Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,660 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2018-0151 ↗ | Cisco IOS and IOS XE Software — Cisco IOS Software and Cisco IOS XE Software Q... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0154 ↗ | Cisco IOS Software — Cisco IOS Software Integrated Services Module for VPN Den... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0155 ↗ | Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0156 ↗ | Cisco IOS Software and Cisco IOS XE Software — Cisco IOS Software and Cisco IO... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0158 ↗ | Cisco IOS Software and Cisco IOS XE Software — Cisco IOS and XE Software Inter... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0159 ↗ | Cisco IOS Software and Cisco IOS XE Software — Cisco IOS and XE Software Inter... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0161 ↗ | Cisco IOS Software — Cisco IOS Software Resource Management Errors Vulnerabili... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0167 ↗ | Cisco IOS, XR, and XE Software — Cisco IOS, XR, and XE Software Buffer Overflo... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0172 ↗ | Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software Improper Input V... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0173 ↗ | Cisco IOS and IOS XE Software — Cisco IOS and IOS XE Software Improper Input V... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0174 ↗ | Cisco IOS XE Software — Cisco IOS Software and Cisco IOS XE Software Improper... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0175 ↗ | Cisco IOS, XR, and XE Software — Cisco IOS, XR, and XE Software Buffer Overflo... | Cisco | Mar 3, 2022 |
| High | CVE-2018-0179 ↗ | Cisco IOS Software — Cisco IOS Software Denial-of-Service Vulnerability | Cisco | Mar 3, 2022 |
| High | CVE-2018-0180 ↗ | Cisco IOS Software — Cisco IOS Software Denial-of-Service Vulnerability | Cisco | Mar 3, 2022 |
| High | CVE-2018-8298 ↗ | ChakraCore ChakraCore scripting engine — ChakraCore Scripting Engine Type Conf... | ChakraCore | Mar 3, 2022 |
| Critical | CVE-2018-8581 ↗ | Microsoft Exchange Server — Microsoft Exchange Server Privilege Escalation Vul... | Microsoft | Mar 3, 2022 |
| High | CVE-2019-1297 ↗ | Microsoft Excel — Microsoft Excel Remote Code Execution Vulnerability | Microsoft | Mar 3, 2022 |
| High | CVE-2019-1652 ↗ | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers — Cisco Smal... | Cisco | Mar 3, 2022 |
| High | CVE-2019-16928 ↗ | Exim Exim Internet Mailer — Exim Out-of-bounds Write Vulnerability | Exim | Mar 3, 2022 |
| High | CVE-2020-11899 ↗ | Treck TCP/IP stack IPv6 — Treck TCP/IP stack Out-of-Bounds Read Vulnerability | Treck TCP/IP stack | Mar 3, 2022 |
| High | CVE-2020-1938 ↗ | Apache Tomcat — Apache Tomcat Improper Privilege Management Vulnerability | Apache | Mar 3, 2022 |
| Critical | CVE-2021-41379 ↗ | Microsoft Windows — Microsoft Windows Installer Privilege Escalation Vulnerabi... | Microsoft | Mar 3, 2022 |
| High | CVE-2022-20699 ↗ | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers — Cisco Sma... | Cisco | Mar 3, 2022 |
| High | CVE-2022-20700 ↗ | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers — Cisco Sma... | Cisco | Mar 3, 2022 |
| High | CVE-2022-20701 ↗ | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers — Cisco Sma... | Cisco | Mar 3, 2022 |
| High | CVE-2022-20703 ↗ | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers — Cisco Sma... | Cisco | Mar 3, 2022 |
| High | CVE-2022-20708 ↗ | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers — Cisco Sma... | Cisco | Mar 3, 2022 |
| High | CVE-2014-6352 ↗ | Microsoft Windows — Microsoft Windows Code Injection Vulnerability | Microsoft | Feb 25, 2022 |
| High | CVE-2017-0222 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Remote Code Executio... | Microsoft | Feb 25, 2022 |
| High | CVE-2017-8570 ↗ | Microsoft Office — Microsoft Office Remote Code Execution Vulnerability | Microsoft | Feb 25, 2022 |
| Critical | CVE-2022-24682 ↗ | Synacor Zimbra Collaborate Suite (ZCS) — Synacor Zimbra Collaborate Suite (ZCS... | Synacor | Feb 25, 2022 |
| High | CVE-2022-23134 ↗ | Zabbix Frontend — Zabbix Frontend Improper Access Control Vulnerability | Zabbix | Feb 22, 2022 |
| High | CVE-2022-23131 ↗ | Zabbix Frontend — Zabbix Frontend Authentication Bypass Vulnerability | Zabbix | Feb 22, 2022 |
| High | CVE-2013-3906 ↗ | Microsoft Graphics Component — Microsoft Graphics Component Memory Corruption... | Microsoft | Feb 15, 2022 |
| High | CVE-2014-1761 ↗ | Microsoft Word — Microsoft Word Memory Corruption Vulnerability | Microsoft | Feb 15, 2022 |
| High | CVE-2017-9841 ↗ | PHPUnit PHPUnit — PHPUnit Command Injection Vulnerability | PHPUnit | Feb 15, 2022 |
| Critical | CVE-2018-15982 ↗ | Adobe Flash Player — Adobe Flash Player Use-After-Free Vulnerability | Adobe | Feb 15, 2022 |
| Critical | CVE-2018-20250 ↗ | RARLAB WinRAR — WinRAR Absolute Path Traversal Vulnerability | RARLAB | Feb 15, 2022 |
| Critical | CVE-2018-8174 ↗ | Microsoft Windows — Microsoft Windows VBScript Engine Out-of-Bounds Write Vuln... | Microsoft | Feb 15, 2022 |
| Critical | CVE-2019-0752 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Type Confusion Vulne... | Microsoft | Feb 15, 2022 |
| High | CVE-2022-0609 ↗ | Google Chromium Animation — Google Chromium Animation Use-After-Free Vulnerabi... | Feb 15, 2022 | |
| High | CVE-2022-24086 ↗ | Adobe Commerce and Magento Open Source — Adobe Commerce and Magento Open Sourc... | Adobe | Feb 15, 2022 |
| High | CVE-2022-22620 ↗ | Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Webkit Use-After-F... | Apple | Feb 11, 2022 |
| High | CVE-2014-4404 ↗ | Apple OS X — Apple OS X Heap-Based Buffer Overflow Vulnerability | Apple | Feb 10, 2022 |
| High | CVE-2015-1130 ↗ | Apple OS X — Apple OS X Authentication Bypass Vulnerability | Apple | Feb 10, 2022 |
| High | CVE-2015-1635 ↗ | Microsoft HTTP.sys — Microsoft HTTP.sys Remote Code Execution Vulnerability | Microsoft | Feb 10, 2022 |
| High | CVE-2015-2051 ↗ | D-Link DIR-645 Router — D-Link DIR-645 Router Remote Code Execution Vulnerabil... | D-Link | Feb 10, 2022 |
| High | CVE-2016-3088 ↗ | Apache ActiveMQ — Apache ActiveMQ Improper Input Validation Vulnerability | Apache | Feb 10, 2022 |
| Critical | CVE-2017-0144 ↗ | Microsoft SMBv1 — Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft | Feb 10, 2022 |
| Critical | CVE-2017-0145 ↗ | Microsoft SMBv1 — Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft | Feb 10, 2022 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.