Browse all

Known Exploited Vulnerabilities (CISA KEV) — all

The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.

Clear

1,622 results

UrgencyCVEName / productVendorKEV added
High CVE-2021-22506 ↗ Micro Focus Micro Focus Access Manager — Micro Focus Access Manager Informatio... Micro Focus Nov 3, 2021
High CVE-2021-23874 ↗ McAfee McAfee Total Protection (MTP) — McAfee Total Protection (MTP) Improper... McAfee Nov 3, 2021
High CVE-2020-7961 ↗ Liferay Liferay Portal — Liferay Portal Deserialization of Untrusted Data Vuln... Liferay Nov 3, 2021
Critical CVE-2021-30116 ↗ Kaseya Virtual System/Server Administrator (VSA) — Kaseya Virtual System/Serve... Kaseya Nov 3, 2021
High CVE-2020-15505 ↗ Ivanti MobileIron Multiple Products — Ivanti MobileIron Multiple Products Remo... Ivanti Nov 3, 2021
High CVE-2016-3718 ↗ ImageMagick ImageMagick — ImageMagick Server-Side Request Forgery (SSRF) Vulne... ImageMagick Nov 3, 2021
High CVE-2016-3715 ↗ ImageMagick ImageMagick — ImageMagick Arbitrary File Deletion Vulnerability ImageMagick Nov 3, 2021
High CVE-2019-4716 ↗ IBM Planning Analytics — IBM Planning Analytics Remote Code Execution Vulnerab... IBM Nov 3, 2021
High CVE-2020-4428 ↗ IBM Data Risk Manager — IBM Data Risk Manager Remote Code Execution Vulnerabil... IBM Nov 3, 2021
High CVE-2020-4427 ↗ IBM Data Risk Manager — IBM Data Risk Manager Security Bypass Vulnerability IBM Nov 3, 2021
High CVE-2020-4430 ↗ IBM Data Risk Manager — IBM Data Risk Manager Directory Traversal Vulnerabilit... IBM Nov 3, 2021
High CVE-2021-30563 ↗ Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Nov 3, 2021
High CVE-2021-21220 ↗ Google Chromium V8 — Google Chromium V8 Improper Input Validation Vulnerabilit... Google Nov 3, 2021
High CVE-2021-21193 ↗ Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2021-21224 ↗ Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Nov 3, 2021
High CVE-2021-38003 ↗ Google Chromium V8 — Google Chromium V8 Memory Corruption Vulnerability Google Nov 3, 2021
High CVE-2021-38000 ↗ Google Chromium Intents — Google Chromium Intents Improper Input Validation Vu... Google Nov 3, 2021
High CVE-2021-21206 ↗ Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2021-30554 ↗ Google Chromium WebGL — Google Chromium WebGL Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2020-6418 ↗ Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Nov 3, 2021
High CVE-2021-37975 ↗ Google Chromium V8 — Google Chromium V8 Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2021-30551 ↗ Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Nov 3, 2021
High CVE-2021-37973 ↗ Google Chromium Portals — Google Chromium Portals Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2021-21148 ↗ Google Chromium V8 — Google Chromium V8 Heap Buffer Overflow Vulnerability Google Nov 3, 2021
High CVE-2021-30633 ↗ Google Chromium Indexed DB API — Google Chromium Indexed DB API Use-After-Free... Google Nov 3, 2021
High CVE-2020-16013 ↗ Google Chromium V8 — Google Chromium V8 Incorrect Implementation Vulnerabililt... Google Nov 3, 2021
High CVE-2021-30632 ↗ Google Chromium V8 — Google Chromium V8 Out-of-Bounds Write Vulnerability Google Nov 3, 2021
High CVE-2020-16009 ↗ Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability Google Nov 3, 2021
High CVE-2021-37976 ↗ Google Chromium — Google Chromium Information Disclosure Vulnerability Google Nov 3, 2021
High CVE-2020-16017 ↗ Google Chrome — Google Chrome Use-After-Free Vulnerability Google Nov 3, 2021
High CVE-2021-21166 ↗ Google Chromium — Google Chromium Race Condition Vulnerability Google Nov 3, 2021
High CVE-2020-15999 ↗ Google Chrome FreeType — Google Chrome FreeType Heap Buffer Overflow Vulnerabi... Google Nov 3, 2021
High CVE-2020-16010 ↗ Google Chrome for Android UI — Google Chrome for Android UI Heap Buffer Overfl... Google Nov 3, 2021
Critical CVE-2018-13379 ↗ Fortinet FortiOS — Fortinet FortiOS SSL VPN Path Traversal Vulnerability Fortinet Nov 3, 2021
Critical CVE-2020-12812 ↗ Fortinet FortiOS — Fortinet FortiOS SSL VPN Improper Authentication Vulnerabil... Fortinet Nov 3, 2021
High CVE-2019-5591 ↗ Fortinet FortiOS — Fortinet FortiOS Default Configuration Vulnerability Fortinet Nov 3, 2021
Critical CVE-2021-35464 ↗ ForgeRock Access Management (AM) — ForgeRock Access Management (AM) Core Serve... ForgeRock Nov 3, 2021
Critical CVE-2021-22986 ↗ F5 BIG-IP and BIG-IQ Centralized Management — F5 BIG-IP and BIG-IQ Centralized... F5 Nov 3, 2021
Critical CVE-2020-5902 ↗ F5 BIG-IP — F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Exe... F5 Nov 3, 2021
High CVE-2020-8655 ↗ EyesOfNetwork EyesOfNetwork — EyesOfNetwork Improper Privilege Management Vuln... EyesOfNetwork Nov 3, 2021
High CVE-2020-8657 ↗ EyesOfNetwork EyesOfNetwork — EyesOfNetwork Use of Hard-Coded Credentials Vuln... EyesOfNetwork Nov 3, 2021
Critical CVE-2018-6789 ↗ Exim Exim — Exim Buffer Overflow Vulnerability Exim Nov 3, 2021
Critical CVE-2021-22205 ↗ GitLab Community and Enterprise Editions — GitLab Community and Enterprise Edi... GitLab Nov 3, 2021
Critical CVE-2018-7600 ↗ Drupal Drupal Core — Drupal Core Remote Code Execution Vulnerability Drupal Nov 3, 2021
High CVE-2020-8515 ↗ DrayTek Multiple Vigor Routers — Multiple DrayTek Vigor Routers Web Management... DrayTek Nov 3, 2021
High CVE-2019-15752 ↗ Docker Desktop Community Edition — Docker Desktop Community Edition Privilege... Docker Nov 3, 2021
Critical CVE-2017-9822 ↗ DotNetNuke (DNN) DotNetNuke (DNN) — DotNetNuke (DNN) Remote Code Execution Vul... DotNetNuke (DNN) Nov 3, 2021
High CVE-2018-18325 ↗ DotNetNuke (DNN) DotNetNuke (DNN) — DotNetNuke (DNN) Inadequate Encryption Str... DotNetNuke (DNN) Nov 3, 2021
High CVE-2018-15811 ↗ DotNetNuke (DNN) DotNetNuke (DNN) — DotNetNuke (DNN) Inadequate Encryption Str... DotNetNuke (DNN) Nov 3, 2021
High CVE-2020-25506 ↗ D-Link DNS-320 Device — D-Link DNS-320 Device Command Injection Vulnerability D-Link Nov 3, 2021

Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.

Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.