Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,721 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2025-6543 ↗ | Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway Buffer Ove... | Citrix | Jun 30, 2025 |
| High | CVE-2024-54085 ↗ | AMI MegaRAC SPx — AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerabil... | AMI | Jun 25, 2025 |
| High | CVE-2024-0769 ↗ | D-Link DIR-859 Router — D-Link DIR-859 Router Path Traversal Vulnerability | D-Link | Jun 25, 2025 |
| Critical | CVE-2019-6693 ↗ | Fortinet FortiOS — Fortinet FortiOS Use of Hard-Coded Credentials Vulnerabilit... | Fortinet | Jun 25, 2025 |
| High | CVE-2023-0386 ↗ | Linux Kernel — Linux Kernel Improper Ownership Management Vulnerability | Linux | Jun 17, 2025 |
| High | CVE-2025-43200 ↗ | Apple Multiple Products — Apple Multiple Products Unspecified Vulnerability | Apple | Jun 16, 2025 |
| High | CVE-2023-33538 ↗ | TP-Link Multiple Routers — TP-Link Multiple Routers Command Injection Vulnerab... | TP-Link | Jun 16, 2025 |
| High | CVE-2025-24016 ↗ | Wazuh Wazuh Server — Wazuh Server Deserialization of Untrusted Data Vulnerabil... | Wazuh | Jun 10, 2025 |
| High | CVE-2025-33053 ↗ | Microsoft Windows — Microsoft Windows External Control of File Name or Path V... | Microsoft | Jun 10, 2025 |
| High | CVE-2025-32433 ↗ | Erlang Erlang/OTP — Erlang Erlang/OTP SSH Server Missing Authentication for Cr... | Erlang | Jun 9, 2025 |
| High | CVE-2024-42009 ↗ | Roundcube Webmail — RoundCube Webmail Cross-Site Scripting Vulnerability | Roundcube | Jun 9, 2025 |
| High | CVE-2025-5419 ↗ | Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerabi... | Jun 5, 2025 | |
| High | CVE-2025-27038 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnera... | Qualcomm | Jun 3, 2025 |
| High | CVE-2025-21480 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorizatio... | Qualcomm | Jun 3, 2025 |
| High | CVE-2025-21479 ↗ | Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorizatio... | Qualcomm | Jun 3, 2025 |
| High | CVE-2023-39780 ↗ | ASUS RT-AX55 Routers — ASUS RT-AX55 Routers OS Command Injection Vulnerability | ASUS | Jun 2, 2025 |
| High | CVE-2024-56145 ↗ | Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability | Craft CMS | Jun 2, 2025 |
| High | CVE-2025-35939 ↗ | Craft CMS Craft CMS — Craft CMS External Control of Assumed-Immutable Web Para... | Craft CMS | Jun 2, 2025 |
| High | CVE-2025-3935 ↗ | ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Authentication... | ConnectWise | Jun 2, 2025 |
| High | CVE-2021-32030 ↗ | ASUS Routers — ASUS Routers Improper Authentication Vulnerability | ASUS | Jun 2, 2025 |
| High | CVE-2025-4632 ↗ | Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server Path Traversal Vulnera... | Samsung | May 22, 2025 |
| High | CVE-2025-4427 ↗ | Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... | Ivanti | May 19, 2025 |
| High | CVE-2025-4428 ↗ | Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM)... | Ivanti | May 19, 2025 |
| High | CVE-2024-11182 ↗ | MDaemon Email Server — MDaemon Email Server Cross-Site Scripting (XSS) Vulnera... | MDaemon | May 19, 2025 |
| High | CVE-2025-27920 ↗ | Srimax Output Messenger — Srimax Output Messenger Directory Traversal Vulnerab... | Srimax | May 19, 2025 |
| High | CVE-2024-27443 ↗ | Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite... | Synacor | May 19, 2025 |
| High | CVE-2023-38950 ↗ | ZKTeco BioTime — ZKTeco BioTime Path Traversal Vulnerability | ZKTeco | May 19, 2025 |
| High | CVE-2024-12987 ↗ | DrayTek Vigor Routers — DrayTek Vigor Routers OS Command Injection Vulnerabili... | DrayTek | May 15, 2025 |
| Critical | CVE-2025-42999 ↗ | SAP NetWeaver — SAP NetWeaver Deserialization Vulnerability | SAP | May 15, 2025 |
| High | CVE-2025-32756 ↗ | Fortinet Multiple Products — Fortinet Multiple Products Stack-Based Buffer Ove... | Fortinet | May 14, 2025 |
| High | CVE-2025-30400 ↗ | Microsoft Windows — Microsoft Windows DWM Core Library Use-After-Free Vulnerab... | Microsoft | May 13, 2025 |
| High | CVE-2025-32701 ↗ | Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Use... | Microsoft | May 13, 2025 |
| High | CVE-2025-32706 ↗ | Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Hea... | Microsoft | May 13, 2025 |
| High | CVE-2025-30397 ↗ | Microsoft Windows — Microsoft Windows Scripting Engine Type Confusion Vulnerab... | Microsoft | May 13, 2025 |
| High | CVE-2025-32709 ↗ | Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock Us... | Microsoft | May 13, 2025 |
| High | CVE-2025-47729 ↗ | TeleMessage TM SGNL — TeleMessage TM SGNL Hidden Functionality Vulnerability | TeleMessage | May 12, 2025 |
| High | CVE-2024-6047 ↗ | GeoVision Multiple Devices — GeoVision Devices OS Command Injection Vulnerabil... | GeoVision | May 7, 2025 |
| High | CVE-2024-11120 ↗ | GeoVision Multiple Devices — GeoVision Devices OS Command Injection Vulnerabil... | GeoVision | May 7, 2025 |
| High | CVE-2025-27363 ↗ | FreeType FreeType — FreeType Out-of-Bounds Write Vulnerability | FreeType | May 6, 2025 |
| Critical | CVE-2025-3248 ↗ | Langflow Langflow — Langflow Missing Authentication Vulnerability | Langflow | May 5, 2025 |
| High | CVE-2024-58136 ↗ | Yiiframework Yii — Yiiframework Yii Improper Protection of Alternate Path Vuln... | Yiiframework | May 2, 2025 |
| High | CVE-2025-34028 ↗ | Commvault Command Center — Commvault Command Center Path Traversal Vulnerabili... | Commvault | May 2, 2025 |
| High | CVE-2023-44221 ↗ | SonicWall SMA100 Appliances — SonicWall SMA100 Appliances OS Command Injection... | SonicWall | May 1, 2025 |
| High | CVE-2024-38475 ↗ | Apache HTTP Server — Apache HTTP Server Improper Escaping of Output Vulnerabil... | Apache | May 1, 2025 |
| Critical | CVE-2025-31324 Explained | SAP NetWeaver — SAP NetWeaver Unrestricted File Upload Vulnerability | SAP | Apr 29, 2025 |
| High | CVE-2025-3928 ↗ | Commvault Web Server — Commvault Web Server Unspecified Vulnerability | Commvault | Apr 28, 2025 |
| High | CVE-2025-42599 ↗ | Qualitia Active! Mail — Qualitia Active! Mail Stack-Based Buffer Overflow Vuln... | Qualitia | Apr 28, 2025 |
| High | CVE-2025-1976 ↗ | Broadcom Brocade Fabric OS — Broadcom Brocade Fabric OS Code Injection Vulnera... | Broadcom | Apr 28, 2025 |
| High | CVE-2025-31200 ↗ | Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerabil... | Apple | Apr 17, 2025 |
| High | CVE-2025-31201 ↗ | Apple Multiple Products — Apple Multiple Products Arbitrary Read and Write Vul... | Apple | Apr 17, 2025 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.