Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2020-24363 ↗ | TP-Link TL-WA855RE — TP-link TL-WA855RE Missing Authentication for Critical Fu... | TP-Link | Sep 2, 2025 |
| High | CVE-2025-57819 ↗ | Sangoma FreePBX — Sangoma FreePBX Authentication Bypass Vulnerability | Sangoma | Aug 29, 2025 |
| High | CVE-2025-7775 ↗ | Citrix NetScaler — Citrix NetScaler Memory Overflow Vulnerability | Citrix | Aug 26, 2025 |
| High | CVE-2024-8069 ↗ | Citrix Session Recording — Citrix Session Recording Deserialization of Untrust... | Citrix | Aug 25, 2025 |
| High | CVE-2024-8068 ↗ | Citrix Session Recording — Citrix Session Recording Improper Privilege Managem... | Citrix | Aug 25, 2025 |
| High | CVE-2025-48384 ↗ | Git Git — Git Link Following Vulnerability | Git | Aug 25, 2025 |
| High | CVE-2025-43300 ↗ | Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Out-of-Bounds Writ... | Apple | Aug 21, 2025 |
| High | CVE-2025-54948 ↗ | Trend Micro Apex One — Trend Micro Apex One OS Command Injection Vulnerability | Trend Micro | Aug 18, 2025 |
| High | CVE-2025-8875 ↗ | N-able N-Central — N-able N-Central Insecure Deserialization Vulnerability | N-able | Aug 13, 2025 |
| High | CVE-2025-8876 ↗ | N-able N-Central — N-able N-Central Command Injection Vulnerability | N-able | Aug 13, 2025 |
| High | CVE-2013-3893 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Resource Management... | Microsoft | Aug 12, 2025 |
| High | CVE-2007-0671 ↗ | Microsoft Office — Microsoft Office Excel Remote Code Execution Vulnerability | Microsoft | Aug 12, 2025 |
| High | CVE-2025-8088 ↗ | RARLAB WinRAR — RARLAB WinRAR Path Traversal Vulnerability | RARLAB | Aug 12, 2025 |
| High | CVE-2022-40799 ↗ | D-Link DNR-322L — D-Link DNR-322L Download of Code Without Integrity Check Vul... | D-Link | Aug 5, 2025 |
| High | CVE-2020-25079 ↗ | D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L Comman... | D-Link | Aug 5, 2025 |
| High | CVE-2020-25078 ↗ | D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L Device... | D-Link | Aug 5, 2025 |
| High | CVE-2025-20281 ↗ | Cisco Identity Services Engine — Cisco Identity Services Engine Injection Vuln... | Cisco | Jul 28, 2025 |
| High | CVE-2025-20337 ↗ | Cisco Identity Services Engine — Cisco Identity Services Engine Injection Vuln... | Cisco | Jul 28, 2025 |
| High | CVE-2023-2533 ↗ | PaperCut NG/MF — PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerabilit... | PaperCut | Jul 28, 2025 |
| Critical | CVE-2025-49706 ↗ | Microsoft SharePoint — Microsoft SharePoint Improper Authentication Vulnerabil... | Microsoft | Jul 22, 2025 |
| Critical | CVE-2025-49704 ↗ | Microsoft SharePoint — Microsoft SharePoint Code Injection Vulnerability | Microsoft | Jul 22, 2025 |
| High | CVE-2025-54309 ↗ | CrushFTP CrushFTP — CrushFTP Unprotected Alternate Channel Vulnerability | CrushFTP | Jul 22, 2025 |
| High | CVE-2025-6558 ↗ | Google Chromium — Google Chromium ANGLE and GPU Improper Input Validation Vuln... | Jul 22, 2025 | |
| High | CVE-2025-2776 ↗ | SysAid SysAid On-Prem — SysAid On-Prem Improper Restriction of XML External En... | SysAid | Jul 22, 2025 |
| High | CVE-2025-2775 ↗ | SysAid SysAid On-Prem — SysAid On-Prem Improper Restriction of XML External En... | SysAid | Jul 22, 2025 |
| Critical | CVE-2025-53770 ↗ | Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data... | Microsoft | Jul 20, 2025 |
| High | CVE-2025-25257 ↗ | Fortinet FortiWeb — Fortinet FortiWeb SQL Injection Vulnerability | Fortinet | Jul 18, 2025 |
| High | CVE-2025-47812 ↗ | Wing FTP Server Wing FTP Server — Wing FTP Server Improper Neutralization of N... | Wing FTP Server | Jul 14, 2025 |
| Critical | CVE-2025-5777 ↗ | Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway Out-of-Bou... | Citrix | Jul 10, 2025 |
| High | CVE-2014-3931 ↗ | Looking Glass Multi-Router Looking Glass (MRLG) — Multi-Router Looking Glass (... | Looking Glass | Jul 7, 2025 |
| High | CVE-2016-10033 ↗ | PHP PHPMailer — PHPMailer Command Injection Vulnerability | PHP | Jul 7, 2025 |
| High | CVE-2019-5418 ↗ | Rails Ruby on Rails — Rails Ruby on Rails Path Traversal Vulnerability | Rails | Jul 7, 2025 |
| High | CVE-2019-9621 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Jul 7, 2025 |
| High | CVE-2025-6554 ↗ | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | Jul 2, 2025 | |
| High | CVE-2025-48927 ↗ | TeleMessage TM SGNL — TeleMessage TM SGNL Initialization of a Resource with an... | TeleMessage | Jul 1, 2025 |
| High | CVE-2025-48928 ↗ | TeleMessage TM SGNL — TeleMessage TM SGNL Exposure of Core Dump File to an Una... | TeleMessage | Jul 1, 2025 |
| High | CVE-2025-6543 ↗ | Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway Buffer Ove... | Citrix | Jun 30, 2025 |
| High | CVE-2024-54085 ↗ | AMI MegaRAC SPx — AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerabil... | AMI | Jun 25, 2025 |
| High | CVE-2024-0769 ↗ | D-Link DIR-859 Router — D-Link DIR-859 Router Path Traversal Vulnerability | D-Link | Jun 25, 2025 |
| Critical | CVE-2019-6693 ↗ | Fortinet FortiOS — Fortinet FortiOS Use of Hard-Coded Credentials Vulnerabilit... | Fortinet | Jun 25, 2025 |
| High | CVE-2023-0386 ↗ | Linux Kernel — Linux Kernel Improper Ownership Management Vulnerability | Linux | Jun 17, 2025 |
| High | CVE-2025-43200 ↗ | Apple Multiple Products — Apple Multiple Products Unspecified Vulnerability | Apple | Jun 16, 2025 |
| High | CVE-2023-33538 ↗ | TP-Link Multiple Routers — TP-Link Multiple Routers Command Injection Vulnerab... | TP-Link | Jun 16, 2025 |
| High | CVE-2025-24016 ↗ | Wazuh Wazuh Server — Wazuh Server Deserialization of Untrusted Data Vulnerabil... | Wazuh | Jun 10, 2025 |
| High | CVE-2025-33053 ↗ | Microsoft Windows — Microsoft Windows External Control of File Name or Path V... | Microsoft | Jun 10, 2025 |
| High | CVE-2025-32433 ↗ | Erlang Erlang/OTP — Erlang Erlang/OTP SSH Server Missing Authentication for Cr... | Erlang | Jun 9, 2025 |
| High | CVE-2024-42009 ↗ | Roundcube Webmail — RoundCube Webmail Cross-Site Scripting Vulnerability | Roundcube | Jun 9, 2025 |
| High | CVE-2025-5419 ↗ | Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerabi... | Jun 5, 2025 | |
| High | CVE-2025-27038 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnera... | Qualcomm | Jun 3, 2025 |
| High | CVE-2025-21480 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorizatio... | Qualcomm | Jun 3, 2025 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.