Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,717 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2026-33824 Explained | Microsoft Internet Key Exchange (IKE) Service Extensions — Microsoft Internet... | Microsoft | Aug 18, 2026 |
| High | CVE-2025-62593 ↗ | Ray-Project Ray — Ray-Project Ray Code Injection Vulnerability | Ray-Project | Aug 17, 2026 |
| High | CVE-2026-72898 Explained | Metabase Metabase — Metabase SQL Injection Vulnerability | Metabase | Aug 11, 2026 |
| High | CVE-2026-68820 Explained | Microsoft Windows Ancillary Function Driver for WinSock — Microsoft Windows An... | Microsoft | Aug 11, 2026 |
| High | CVE-2026-20349 Explained | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Th... | Cisco | Aug 11, 2026 |
| High | CVE-2026-8037 ↗ | Progress LoadMaster — Progress LoadMaster Command Injection Vulnerability | Progress | Aug 7, 2026 |
| High | CVE-2026-63077 Explained | JetBrains TeamCity — JetBrains TeamCity Deserialization of Untrusted Data Vuln... | JetBrains | Aug 5, 2026 |
| High | CVE-2026-9198 Explained | IBM Langflow — IBM Langflow Code Injection Vulnerability | IBM | Aug 4, 2026 |
| High | CVE-2026-34486 Explained | Apache Tomcat — Apache Tomcat Missing Encryption of Sensitive Data Vulnerabili... | Apache | Aug 4, 2026 |
| High | CVE-2026-18556 Explained | N-able N-central — N-able N-central Authentication Bypass Using an Alternate P... | N-able | Aug 4, 2026 |
| High | CVE-2026-18577 Explained | N-able N-central — N-able N-central Authentication Bypass Using an Alternate P... | N-able | Aug 3, 2026 |
| Critical | CVE-2026-20316 Explained | Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Manageme... | Cisco | Jul 29, 2026 |
| High | CVE-2026-16812 ↗ | Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Comma... | Arista | Jul 27, 2026 |
| High | CVE-2025-68686 ↗ | Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Un... | Fortinet | Jul 27, 2026 |
| High | CVE-2026-50522 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Jul 22, 2026 |
| High | CVE-2026-16232 ↗ | Check Point SmartConsole — Check Point SmartConsole Improper Authentication Vu... | Check Point | Jul 22, 2026 |
| High | CVE-2021-27137 ↗ | DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability | DD-WRT | Jul 21, 2026 |
| High | CVE-2026-0770 ↗ | Langflow Langflow — Langflow Inclusion of Functionality from Untrusted Control... | Langflow | Jul 21, 2026 |
| High | CVE-2026-63030 Explained | WordPress Core — WordPress Core Interpretation Conflict Vulnerability | WordPress | Jul 21, 2026 |
| High | CVE-2026-60137 ↗ | WordPress Core — WordPress Core SQL Injection Vulnerability | WordPress | Jul 21, 2026 |
| High | CVE-2026-39808 ↗ | Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerabili... | Fortinet | Jul 16, 2026 |
| High | CVE-2026-25089 ↗ | Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerabili... | Fortinet | Jul 16, 2026 |
| High | CVE-2026-58644 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Jul 16, 2026 |
| High | CVE-2023-4346 Explained | KNX Association KNX Protocol Connection Authorization Option 1 — KNX Associati... | KNX Association | Jul 15, 2026 |
| High | CVE-2026-46817 ↗ | Oracle E-Business Suite — Oracle E-Business Suite Improper Privilege Managemen... | Oracle | Jul 15, 2026 |
| Critical | CVE-2026-15410 Explained | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Code Injection Vul... | SonicWall | Jul 14, 2026 |
| Critical | CVE-2026-15409 Explained | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Server-Side Reques... | SonicWall | Jul 14, 2026 |
| High | CVE-2026-56164 ↗ | Microsoft SharePoint Server — Microsoft SharePoint Server Missing Authenticati... | Microsoft | Jul 14, 2026 |
| High | CVE-2026-56155 ↗ | Microsoft Active Directory Federation Services — Microsoft Active Directory Fe... | Microsoft | Jul 14, 2026 |
| High | CVE-2008-4128 Explained | Cisco IOS — Cisco IOS Cross-Site Request Forgery Vulnerability | Cisco | Jul 13, 2026 |
| High | CVE-2026-48939 ↗ | iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type V... | iCagenda | Jul 10, 2026 |
| High | CVE-2026-56291 ↗ | Balbooa Forms — Balbooa Forms Unrestricted Upload of File with Dangerous Type... | Balbooa | Jul 10, 2026 |
| High | CVE-2026-48282 Explained | Adobe ColdFusion — Adobe ColdFusion Path Traversal Vulnerability | Adobe | Jul 7, 2026 |
| High | CVE-2026-56290 ↗ | Joomlack Page Builder — Joomlack Page Builder Improper Access Control Vulnerab... | Joomlack | Jul 7, 2026 |
| High | CVE-2026-55255 ↗ | Langflow Langflow — Langflow Authorization Bypass Through User-Controlled Key... | Langflow | Jul 7, 2026 |
| High | CVE-2026-48908 ↗ | JoomShaper SP Page Builder — JoomShaper SP Page Builder Unrestricted Upload of... | JoomShaper | Jul 7, 2026 |
| Critical | CVE-2026-45659 Explained | Microsoft SharePoint Server — Microsoft SharePoint Server Deserialization of U... | Microsoft | Jul 1, 2026 |
| High | CVE-2026-48558 Explained | SimpleHelp SimpleHelp — SimpleHelp Authentication Bypass Vulnerability | SimpleHelp | Jun 29, 2026 |
| High | CVE-2026-20230 Explained | Cisco Unified Communications Manager — Cisco Unified Communications Manager Se... | Cisco | Jun 25, 2026 |
| Critical | CVE-2026-12569 Explained | PTC Windchill and FlexPLM — PTC Windchill and FlexPLM Improper Input Validatio... | PTC | Jun 25, 2026 |
| High | CVE-2026-34908 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Access Control Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2026-34909 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Path Traversal Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2026-34910 Explained | Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Input Validation Vulnerability | Ubiquiti | Jun 23, 2026 |
| High | CVE-2025-67038 ↗ | Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability | Lantronix | Jun 23, 2026 |
| High | CVE-2026-20253 Explained | Splunk Enterprise — Splunk Enterprise Missing Authentication for Critical Func... | Splunk | Jun 18, 2026 |
| High | CVE-2026-48907 ↗ | Widget Factory Joomla Content Editor — Widget Factory Joomla Content Editor Im... | Widget Factory | Jun 16, 2026 |
| High | CVE-2026-20262 Explained | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Directory or Pat... | Cisco | Jun 15, 2026 |
| High | CVE-2026-54420 ↗ | LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink)... | LiteSpeed | Jun 15, 2026 |
| Critical | CVE-2026-35273 Explained | Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise People... | Oracle | Jun 12, 2026 |
| High | CVE-2026-10520 Explained | Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability | Ivanti | Jun 11, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.