Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2026-3502 ↗ | TrueConf Client — TrueConf Client Download of Code Without Integrity Check Vul... | TrueConf | Apr 2, 2026 |
| High | CVE-2026-5281 ↗ | Google Dawn — Google Dawn Use-After-Free Vulnerability | Apr 1, 2026 | |
| High | CVE-2026-3055 Explained | Citrix NetScaler — Citrix NetScaler Out-of-Bounds Read Vulnerability | Citrix | Mar 30, 2026 |
| High | CVE-2025-53521 Explained | F5 BIG-IP — F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | F5 | Mar 27, 2026 |
| High | CVE-2026-33634 ↗ | Aquasecurity Trivy — Aquasecurity Trivy Embedded Malicious Code Vulnerability | Aquasecurity | Mar 26, 2026 |
| High | CVE-2026-33017 ↗ | Langflow Langflow — Langflow Code Injection Vulnerability | Langflow | Mar 25, 2026 |
| High | CVE-2025-31277 ↗ | Apple Multiple Products — Apple Multiple Products Buffer Overflow Vulnerabilit... | Apple | Mar 20, 2026 |
| High | CVE-2025-43520 ↗ | Apple Multiple Products — Apple Multiple Products Classic Buffer Overflow Vuln... | Apple | Mar 20, 2026 |
| High | CVE-2025-43510 ↗ | Apple Multiple Products — Apple Multiple Products Improper Locking Vulnerabili... | Apple | Mar 20, 2026 |
| High | CVE-2025-54068 ↗ | Laravel Livewire — Laravel Livewire Code Injection Vulnerability | Laravel | Mar 20, 2026 |
| High | CVE-2025-32432 ↗ | Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability | Craft CMS | Mar 20, 2026 |
| Critical | CVE-2026-20131 ↗ | Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Manageme... | Cisco | Mar 19, 2026 |
| High | CVE-2026-20963 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Mar 18, 2026 |
| High | CVE-2025-66376 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Mar 18, 2026 |
| High | CVE-2025-47813 ↗ | Wing FTP Server Wing FTP Server — Wing FTP Server Information Disclosure Vulne... | Wing FTP Server | Mar 16, 2026 |
| High | CVE-2026-3909 ↗ | Google Skia — Google Skia Out-of-Bounds Write Vulnerability | Mar 13, 2026 | |
| High | CVE-2026-3910 ↗ | Google Chromium V8 — Google Chromium V8 Improper Restriction of Operations Wit... | Mar 13, 2026 | |
| High | CVE-2025-68613 ↗ | n8n n8n — n8n Improper Control of Dynamically-Managed Code Resources Vulnerabi... | n8n | Mar 11, 2026 |
| High | CVE-2026-1603 ↗ | Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) Authentication B... | Ivanti | Mar 9, 2026 |
| High | CVE-2025-26399 ↗ | SolarWinds Web Help Desk — SolarWinds Web Help Desk Deserialization of Untrust... | SolarWinds | Mar 9, 2026 |
| High | CVE-2021-22054 ↗ | Omnissa Workspace One UEM — Omnissa Workspace ONE Server-Side Request Forgery | Omnissa | Mar 9, 2026 |
| High | CVE-2023-41974 ↗ | Apple iOS and iPadOS — Apple iOS and iPadOS Use-After-Free Vulnerability | Apple | Mar 5, 2026 |
| High | CVE-2021-30952 ↗ | Apple Multiple Products — Apple Multiple Products Integer Overflow or Wraparou... | Apple | Mar 5, 2026 |
| High | CVE-2023-43000 ↗ | Apple Multiple Products — Apple Multiple products Use-After-Free Vulnerability | Apple | Mar 5, 2026 |
| High | CVE-2021-22681 ↗ | Rockwell Multiple Products — Rockwell Multiple Products Insufficient Protected... | Rockwell | Mar 5, 2026 |
| High | CVE-2017-7921 ↗ | Hikvision Multiple Products — Hikvision Multiple Products Improper Authenticat... | Hikvision | Mar 5, 2026 |
| High | CVE-2026-21385 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Memory Corruption Vuln... | Qualcomm | Mar 3, 2026 |
| High | CVE-2026-22719 ↗ | Broadcom VMware Aria Operations — Broadcom VMware Aria Operations Command Inje... | Broadcom | Mar 3, 2026 |
| High | CVE-2026-20127 ↗ | Cisco Catalyst SD-WAN Controller and Manager — Cisco Catalyst SD-WAN Controlle... | Cisco | Feb 25, 2026 |
| High | CVE-2022-20775 ↗ | Cisco SD-WAN — Cisco SD-WAN Path Traversal Vulnerability | Cisco | Feb 25, 2026 |
| High | CVE-2026-25108 ↗ | Soliton Systems K.K FileZen — Soliton Systems K.K FileZen OS Command Injection... | Soliton Systems K.K | Feb 24, 2026 |
| High | CVE-2025-68461 ↗ | Roundcube Webmail — RoundCube Webmail Cross-site Scripting Vulnerability | Roundcube | Feb 20, 2026 |
| High | CVE-2025-49113 ↗ | Roundcube Webmail — RoundCube Webmail Deserialization of Untrusted Data Vulner... | Roundcube | Feb 20, 2026 |
| High | CVE-2026-22769 ↗ | Dell RecoverPoint for Virtual Machines (RP4VMs) — Dell RecoverPoint for Virtua... | Dell | Feb 18, 2026 |
| High | CVE-2021-22175 ↗ | GitLab GitLab — GitLab Server-Side Request Forgery (SSRF) Vulnerability | GitLab | Feb 18, 2026 |
| High | CVE-2026-2441 ↗ | Google Chromium — Google Chromium CSS Use-After-Free Vulnerability | Feb 17, 2026 | |
| High | CVE-2008-0015 ↗ | Microsoft Windows — Microsoft Windows Video ActiveX Control Remote Code Execu... | Microsoft | Feb 17, 2026 |
| High | CVE-2024-7694 ↗ | TeamT5 ThreatSonar Anti-Ransomware — TeamT5 ThreatSonar Anti-Ransomware Unrest... | TeamT5 | Feb 17, 2026 |
| High | CVE-2020-7796 ↗ | Synacor Zimbra Collaboration Suite — Synacor Zimbra Collaboration Suite (ZCS)... | Synacor | Feb 17, 2026 |
| Critical | CVE-2026-1731 ↗ | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) — BeyondTru... | BeyondTrust | Feb 13, 2026 |
| High | CVE-2025-40536 ↗ | SolarWinds Web Help Desk — SolarWinds Web Help Desk Security Control Bypass Vu... | SolarWinds | Feb 12, 2026 |
| High | CVE-2025-15556 ↗ | Notepad++ Notepad++ — Notepad++ Download of Code Without Integrity Check Vulne... | Notepad++ | Feb 12, 2026 |
| High | CVE-2024-43468 ↗ | Microsoft Configuration Manager — Microsoft Configuration Manager SQL Injectio... | Microsoft | Feb 12, 2026 |
| High | CVE-2026-20700 ↗ | Apple Multiple Products — Apple Multiple Buffer Overflow Vulnerability | Apple | Feb 12, 2026 |
| High | CVE-2026-21514 ↗ | Microsoft Office — Microsoft Office Word Reliance on Untrusted Inputs in a Sec... | Microsoft | Feb 10, 2026 |
| High | CVE-2026-21519 ↗ | Microsoft Windows — Microsoft Windows Type Confusion Vulnerability | Microsoft | Feb 10, 2026 |
| High | CVE-2026-21533 ↗ | Microsoft Windows — Microsoft Windows Improper Privilege Management Vulnerabil... | Microsoft | Feb 10, 2026 |
| High | CVE-2026-21510 ↗ | Microsoft Windows — Microsoft Windows Shell Protection Mechanism Failure Vulne... | Microsoft | Feb 10, 2026 |
| High | CVE-2026-21525 ↗ | Microsoft Windows — Microsoft Windows NULL Pointer Dereference Vulnerability | Microsoft | Feb 10, 2026 |
| High | CVE-2026-21513 ↗ | Microsoft Windows — Microsoft MSHTML Framework Protection Mechanism Failure Vu... | Microsoft | Feb 10, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.