Browse all

Known Exploited Vulnerabilities (CISA KEV) — all

The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.

Clear

1,657 results

UrgencyCVEName / productVendorKEV added
High CVE-2025-21479 ↗ Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorizatio... Qualcomm Jun 3, 2025
High CVE-2023-39780 ↗ ASUS RT-AX55 Routers — ASUS RT-AX55 Routers OS Command Injection Vulnerability ASUS Jun 2, 2025
High CVE-2024-56145 ↗ Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability Craft CMS Jun 2, 2025
High CVE-2025-35939 ↗ Craft CMS Craft CMS — Craft CMS External Control of Assumed-Immutable Web Para... Craft CMS Jun 2, 2025
High CVE-2025-3935 ↗ ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Authentication... ConnectWise Jun 2, 2025
High CVE-2021-32030 ↗ ASUS Routers — ASUS Routers Improper Authentication Vulnerability ASUS Jun 2, 2025
High CVE-2025-4632 ↗ Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server Path Traversal Vulnera... Samsung May 22, 2025
High CVE-2025-4427 ↗ Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... Ivanti May 19, 2025
High CVE-2025-4428 ↗ Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... Ivanti May 19, 2025
High CVE-2024-11182 ↗ MDaemon Email Server — MDaemon Email Server Cross-Site Scripting (XSS) Vulnera... MDaemon May 19, 2025
High CVE-2025-27920 ↗ Srimax Output Messenger — Srimax Output Messenger Directory Traversal Vulnerab... Srimax May 19, 2025
High CVE-2024-27443 ↗ Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... Synacor May 19, 2025
High CVE-2023-38950 ↗ ZKTeco BioTime — ZKTeco BioTime Path Traversal Vulnerability ZKTeco May 19, 2025
High CVE-2024-12987 ↗ DrayTek Vigor Routers — DrayTek Vigor Routers OS Command Injection Vulnerabili... DrayTek May 15, 2025
High CVE-2025-42999 ↗ SAP NetWeaver — SAP NetWeaver Deserialization Vulnerability SAP May 15, 2025
High CVE-2025-32756 ↗ Fortinet Multiple Products — Fortinet Multiple Products Stack-Based Buffer Ove... Fortinet May 14, 2025
High CVE-2025-30400 ↗ Microsoft Windows — Microsoft Windows DWM Core Library Use-After-Free Vulnerab... Microsoft May 13, 2025
High CVE-2025-32701 ↗ Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Use... Microsoft May 13, 2025
High CVE-2025-32706 ↗ Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Hea... Microsoft May 13, 2025
High CVE-2025-30397 ↗ Microsoft Windows — Microsoft Windows Scripting Engine Type Confusion Vulnerab... Microsoft May 13, 2025
High CVE-2025-32709 ↗ Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock Us... Microsoft May 13, 2025
High CVE-2025-47729 ↗ TeleMessage TM SGNL — TeleMessage TM SGNL Hidden Functionality Vulnerability TeleMessage May 12, 2025
High CVE-2024-6047 ↗ GeoVision Multiple Devices — GeoVision Devices OS Command Injection Vulnerabil... GeoVision May 7, 2025
High CVE-2024-11120 ↗ GeoVision Multiple Devices — GeoVision Devices OS Command Injection Vulnerabil... GeoVision May 7, 2025
High CVE-2025-27363 ↗ FreeType FreeType — FreeType Out-of-Bounds Write Vulnerability FreeType May 6, 2025
Critical CVE-2025-3248 ↗ Langflow Langflow — Langflow Missing Authentication Vulnerability Langflow May 5, 2025
High CVE-2024-58136 ↗ Yiiframework Yii — Yiiframework Yii Improper Protection of Alternate Path Vuln... Yiiframework May 2, 2025
High CVE-2025-34028 ↗ Commvault Command Center — Commvault Command Center Path Traversal Vulnerabili... Commvault May 2, 2025
High CVE-2023-44221 ↗ SonicWall SMA100 Appliances — SonicWall SMA100 Appliances OS Command Injection... SonicWall May 1, 2025
High CVE-2024-38475 ↗ Apache HTTP Server — Apache HTTP Server Improper Escaping of Output Vulnerabil... Apache May 1, 2025
Critical CVE-2025-31324 ↗ SAP NetWeaver — SAP NetWeaver Unrestricted File Upload Vulnerability SAP Apr 29, 2025
High CVE-2025-3928 ↗ Commvault Web Server — Commvault Web Server Unspecified Vulnerability Commvault Apr 28, 2025
High CVE-2025-42599 ↗ Qualitia Active! Mail — Qualitia Active! Mail Stack-Based Buffer Overflow Vuln... Qualitia Apr 28, 2025
High CVE-2025-1976 ↗ Broadcom Brocade Fabric OS — Broadcom Brocade Fabric OS Code Injection Vulnera... Broadcom Apr 28, 2025
High CVE-2025-31200 ↗ Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerabil... Apple Apr 17, 2025
High CVE-2025-31201 ↗ Apple Multiple Products — Apple Multiple Products Arbitrary Read and Write Vul... Apple Apr 17, 2025
High CVE-2025-24054 ↗ Microsoft Windows — Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerabil... Microsoft Apr 17, 2025
High CVE-2021-20035 ↗ SonicWall SMA100 Appliances — SonicWall SMA100 Appliances OS Command Injection... SonicWall Apr 16, 2025
High CVE-2024-53197 ↗ Linux Kernel — Linux Kernel Out-of-Bounds Access Vulnerability Linux Apr 9, 2025
High CVE-2024-53150 ↗ Linux Kernel — Linux Kernel Out-of-Bounds Read Vulnerability Linux Apr 9, 2025
High CVE-2025-30406 ↗ Gladinet CentreStack — Gladinet CentreStack and Triofox Use of Hard-coded Cryp... Gladinet Apr 8, 2025
Critical CVE-2025-29824 ↗ Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Use... Microsoft Apr 8, 2025
Critical CVE-2025-31161 ↗ CrushFTP CrushFTP — CrushFTP Authentication Bypass Vulnerability CrushFTP Apr 7, 2025
Critical CVE-2025-22457 ↗ Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure... Ivanti Apr 4, 2025
High CVE-2025-24813 ↗ Apache Tomcat — Apache Tomcat Path Equivalence Vulnerability Apache Apr 1, 2025
High CVE-2024-20439 ↗ Cisco Smart Licensing Utility — Cisco Smart Licensing Utility Static Credentia... Cisco Mar 31, 2025
High CVE-2025-2783 ↗ Google Chromium Mojo — Google Chromium Mojo Sandbox Escape Vulnerability Google Mar 27, 2025
High CVE-2019-9874 ↗ Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platfo... Sitecore Mar 26, 2025
High CVE-2019-9875 ↗ Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platfo... Sitecore Mar 26, 2025
High CVE-2025-30154 ↗ reviewdog action-setup GitHub Action — reviewdog/action-setup GitHub Action Em... reviewdog Mar 24, 2025

Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.

Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.