive Security Appliance (A... | Cisco | May 24, 2022 |
| High | CVE-2016-4657 ↗ | Apple iOS — Apple iOS Webkit Memory Corruption Vulnerability | Apple | May 24, 2022 |
| High | CVE-2016-4656 ↗ | Apple iOS — Apple iOS Memory Corruption Vulnerability | Apple | May 24, 2022 |
| High | CVE-2016-4655 ↗ | Apple iOS — Apple iOS Information Disclosure Vulnerability | Apple | May 24, 2022 |
| Critical | CVE-2016-3351 ↗ | Microsoft Internet Explorer and Edge — Microsoft Internet Explorer and Edge In... | Microsoft | May 24, 2022 |
| High | CVE-2016-0162 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Information Disclosu... | Microsoft | May 24, 2022 |
| Critical | CVE-2017-18362 ↗ | Kaseya Virtual System/Server Administrator (VSA) — Kaseya VSA SQL Injection Vu... | Kaseya | May 24, 2022 |
| High | CVE-2017-8543 ↗ | Microsoft Windows — Microsoft Windows Search Remote Code Execution Vulnerabili... | Microsoft | May 24, 2022 |
| High | CVE-2017-8291 ↗ | Artifex Ghostscript — Artifex Ghostscript Type Confusion Vulnerability | Artifex | May 24, 2022 |
| High | CVE-2017-0210 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Privilege Escalation... | Microsoft | May 24, 2022 |
| High | CVE-2017-0149 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vu... | Microsoft | May 24, 2022 |
| High | CVE-2017-0005 ↗ | Microsoft Windows — Microsoft Windows Graphics Device Interface (GDI) Privileg... | Microsoft | May 24, 2022 |
| High | CVE-2017-0022 ↗ | Microsoft XML Core Services — Microsoft XML Core Services Information Disclosu... | Microsoft | May 24, 2022 |
| Critical | CVE-2017-0147 ↗ | Microsoft SMBv1 server — Microsoft Windows SMBv1 Information Disclosure Vulner... | Microsoft | May 24, 2022 |
| Critical | CVE-2018-19943 ↗ | QNAP Network Attached Storage (NAS) — QNAP NAS File Station Cross-Site Scripti... | QNAP | May 24, 2022 |
| Critical | CVE-2018-19949 ↗ | QNAP Network Attached Storage (NAS) — QNAP NAS File Station Command Injection... | QNAP | May 24, 2022 |
| Critical | CVE-2018-19953 ↗ | QNAP Network Attached Storage (NAS) — QNAP NAS File Station Cross-Site Scripti... | QNAP | May 24, 2022 |
| High | CVE-2018-8611 ↗ | Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerabilit... | Microsoft | May 24, 2022 |
| High | CVE-2018-8589 ↗ | Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | May 23, 2022 |
| High | CVE-2018-5002 ↗ | Adobe Flash Player — Adobe Flash Player Stack-based Buffer Overflow Vulnerabil... | Adobe | May 23, 2022 |
| Critical | CVE-2019-1130 ↗ | Microsoft Windows — Microsoft Windows AppX Deployment Service Privilege Escala... | Microsoft | May 23, 2022 |
| Critical | CVE-2019-1385 ↗ | Microsoft Windows — Microsoft Windows AppX Deployment Extensions Privilege Esc... | Microsoft | May 23, 2022 |
| High | CVE-2019-18426 ↗ | Meta Platforms WhatsApp — WhatsApp Cross-Site Scripting Vulnerability | Meta Platforms | May 23, 2022 |
| High | CVE-2019-8720 ↗ | WebKitGTK WebKitGTK — WebKitGTK Memory Corruption Vulnerability | WebKitGTK | May 23, 2022 |
| High | CVE-2019-11708 ↗ | Mozilla Firefox and Thunderbird — Mozilla Firefox and Thunderbird Sandbox Esca... | Mozilla | May 23, 2022 |
| High | CVE-2019-11707 ↗ | Mozilla Firefox and Thunderbird — Mozilla Firefox and Thunderbird Type Confusi... | Mozilla | May 23, 2022 |
| High | CVE-2019-13720 ↗ | Google Chrome WebAudio — Google Chrome WebAudio Use-After-Free Vulnerability | May 23, 2022 | |
| High | CVE-2019-0880 ↗ | Microsoft Windows — Microsoft Windows Privilege Escalation Vulnerability | Microsoft | May 23, 2022 |
| High | CVE-2019-0703 ↗ | Microsoft Windows — Microsoft Windows SMB Information Disclosure Vulnerability | Microsoft | May 23, 2022 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.