Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,717 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2026-20245 Explained | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Improper Encodin... | Cisco | Jun 9, 2026 |
| High | CVE-2026-7473 Explained | Arista Extensible Operating System — Arista Extensible Operating System Incomp... | Arista | Jun 9, 2026 |
| High | CVE-2026-11645 Explained | Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerabi... | Jun 9, 2026 | |
| Critical | CVE-2026-50751 Explained | Check Point Security Gateway — Check Point Security Gateway Improper Authentic... | Check Point | Jun 8, 2026 |
| High | CVE-2026-42271 Explained | BerriAI LiteLLM — BerriAI LiteLLM Command Injection Vulnerability | BerriAI | Jun 8, 2026 |
| High | CVE-2026-28318 Explained | SolarWinds Serv-U — SolarWinds Serv-U Uncontrolled Resource Consumption Vulner... | SolarWinds | Jun 5, 2026 |
| High | CVE-2026-45247 ↗ | Mirasvit Mirasvit Full Page Cache Warmer — Mirasvit Full Page Cache Warmer Des... | Mirasvit | Jun 3, 2026 |
| High | CVE-2025-48595 Explained | Android Framework — Android Framework Integer Overflow Vulnerability | Android | Jun 2, 2026 |
| High | CVE-2022-0492 Explained | Linux Kernel — Linux Kernel Improper Authentication Vulnerability | Linux | Jun 2, 2026 |
| High | CVE-2024-21182 Explained | Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability | Oracle | Jun 1, 2026 |
| Critical | CVE-2026-0257 Explained | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vu... | Palo Alto Networks | May 29, 2026 |
| High | CVE-2026-8398 ↗ | Daemon Daemon Tools Lite — Daemon Tools Lite Embedded Malicious Code Vulnerabi... | Daemon | May 27, 2026 |
| Critical | CVE-2026-45321 Explained | TanStack TanStack — TanStack Unspecified Vulnerability | TanStack | May 27, 2026 |
| Critical | CVE-2026-48027 Explained | Nx Nx Console — Nx Console Embedded Malicious Code Vulnerability | Nx | May 27, 2026 |
| High | CVE-2026-48172 Explained | LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin Privilege Escalation Vulnera... | LiteSpeed | May 26, 2026 |
| High | CVE-2026-9082 Explained | Drupal Core — Drupal Core SQL Injection Vulnerability | Drupal | May 22, 2026 |
| High | CVE-2026-34926 Explained | Trend Micro Apex One — Trend Micro Apex One (On-Premise) Directory Traversal V... | Trend Micro | May 21, 2026 |
| High | CVE-2025-34291 Explained | Langflow Langflow — Langflow Origin Validation Error Vulnerability | Langflow | May 21, 2026 |
| High | CVE-2026-45498 ↗ | Microsoft Defender — Microsoft Defender Denial of Service Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2026-41091 ↗ | Microsoft Defender — Microsoft Defender Link Following Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2010-0806 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulne... | Microsoft | May 20, 2026 |
| High | CVE-2010-0249 Explained | Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulne... | Microsoft | May 20, 2026 |
| High | CVE-2009-3459 Explained | Adobe Acrobat and Reader — Adobe Acrobat and Reader Heap-Based Buffer Overflow... | Adobe | May 20, 2026 |
| High | CVE-2009-1537 ↗ | Microsoft DirectX — Microsoft DirectX NULL Byte Overwrite Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2008-4250 Explained | Microsoft Windows — Microsoft Windows Buffer Overflow Vulnerability | Microsoft | May 20, 2026 |
| High | CVE-2026-42897 Explained | Microsoft Microsoft — Microsoft Exchange Server Cross-Site Scripting Vulnerabi... | Microsoft | May 15, 2026 |
| High | CVE-2026-20182 Explained | Cisco Catalyst SD-WAN — Cisco Catalyst SD-WAN Controller Authentication Bypass... | Cisco | May 14, 2026 |
| High | CVE-2026-42208 Explained | BerriAI LiteLLM — BerriAI LiteLLM SQL Injection Vulnerability | BerriAI | May 8, 2026 |
| High | CVE-2026-6973 Explained | Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... | Ivanti | May 7, 2026 |
| High | CVE-2026-0300 Explained | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Out-of-bounds Write Vuln... | Palo Alto Networks | May 6, 2026 |
| High | CVE-2026-31431 Explained | Linux Kernel — Linux Kernel Incorrect Resource Transfer Between Spheres Vulner... | Linux | May 1, 2026 |
| Critical | CVE-2026-41940 Explained | WebPros cPanel & WHM and WP2 (WordPress Squared) — WebPros cPanel & WHM and WP... | WebPros | Apr 30, 2026 |
| High | CVE-2026-32202 Explained | Microsoft Windows — Microsoft Windows Protection Mechanism Failure Vulnerabili... | Microsoft | Apr 28, 2026 |
| Critical | CVE-2024-1708 Explained | ConnectWise ScreenConnect — ConnectWise ScreenConnect Path Traversal Vulnerabi... | ConnectWise | Apr 28, 2026 |
| Critical | CVE-2024-57726 Explained | SimpleHelp SimpleHelp — SimpleHelp Missing Authorization Vulnerability | SimpleHelp | Apr 24, 2026 |
| Critical | CVE-2024-57728 ↗ | SimpleHelp SimpleHelp — SimpleHelp Path Traversal Vulnerability | SimpleHelp | Apr 24, 2026 |
| High | CVE-2024-7399 ↗ | Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server Path Traversal Vulnera... | Samsung | Apr 24, 2026 |
| High | CVE-2025-29635 ↗ | D-Link DIR-823X — D-Link DIR-823X Command Injection Vulnerability | D-Link | Apr 24, 2026 |
| High | CVE-2026-39987 ↗ | Marimo Marimo — Marimo Remote Code Execution Vulnerability | Marimo | Apr 23, 2026 |
| Critical | CVE-2026-33825 ↗ | Microsoft Defender — Microsoft Defender Insufficient Granularity of Access Con... | Microsoft | Apr 22, 2026 |
| Critical | CVE-2024-27199 Explained | JetBrains TeamCity — JetBrains TeamCity Relative Path Traversal Vulnerability | JetBrains | Apr 20, 2026 |
| High | CVE-2025-32975 ↗ | Quest KACE Systems Management Appliance (SMA) — Quest KACE Systems Management... | Quest | Apr 20, 2026 |
| High | CVE-2026-20128 ↗ | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Storing Password... | Cisco | Apr 20, 2026 |
| High | CVE-2025-48700 Explained | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Apr 20, 2026 |
| Critical | CVE-2023-27351 Explained | PaperCut NG/MF — PaperCut NG/MF Improper Authentication Vulnerability | PaperCut | Apr 20, 2026 |
| High | CVE-2025-2749 ↗ | Kentico Kentico Xperience — Kentico Xperience Path Traversal Vulnerability | Kentico | Apr 20, 2026 |
| High | CVE-2026-20133 ↗ | Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Exposure of Sens... | Cisco | Apr 20, 2026 |
| High | CVE-2026-20122 Explained | Cisco Catalyst SD-WAN Manger — Cisco Catalyst SD-WAN Manager Incorrect Use of... | Cisco | Apr 20, 2026 |
| High | CVE-2026-34197 Explained | Apache ActiveMQ — Apache ActiveMQ Improper Input Validation Vulnerability | Apache | Apr 16, 2026 |
| High | CVE-2026-32201 Explained | Microsoft SharePoint Server — Microsoft SharePoint Server Improper Input Valid... | Microsoft | Apr 14, 2026 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.