Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| Critical | CVE-2026-0257 Explained | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vu... | Palo Alto Networks | May 29, 2026 |
| High | CVE-2026-8398 ↗ | Daemon Daemon Tools Lite — Daemon Tools Lite Embedded Malicious Code Vulnerabi... | Daemon | May 27, 2026 |
| Critical | CVE-2026-45321 Explained | TanStack TanStack — TanStack Unspecified Vulnerability | TanStack | May 27, 2026 |
| Critical | CVE-2026-48027 Explained | Nx Nx Console — Nx Console Embedded Malicious Code Vulnerability | Nx | May 27, 2026 |
| High | CVE-2026-48172 Explained | LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin Privilege Escalation Vulnera... | LiteSpeed | May 26, 2026 |
| High | CVE-2026-9082 Explained | Drupal Core — Drupal Core SQL Injection Vulnerability | Drupal | May 22, 2026 |
| High | CVE-2026-34926 Explained | Trend Micro Apex One — Trend Micro Apex One (On-Premise) Directory Traversal V... | Trend Micro | May 21, 2026 |
| High | CVE-2025-34291 Explained | Langflow Langflow — Langflow Origin Validation Error Vulnerability | Langflow | May 21, 2026 |
| High | CVE-2026-45498 ↗ | Microsoft Defender — Microsoft Defender Denial of Service Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2026-41091 ↗ | Microsoft Defender — Microsoft Defender Link Following Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2010-0806 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulne... | Microsoft | May 20, 2026 |
| High | CVE-2010-0249 Explained | Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulne... | Microsoft | May 20, 2026 |
| High | CVE-2009-3459 Explained | Adobe Acrobat and Reader — Adobe Acrobat and Reader Heap-Based Buffer Overflow... | Adobe | May 20, 2026 |
| High | CVE-2009-1537 ↗ | Microsoft DirectX — Microsoft DirectX NULL Byte Overwrite Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2008-4250 Explained | Microsoft Windows — Microsoft Windows Buffer Overflow Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2026-42897 Explained | Microsoft Microsoft — Microsoft Exchange Server Cross-Site Scripting Vulnerabi... | Microsoft | May 15, 2026 |
| High | CVE-2026-20182 Explained | Cisco Catalyst SD-WAN — Cisco Catalyst SD-WAN Controller Authentication Bypass... | Cisco | May 14, 2026 |
| High | CVE-2026-42208 Explained | BerriAI LiteLLM — BerriAI LiteLLM SQL Injection Vulnerability | BerriAI | May 8, 2026 |
| High | CVE-2026-6973 Explained | Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... | Ivanti | May 7, 2026 |
| High | CVE-2026-0300 Explained | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Out-of-bounds Write Vuln... | Palo Alto Networks | May 6, 2026 |
| High | CVE-2026-31431 Explained | Linux Kernel — Linux Kernel Incorrect Resource Transfer Between Spheres Vulner... | Linux | May 1, 2026 |
| Critical | CVE-2026-41940 Explained | WebPros cPanel & WHM and WP2 (WordPress Squared) — WebPros cPanel & WHM and WP... | WebPros | Apr 30, 2026 |
| High | CVE-2026-32202 Explained | Microsoft Windows — Microsoft Windows Protection Mechanism Failure Vulnerabili... | Microsoft | Apr 28, 2026 |
| Critical | CVE-2024-1708 Explained | ConnectWise ScreenConnect — ConnectWise ScreenConnect Path Traversal Vulnerabi... | ConnectWise | Apr 28, 2026 |
| Critical | CVE-2024-57726 Explained | SimpleHelp SimpleHelp — SimpleHelp Missing Authorization Vulnerability | SimpleHelp | Apr 24, 2026 |
| Critical | CVE-2024-57728 ↗ | SimpleHelp SimpleHelp — SimpleHelp Path Traversal Vulnerability | SimpleHelp | Apr 24, 2026 |
| High | CVE-2024-7399 ↗ | Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server Path Traversal Vulnera... | Samsung | Apr 24, 2026 |
| High | CVE-2025-29635 ↗ | D-Link DIR-823X — D-Link DIR-823X Command Injection Vulnerability | D-Link | Apr 24, 2026 |
| High | CVE-2026-39987 ↗ | Marimo Marimo — Marimo Remote Code Execution Vulnerability | Marimo | Apr 23, 2026 |
| Critical | CVE-2026-33825 ↗ | Microsoft Defender — Microsoft Defender Insufficient Granularity of Access Con... | Microsoft | Apr 22, 2026 |
| Critical | CVE-2024-27199 Explained | JetBrains TeamCity — JetBrains TeamCity Relative Path Traversal Vulnerability | JetBrains | Apr 20, 2026 |
| High | CVE-2025-32975 ↗ | Quest KACE Systems Management Appliance (SMA) — Quest KACE Systems Management... | Quest | Apr 20, 2026 |
| High | CVE-2026-20128 ↗ | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Storing Password... | Cisco | Apr 20, 2026 |
| High | CVE-2025-48700 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Apr 20, 2026 |
| Critical | CVE-2023-27351 Explained | PaperCut NG/MF — PaperCut NG/MF Improper Authentication Vulnerability | PaperCut | Apr 20, 2026 |
| High | CVE-2025-2749 ↗ | Kentico Kentico Xperience — Kentico Xperience Path Traversal Vulnerability | Kentico | Apr 20, 2026 |
| High | CVE-2026-20133 ↗ | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Exposure of Sens... | Cisco | Apr 20, 2026 |
| High | CVE-2026-20122 Explained | Cisco Catalyst SD-WAN Manger — Cisco Catalyst SD-WAN Manager Incorrect Use of... | Cisco | Apr 20, 2026 |
| High | CVE-2026-34197 Explained | Apache ActiveMQ — Apache ActiveMQ Improper Input Validation Vulnerability | Apache | Apr 16, 2026 |
| High | CVE-2026-32201 Explained | Microsoft SharePoint Server — Microsoft SharePoint Server Improper Input Valid... | Microsoft | Apr 14, 2026 |
| High | CVE-2009-0238 ↗ | Microsoft Office — Microsoft Office Remote Code Execution | Microsoft | Apr 14, 2026 |
| High | CVE-2026-34621 ↗ | Adobe Acrobat and Reader — Adobe Acrobat and Reader Prototype Pollution Vulner... | Adobe | Apr 13, 2026 |
| High | CVE-2026-21643 Explained | Fortinet FortiClient EMS — Fortinet FortiClient EMS SQL Injection Vulnerabilit... | Fortinet | Apr 13, 2026 |
| High | CVE-2020-9715 ↗ | Adobe Acrobat — Adobe Acrobat Use-After-Free Vulnerability | Adobe | Apr 13, 2026 |
| High | CVE-2023-36424 ↗ | Microsoft Windows — Microsoft Windows Out-of-Bounds Read Vulnerability | Microsoft | Apr 13, 2026 |
| Critical | CVE-2023-21529 Explained | Microsoft Exchange Server — Microsoft Exchange Server Deserialization of Untru... | Microsoft | Apr 13, 2026 |
| High | CVE-2025-60710 ↗ | Microsoft Windows — Microsoft Windows Link Following Vulnerability | Microsoft | Apr 13, 2026 |
| High | CVE-2012-1854 ↗ | Microsoft Visual Basic for Applications (VBA) — Microsoft Visual Basic for App... | Microsoft | Apr 13, 2026 |
| High | CVE-2026-1340 Explained | Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... | Ivanti | Apr 8, 2026 |
| High | CVE-2026-35616 ↗ | Fortinet FortiClient EMS — Fortinet FortiClient EMS Improper Access Control Vu... | Fortinet | Apr 6, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.