Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2025-1316 ↗ | Edimax IC-7100 IP Camera — Edimax IC-7100 IP Camera OS Command Injection Vulne... | Edimax | Mar 19, 2025 |
| High | CVE-2024-48248 ↗ | NAKIVO Backup and Replication — NAKIVO Backup and Replication Absolute Path Tr... | NAKIVO | Mar 19, 2025 |
| High | CVE-2017-12637 ↗ | SAP NetWeaver — SAP NetWeaver Directory Traversal Vulnerability | SAP | Mar 19, 2025 |
| Critical | CVE-2025-24472 ↗ | Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy Authenticati... | Fortinet | Mar 18, 2025 |
| High | CVE-2025-30066 ↗ | tj-actions changed-files GitHub Action — tj-actions/changed-files GitHub Actio... | tj-actions | Mar 18, 2025 |
| High | CVE-2025-24201 ↗ | Apple Multiple Products — Apple Multiple Products WebKit Out-of-Bounds Write V... | Apple | Mar 13, 2025 |
| High | CVE-2025-21590 ↗ | Juniper Junos OS — Juniper Junos OS Improper Isolation or Compartmentalization... | Juniper | Mar 13, 2025 |
| Critical | CVE-2025-26633 ↗ | Microsoft Windows — Microsoft Windows Management Console (MMC) Improper Neutra... | Microsoft | Mar 11, 2025 |
| High | CVE-2025-24983 ↗ | Microsoft Windows — Microsoft Windows Win32k Use-After-Free Vulnerability | Microsoft | Mar 11, 2025 |
| High | CVE-2025-24984 ↗ | Microsoft Windows — Microsoft Windows NTFS Information Disclosure Vulnerabilit... | Microsoft | Mar 11, 2025 |
| High | CVE-2025-24985 ↗ | Microsoft Windows — Microsoft Windows Fast FAT File System Driver Integer Over... | Microsoft | Mar 11, 2025 |
| High | CVE-2025-24991 ↗ | Microsoft Windows — Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability | Microsoft | Mar 11, 2025 |
| High | CVE-2025-24993 ↗ | Microsoft Windows — Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerab... | Microsoft | Mar 11, 2025 |
| High | CVE-2025-25181 ↗ | Advantive VeraCore — Advantive VeraCore SQL Injection Vulnerability | Advantive | Mar 10, 2025 |
| High | CVE-2024-57968 ↗ | Advantive VeraCore — Advantive VeraCore Unrestricted File Upload Vulnerability | Advantive | Mar 10, 2025 |
| High | CVE-2024-13159 ↗ | Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) Absolute Path Tr... | Ivanti | Mar 10, 2025 |
| High | CVE-2024-13160 ↗ | Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) Absolute Path Tr... | Ivanti | Mar 10, 2025 |
| High | CVE-2024-13161 ↗ | Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) Absolute Path Tr... | Ivanti | Mar 10, 2025 |
| High | CVE-2024-50302 ↗ | Linux Kernel — Linux Kernel Use of Uninitialized Resource Vulnerability | Linux | Mar 4, 2025 |
| High | CVE-2025-22224 ↗ | VMware ESXi and Workstation — VMware ESXi and Workstation TOCTOU Race Conditio... | VMware | Mar 4, 2025 |
| Critical | CVE-2025-22225 ↗ | VMware ESXi — VMware ESXi Arbitrary Write Vulnerability | VMware | Mar 4, 2025 |
| High | CVE-2025-22226 ↗ | VMware ESXi, Workstation, and Fusion — VMware ESXi, Workstation, and Fusion In... | VMware | Mar 4, 2025 |
| High | CVE-2023-20118 ↗ | Cisco Small Business RV Series Routers — Cisco Small Business RV Series Router... | Cisco | Mar 3, 2025 |
| High | CVE-2022-43939 ↗ | Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Penta... | Hitachi Vantara | Mar 3, 2025 |
| High | CVE-2022-43769 ↗ | Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Penta... | Hitachi Vantara | Mar 3, 2025 |
| Critical | CVE-2018-8639 ↗ | Microsoft Windows — Microsoft Windows Win32k Improper Resource Shutdown or Rel... | Microsoft | Mar 3, 2025 |
| High | CVE-2024-4885 ↗ | Progress WhatsUp Gold — Progress WhatsUp Gold Path Traversal Vulnerability | Progress | Mar 3, 2025 |
| High | CVE-2024-49035 ↗ | Microsoft Partner Center — Microsoft Partner Center Improper Access Control Vu... | Microsoft | Feb 25, 2025 |
| High | CVE-2023-34192 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | Feb 25, 2025 |
| High | CVE-2017-3066 ↗ | Adobe ColdFusion — Adobe ColdFusion Deserialization Vulnerability | Adobe | Feb 24, 2025 |
| High | CVE-2024-20953 ↗ | Oracle Agile Product Lifecycle Management (PLM) — Oracle Agile Product Lifecyc... | Oracle | Feb 24, 2025 |
| High | CVE-2025-24989 ↗ | Microsoft Power Pages — Microsoft Power Pages Improper Access Control Vulnerab... | Microsoft | Feb 21, 2025 |
| High | CVE-2025-23209 ↗ | Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability | Craft CMS | Feb 20, 2025 |
| High | CVE-2025-0111 ↗ | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS File Read Vulnerability | Palo Alto Networks | Feb 20, 2025 |
| Critical | CVE-2024-53704 ↗ | SonicWall SonicOS — SonicWall SonicOS SSLVPN Improper Authentication Vulnerabi... | SonicWall | Feb 18, 2025 |
| High | CVE-2025-0108 ↗ | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vu... | Palo Alto Networks | Feb 18, 2025 |
| Critical | CVE-2024-57727 ↗ | SimpleHelp SimpleHelp — SimpleHelp Path Traversal Vulnerability | SimpleHelp | Feb 13, 2025 |
| High | CVE-2024-41710 ↗ | Mitel SIP Phones — Mitel SIP Phones Argument Injection Vulnerability | Mitel | Feb 12, 2025 |
| High | CVE-2025-24200 ↗ | Apple iOS and iPadOS — Apple iOS and iPadOS Incorrect Authorization Vulnerabil... | Apple | Feb 12, 2025 |
| High | CVE-2025-21391 ↗ | Microsoft Windows — Microsoft Windows Storage Link Following Vulnerability | Microsoft | Feb 11, 2025 |
| High | CVE-2025-21418 ↗ | Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock He... | Microsoft | Feb 11, 2025 |
| High | CVE-2024-40890 ↗ | Zyxel DSL CPE Devices — Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | Feb 11, 2025 |
| High | CVE-2024-40891 ↗ | Zyxel DSL CPE Devices — Zyxel DSL CPE OS Command Injection Vulnerability | Zyxel | Feb 11, 2025 |
| High | CVE-2025-0994 ↗ | Trimble Cityworks — Trimble Cityworks Deserialization Vulnerability | Trimble | Feb 7, 2025 |
| High | CVE-2025-0411 ↗ | 7-Zip 7-Zip — 7-Zip Mark of the Web Bypass Vulnerability | 7-Zip | Feb 6, 2025 |
| High | CVE-2022-23748 ↗ | Audinate Dante Discovery — Dante Discovery Process Control Vulnerability | Audinate | Feb 6, 2025 |
| High | CVE-2024-21413 ↗ | Microsoft Office Outlook — Microsoft Outlook Improper Input Validation Vulnera... | Microsoft | Feb 6, 2025 |
| High | CVE-2020-29574 ↗ | Sophos CyberoamOS — CyberoamOS (CROS) SQL Injection Vulnerability | Sophos | Feb 6, 2025 |
| High | CVE-2020-15069 ↗ | Sophos XG Firewall — Sophos XG Firewall Buffer Overflow Vulnerability | Sophos | Feb 6, 2025 |
| High | CVE-2024-53104 ↗ | Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability | Linux | Feb 5, 2025 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.