Browse all

Known Exploited Vulnerabilities (CISA KEV) — all

The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.

Clear

1,721 results

UrgencyCVEName / productVendorKEV added
High CVE-2026-20133 ↗ Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Exposure of Sens... Cisco Apr 20, 2026
High CVE-2026-20122 Explained Cisco Catalyst SD-WAN Manger — Cisco Catalyst SD-WAN Manager Incorrect Use of... Cisco Apr 20, 2026
High CVE-2026-34197 Explained Apache ActiveMQ — Apache ActiveMQ Improper Input Validation Vulnerability Apache Apr 16, 2026
High CVE-2026-32201 Explained Microsoft SharePoint Server — Microsoft SharePoint Server Improper Input Valid... Microsoft Apr 14, 2026
High CVE-2009-0238 ↗ Microsoft Office — Microsoft Office Remote Code Execution Microsoft Apr 14, 2026
High CVE-2026-34621 ↗ Adobe Acrobat and Reader — Adobe Acrobat and Reader Prototype Pollution Vulner... Adobe Apr 13, 2026
High CVE-2026-21643 Explained Fortinet FortiClient EMS — Fortinet FortiClient EMS SQL Injection Vulnerabilit... Fortinet Apr 13, 2026
High CVE-2020-9715 ↗ Adobe Acrobat — Adobe Acrobat Use-After-Free Vulnerability Adobe Apr 13, 2026
High CVE-2023-36424 ↗ Microsoft Windows — Microsoft Windows Out-of-Bounds Read Vulnerability Microsoft Apr 13, 2026
Critical CVE-2023-21529 Explained Microsoft Exchange Server — Microsoft Exchange Server Deserialization of Untru... Microsoft Apr 13, 2026
Critical CVE-2025-60710 Explained Microsoft Windows — Microsoft Windows Link Following Vulnerability Microsoft Apr 13, 2026
High CVE-2012-1854 ↗ Microsoft Visual Basic for Applications (VBA) — Microsoft Visual Basic for App... Microsoft Apr 13, 2026
High CVE-2026-1340 Explained Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... Ivanti Apr 8, 2026
High CVE-2026-35616 ↗ Fortinet FortiClient EMS — Fortinet FortiClient EMS Improper Access Control Vu... Fortinet Apr 6, 2026
High CVE-2026-3502 ↗ TrueConf Client — TrueConf Client Download of Code Without Integrity Check Vul... TrueConf Apr 2, 2026
High CVE-2026-5281 Explained Google Dawn — Google Dawn Use-After-Free Vulnerability Google Apr 1, 2026
High CVE-2026-3055 Explained Citrix NetScaler — Citrix NetScaler Out-of-Bounds Read Vulnerability Citrix Mar 30, 2026
High CVE-2025-53521 Explained F5 BIG-IP — F5 BIG-IP Stack-Based Buffer Overflow Vulnerability F5 Mar 27, 2026
High CVE-2026-33634 ↗ Aquasecurity Trivy — Aquasecurity Trivy Embedded Malicious Code Vulnerability Aquasecurity Mar 26, 2026
High CVE-2026-33017 ↗ Langflow Langflow — Langflow Code Injection Vulnerability Langflow Mar 25, 2026
High CVE-2025-31277 ↗ Apple Multiple Products — Apple Multiple Products Buffer Overflow Vulnerabilit... Apple Mar 20, 2026
High CVE-2025-43520 ↗ Apple Multiple Products — Apple Multiple Products Classic Buffer Overflow Vuln... Apple Mar 20, 2026
High CVE-2025-43510 Explained Apple Multiple Products — Apple Multiple Products Improper Locking Vulnerabili... Apple Mar 20, 2026
High CVE-2025-54068 ↗ Laravel Livewire — Laravel Livewire Code Injection Vulnerability Laravel Mar 20, 2026
High CVE-2025-32432 ↗ Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability Craft CMS Mar 20, 2026
Critical CVE-2026-20131 Explained Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Manageme... Cisco Mar 19, 2026
High CVE-2026-20963 ↗ Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... Microsoft Mar 18, 2026
High CVE-2025-66376 ↗ Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... Synacor Mar 18, 2026
High CVE-2025-47813 ↗ Wing FTP Server Wing FTP Server — Wing FTP Server Information Disclosure Vulne... Wing FTP Server Mar 16, 2026
High CVE-2026-3909 ↗ Google Skia — Google Skia Out-of-Bounds Write Vulnerability Google Mar 13, 2026
High CVE-2026-3910 ↗ Google Chromium V8 — Google Chromium V8 Improper Restriction of Operations Wit... Google Mar 13, 2026
High CVE-2025-68613 Explained n8n n8n — n8n Improper Control of Dynamically-Managed Code Resources Vulnerabi... n8n Mar 11, 2026
High CVE-2026-1603 ↗ Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) Authentication B... Ivanti Mar 9, 2026
Critical CVE-2025-26399 Explained SolarWinds Web Help Desk — SolarWinds Web Help Desk Deserialization of Untrust... SolarWinds Mar 9, 2026
High CVE-2021-22054 ↗ Omnissa Workspace One UEM — Omnissa Workspace ONE Server-Side Request Forgery Omnissa Mar 9, 2026
High CVE-2023-41974 ↗ Apple iOS and iPadOS — Apple iOS and iPadOS Use-After-Free Vulnerability Apple Mar 5, 2026
High CVE-2021-30952 Explained Apple Multiple Products — Apple Multiple Products Integer Overflow or Wraparou... Apple Mar 5, 2026
High CVE-2023-43000 ↗ Apple Multiple Products — Apple Multiple products Use-After-Free Vulnerability Apple Mar 5, 2026
High CVE-2021-22681 ↗ Rockwell Multiple Products — Rockwell Multiple Products Insufficient Protected... Rockwell Mar 5, 2026
High CVE-2017-7921 ↗ Hikvision Multiple Products — Hikvision Multiple Products Improper Authenticat... Hikvision Mar 5, 2026
High CVE-2026-21385 ↗ Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Memory Corruption Vuln... Qualcomm Mar 3, 2026
High CVE-2026-22719 ↗ Broadcom VMware Aria Operations — Broadcom VMware Aria Operations Command Inje... Broadcom Mar 3, 2026
High CVE-2026-20127 ↗ Cisco Catalyst SD-WAN Controller and Manager — Cisco Catalyst SD-WAN Controlle... Cisco Feb 25, 2026
High CVE-2022-20775 ↗ Cisco SD-WAN — Cisco SD-WAN Path Traversal Vulnerability Cisco Feb 25, 2026
High CVE-2026-25108 ↗ Soliton Systems K.K FileZen — Soliton Systems K.K FileZen OS Command Injection... Soliton Systems K.K Feb 24, 2026
High CVE-2025-68461 ↗ Roundcube Webmail — RoundCube Webmail Cross-site Scripting Vulnerability Roundcube Feb 20, 2026
High CVE-2025-49113 ↗ Roundcube Webmail — RoundCube Webmail Deserialization of Untrusted Data Vulner... Roundcube Feb 20, 2026
High CVE-2026-22769 ↗ Dell RecoverPoint for Virtual Machines (RP4VMs) — Dell RecoverPoint for Virtua... Dell Feb 18, 2026
High CVE-2021-22175 ↗ GitLab GitLab — GitLab Server-Side Request Forgery (SSRF) Vulnerability GitLab Feb 18, 2026
High CVE-2026-2441 ↗ Google Chromium — Google Chromium CSS Use-After-Free Vulnerability Google Feb 17, 2026

Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.

Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.