Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2025-12480 ↗ | Gladinet Triofox — Gladinet Triofox Improper Access Control Vulnerability | Gladinet | Nov 12, 2025 |
| High | CVE-2025-21042 ↗ | Samsung Mobile Devices — Samsung Mobile Devices Out-of-Bounds Write Vulnerabil... | Samsung | Nov 10, 2025 |
| High | CVE-2025-11371 ↗ | Gladinet CentreStack and Triofox — Gladinet CentreStack and Triofox Files or D... | Gladinet | Nov 4, 2025 |
| High | CVE-2025-48703 ↗ | CWP Control Web Panel — CWP Control Web Panel OS Command Injection Vulnerabili... | CWP | Nov 4, 2025 |
| High | CVE-2025-24893 ↗ | XWiki Platform — XWiki Platform Eval Injection Vulnerability | XWiki | Oct 30, 2025 |
| High | CVE-2025-41244 ↗ | Broadcom VMware Aria Operations and VMware Tools — Broadcom VMware Aria Operat... | Broadcom | Oct 30, 2025 |
| High | CVE-2025-6205 ↗ | Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Missing Auth... | Dassault Systèmes | Oct 28, 2025 |
| High | CVE-2025-6204 ↗ | Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Code Injecti... | Dassault Systèmes | Oct 28, 2025 |
| High | CVE-2025-59287 ↗ | Microsoft Windows — Microsoft Windows Server Update Service (WSUS) Deserializa... | Microsoft | Oct 24, 2025 |
| High | CVE-2025-54236 ↗ | Adobe Commerce and Magento — Adobe Commerce and Magento Improper Input Validat... | Adobe | Oct 24, 2025 |
| High | CVE-2025-61932 ↗ | Motex LANSCOPE Endpoint Manager — Motex LANSCOPE Endpoint Manager Improper Ver... | Motex | Oct 22, 2025 |
| Critical | CVE-2025-61884 ↗ | Oracle E-Business Suite — Oracle E-Business Suite Server-Side Request Forgery... | Oracle | Oct 20, 2025 |
| High | CVE-2025-33073 ↗ | Microsoft Windows — Microsoft Windows SMB Client Improper Access Control Vulne... | Microsoft | Oct 20, 2025 |
| High | CVE-2025-2747 ↗ | Kentico Xperience CMS — Kentico Xperience CMS Authentication Bypass Using an A... | Kentico | Oct 20, 2025 |
| High | CVE-2025-2746 ↗ | Kentico Xperience CMS — Kentico Xperience CMS Authentication Bypass Using an A... | Kentico | Oct 20, 2025 |
| High | CVE-2022-48503 ↗ | Apple Multiple Products — Apple Multiple Products Unspecified Vulnerability | Apple | Oct 20, 2025 |
| High | CVE-2025-54253 ↗ | Adobe Experience Manager (AEM) Forms — Adobe Experience Manager Forms Code Exe... | Adobe | Oct 15, 2025 |
| High | CVE-2016-7836 ↗ | SKYSEA Client View — SKYSEA Client View Improper Authentication Vulnerability | SKYSEA | Oct 14, 2025 |
| High | CVE-2025-59230 ↗ | Microsoft Windows — Microsoft Windows Improper Access Control Vulnerability | Microsoft | Oct 14, 2025 |
| High | CVE-2025-24990 ↗ | Microsoft Windows — Microsoft Windows Untrusted Pointer Dereference Vulnerabil... | Microsoft | Oct 14, 2025 |
| High | CVE-2025-47827 ↗ | IGEL IGEL OS — IGEL OS Use of a Key Past its Expiration Date Vulnerability | IGEL | Oct 14, 2025 |
| High | CVE-2021-43798 ↗ | Grafana Labs Grafana — Grafana Path Traversal Vulnerability | Grafana Labs | Oct 9, 2025 |
| High | CVE-2025-27915 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Oct 7, 2025 |
| Critical | CVE-2025-61882 ↗ | Oracle E-Business Suite — Oracle E-Business Suite Unspecified Vulnerability | Oracle | Oct 6, 2025 |
| High | CVE-2010-3765 ↗ | Mozilla Multiple Products — Mozilla Multiple Products Remote Code Execution Vu... | Mozilla | Oct 6, 2025 |
| High | CVE-2011-3402 ↗ | Microsoft Windows — Microsoft Windows Remote Code Execution Vulnerability | Microsoft | Oct 6, 2025 |
| High | CVE-2013-3918 ↗ | Microsoft Windows — Microsoft Windows Out-of-Bounds Write Vulnerability | Microsoft | Oct 6, 2025 |
| High | CVE-2021-43226 ↗ | Microsoft Windows — Microsoft Windows Privilege Escalation Vulnerability | Microsoft | Oct 6, 2025 |
| High | CVE-2010-3962 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Uninitialized Memory... | Microsoft | Oct 6, 2025 |
| High | CVE-2021-22555 ↗ | Linux Kernel — Linux Kernel Heap Out-of-Bounds Write Vulnerability | Linux | Oct 6, 2025 |
| High | CVE-2025-4008 ↗ | Smartbedded Meteobridge — Smartbedded Meteobridge Command Injection Vulnerabil... | Smartbedded | Oct 2, 2025 |
| High | CVE-2025-21043 ↗ | Samsung Mobile Devices — Samsung Mobile Devices Out-of-Bounds Write Vulnerabil... | Samsung | Oct 2, 2025 |
| High | CVE-2015-7755 ↗ | Juniper ScreenOS — Juniper ScreenOS Improper Authentication Vulnerability | Juniper | Oct 2, 2025 |
| High | CVE-2017-1000353 ↗ | Jenkins Jenkins — Jenkins Remote Code Execution Vulnerability | Jenkins | Oct 2, 2025 |
| High | CVE-2014-6278 ↗ | GNU GNU Bash — GNU Bash OS Command Injection Vulnerability | GNU | Oct 2, 2025 |
| High | CVE-2021-21311 ↗ | Adminer Adminer — Adminer Server-Side Request Forgery Vulnerability | Adminer | Sep 29, 2025 |
| High | CVE-2025-20352 ↗ | Cisco IOS and IOS XE — Cisco IOS and IOS XE Software SNMP Denial of Service an... | Cisco | Sep 29, 2025 |
| Critical | CVE-2025-10035 ↗ | Fortra GoAnywhere MFT — Fortra GoAnywhere MFT Deserialization of Untrusted Dat... | Fortra | Sep 29, 2025 |
| High | CVE-2025-59689 ↗ | Libraesva Email Security Gateway — Libraesva Email Security Gateway Command In... | Libraesva | Sep 29, 2025 |
| High | CVE-2025-32463 ↗ | Sudo Sudo — Sudo Inclusion of Functionality from Untrusted Control Sphere Vuln... | Sudo | Sep 29, 2025 |
| High | CVE-2025-20333 ↗ | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat D... | Cisco | Sep 25, 2025 |
| High | CVE-2025-20362 ↗ | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat D... | Cisco | Sep 25, 2025 |
| High | CVE-2025-10585 ↗ | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | Sep 23, 2025 | |
| High | CVE-2025-5086 ↗ | Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Deserializat... | Dassault Systèmes | Sep 11, 2025 |
| High | CVE-2025-53690 ↗ | Sitecore Multiple Products — Sitecore Multiple Products Deserialization of Unt... | Sitecore | Sep 4, 2025 |
| High | CVE-2025-48543 ↗ | Android Runtime — Android Runtime Use-After-Free Vulnerability | Android | Sep 4, 2025 |
| High | CVE-2025-38352 ↗ | Linux Kernel — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition... | Linux | Sep 4, 2025 |
| High | CVE-2025-9377 ↗ | TP-Link Multiple Routers — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Comma... | TP-Link | Sep 3, 2025 |
| High | CVE-2023-50224 ↗ | TP-Link TL-WR841N — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulner... | TP-Link | Sep 3, 2025 |
| High | CVE-2025-55177 ↗ | Meta Platforms WhatsApp — Meta Platforms WhatsApp Incorrect Authorization Vuln... | Meta Platforms | Sep 2, 2025 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.