Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2024-45195 ↗ | Apache OFBiz — Apache OFBiz Forced Browsing Vulnerability | Apache | Feb 4, 2025 |
| High | CVE-2024-29059 ↗ | Microsoft .NET Framework — Microsoft .NET Framework Information Disclosure Vul... | Microsoft | Feb 4, 2025 |
| High | CVE-2018-9276 ↗ | Paessler PRTG Network Monitor — Paessler PRTG Network Monitor OS Command Injec... | Paessler | Feb 4, 2025 |
| High | CVE-2018-19410 ↗ | Paessler PRTG Network Monitor — Paessler PRTG Network Monitor Local File Inclu... | Paessler | Feb 4, 2025 |
| High | CVE-2025-24085 ↗ | Apple Multiple Products — Apple Multiple Products Use-After-Free Vulnerability | Apple | Jan 29, 2025 |
| Critical | CVE-2025-23006 ↗ | SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Deserialization Vu... | SonicWall | Jan 24, 2025 |
| High | CVE-2020-11023 ↗ | JQuery JQuery — JQuery Cross-Site Scripting (XSS) Vulnerability | JQuery | Jan 23, 2025 |
| High | CVE-2024-50603 ↗ | Aviatrix Controllers — Aviatrix Controllers OS Command Injection Vulnerability | Aviatrix | Jan 16, 2025 |
| Critical | CVE-2024-55591 ↗ | Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy Authenticati... | Fortinet | Jan 14, 2025 |
| High | CVE-2025-21333 ↗ | Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-b... | Microsoft | Jan 14, 2025 |
| High | CVE-2025-21334 ↗ | Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-Af... | Microsoft | Jan 14, 2025 |
| High | CVE-2025-21335 ↗ | Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-Af... | Microsoft | Jan 14, 2025 |
| High | CVE-2024-12686 ↗ | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) — BeyondTru... | BeyondTrust | Jan 13, 2025 |
| Critical | CVE-2023-48365 ↗ | Qlik Sense — Qlik Sense HTTP Tunneling Vulnerability | Qlik | Jan 13, 2025 |
| Critical | CVE-2025-0282 ↗ | Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure... | Ivanti | Jan 8, 2025 |
| Critical | CVE-2024-41713 ↗ | Mitel MiCollab — Mitel MiCollab Path Traversal Vulnerability | Mitel | Jan 7, 2025 |
| Critical | CVE-2024-55550 ↗ | Mitel MiCollab — Mitel MiCollab Path Traversal Vulnerability | Mitel | Jan 7, 2025 |
| High | CVE-2020-2883 ↗ | Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability | Oracle | Jan 7, 2025 |
| High | CVE-2024-3393 ↗ | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Malicious DNS Packet Vul... | Palo Alto Networks | Dec 30, 2024 |
| High | CVE-2021-44207 ↗ | Acclaim Systems USAHERDS — Acclaim Systems USAHERDS Use of Hard-Coded Credenti... | Acclaim Systems | Dec 23, 2024 |
| High | CVE-2024-12356 ↗ | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) — BeyondTru... | BeyondTrust | Dec 19, 2024 |
| High | CVE-2018-14933 ↗ | NUUO NVRmini Devices — NUUO NVRmini Devices OS Command Injection Vulnerability... | NUUO | Dec 18, 2024 |
| High | CVE-2022-23227 ↗ | NUUO NVRmini2 Devices — NUUO NVRmini2 Devices Missing Authentication Vulnerabi... | NUUO | Dec 18, 2024 |
| High | CVE-2019-11001 ↗ | Reolink Multiple IP Cameras — Reolink Multiple IP Cameras OS Command Injection... | Reolink | Dec 18, 2024 |
| High | CVE-2021-40407 ↗ | Reolink RLC-410W IP Camera — Reolink RLC-410W IP Camera OS Command Injection V... | Reolink | Dec 18, 2024 |
| Critical | CVE-2024-55956 ↗ | Cleo Multiple Products — Cleo Multiple Products Unauthenticated File Upload Vu... | Cleo | Dec 17, 2024 |
| High | CVE-2024-20767 ↗ | Adobe ColdFusion — Adobe ColdFusion Improper Access Control Vulnerability | Adobe | Dec 16, 2024 |
| High | CVE-2024-35250 ↗ | Microsoft Windows — Microsoft Windows Kernel-Mode Driver Untrusted Pointer Der... | Microsoft | Dec 16, 2024 |
| Critical | CVE-2024-50623 ↗ | Cleo Multiple Products — Cleo Multiple Products Unrestricted File Upload Vulne... | Cleo | Dec 13, 2024 |
| High | CVE-2024-49138 ↗ | Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Hea... | Microsoft | Dec 10, 2024 |
| Critical | CVE-2024-51378 ↗ | CyberPersons CyberPanel — CyberPanel Incorrect Default Permissions Vulnerabili... | CyberPersons | Dec 4, 2024 |
| High | CVE-2023-45727 ↗ | North Grid Proself — North Grid Proself Improper Restriction of XML External E... | North Grid | Dec 3, 2024 |
| High | CVE-2024-11680 ↗ | ProjectSend ProjectSend — ProjectSend Improper Authentication Vulnerability | ProjectSend | Dec 3, 2024 |
| Critical | CVE-2024-11667 ↗ | Zyxel Multiple Firewalls — Zyxel Multiple Firewalls Path Traversal Vulnerabili... | Zyxel | Dec 3, 2024 |
| Critical | CVE-2023-28461 ↗ | Array Networks AG/vxAG ArrayOS — Array Networks AG and vxAG ArrayOS Missing Au... | Array Networks | Nov 25, 2024 |
| High | CVE-2024-44308 ↗ | Apple Multiple Products — Apple Multiple Products Code Execution Vulnerability | Apple | Nov 21, 2024 |
| High | CVE-2024-44309 ↗ | Apple Multiple Products — Apple Multiple Products Cross-Site Scripting (XSS) V... | Apple | Nov 21, 2024 |
| High | CVE-2024-21287 ↗ | Oracle Agile Product Lifecycle Management (PLM) — Oracle Agile Product Lifecyc... | Oracle | Nov 21, 2024 |
| High | CVE-2024-38812 ↗ | VMware vCenter Server — VMware vCenter Server Heap-Based Buffer Overflow Vulne... | VMware | Nov 20, 2024 |
| High | CVE-2024-38813 ↗ | VMware vCenter Server — VMware vCenter Server Privilege Escalation Vulnerabili... | VMware | Nov 20, 2024 |
| High | CVE-2024-1212 ↗ | Progress Kemp LoadMaster — Progress Kemp LoadMaster OS Command Injection Vulne... | Progress | Nov 18, 2024 |
| Critical | CVE-2024-0012 ↗ | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Management Interface Aut... | Palo Alto Networks | Nov 18, 2024 |
| Critical | CVE-2024-9474 ↗ | Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Management Interface OS... | Palo Alto Networks | Nov 18, 2024 |
| High | CVE-2024-9463 ↗ | Palo Alto Networks Expedition — Palo Alto Networks Expedition OS Command Injec... | Palo Alto Networks | Nov 14, 2024 |
| High | CVE-2024-9465 ↗ | Palo Alto Networks Expedition — Palo Alto Networks Expedition SQL Injection Vu... | Palo Alto Networks | Nov 14, 2024 |
| Critical | CVE-2024-49039 ↗ | Microsoft Windows — Microsoft Windows Task Scheduler Privilege Escalation Vuln... | Microsoft | Nov 12, 2024 |
| High | CVE-2024-43451 ↗ | Microsoft Windows — Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerab... | Microsoft | Nov 12, 2024 |
| High | CVE-2021-41277 ↗ | Metabase Metabase — Metabase GeoJSON API Local File Inclusion Vulnerability | Metabase | Nov 12, 2024 |
| High | CVE-2014-2120 ↗ | Cisco Adaptive Security Appliance (ASA) — Cisco Adaptive Security Appliance (A... | Cisco | Nov 12, 2024 |
| High | CVE-2021-26086 ↗ | Atlassian Jira Server and Data Center — Atlassian Jira Server and Data Center... | Atlassian | Nov 12, 2024 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.