Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-0108 | Palo Alto Networks | PAN-OS | 8.8 High | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 2025-02-18 | 2025-03-11 | Unknown |
| CVE-2024-53704 | SonicWall | SonicOS | 9.8 Critical | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | 2025-02-18 | 2025-03-11 | Known |
| CVE-2024-57727 | SimpleHelp | SimpleHelp | 7.5 High | SimpleHelp Path Traversal Vulnerability | 2025-02-13 | 2025-03-06 | Known |
| CVE-2025-24200 | Apple | iOS and iPadOS | 6.1 Medium | Apple iOS and iPadOS Incorrect Authorization Vulnerability | 2025-02-12 | 2025-03-05 | Unknown |
| CVE-2024-41710 | Mitel | SIP Phones | 7.2 High | Mitel SIP Phones Argument Injection Vulnerability | 2025-02-12 | 2025-03-05 | Unknown |
| CVE-2025-21418 | Microsoft | Windows | 7.8 High | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2025-21391 | Microsoft | Windows | 7.1 High | Microsoft Windows Storage Link Following Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-40891 | Zyxel | DSL CPE Devices | 8.8 High | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-40890 | Zyxel | DSL CPE Devices | 8.8 High | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2025-0994 | Trimble | Cityworks | 8.6 High | Trimble Cityworks Deserialization Vulnerability | 2025-02-07 | 2025-02-28 | Unknown |
| CVE-2025-0411 | 7-Zip | 7-Zip | 7.0 High | 7-Zip Mark of the Web Bypass Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2024-21413 | Microsoft | Office Outlook | 9.8 Critical | Microsoft Outlook Improper Input Validation Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2022-23748 | Audinate | Dante Discovery | 7.8 High | Dante Discovery Process Control Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2020-29574 | Sophos | CyberoamOS | 9.8 Critical | CyberoamOS (CROS) SQL Injection Vulnerability | 2025-02-06 | 2025-02-27 | Known |
| CVE-2020-15069 | Sophos | XG Firewall | 9.8 Critical | Sophos XG Firewall Buffer Overflow Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2024-53104 | Linux | Kernel | 7.8 High | Linux Kernel Out-of-Bounds Write Vulnerability | 2025-02-05 | 2025-02-26 | Unknown |
| CVE-2024-45195 | Apache | OFBiz | 7.5 High | Apache OFBiz Forced Browsing Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2024-29059 | Microsoft | .NET Framework | 7.5 High | Microsoft .NET Framework Information Disclosure Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2018-9276 | Paessler | PRTG Network Monitor | 7.2 High | Paessler PRTG Network Monitor OS Command Injection Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2018-19410 | Paessler | PRTG Network Monitor | 9.8 Critical | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2025-24085 | Apple | Multiple Products | 10.0 Critical | Apple Multiple Products Use-After-Free Vulnerability | 2025-01-29 | 2025-02-19 | Unknown |
| CVE-2025-23006 | SonicWall | SMA1000 Appliances | 9.8 Critical | SonicWall SMA1000 Appliances Deserialization Vulnerability | 2025-01-24 | 2025-02-14 | Known |
| CVE-2020-11023 | JQuery | JQuery | 6.1 Medium | JQuery Cross-Site Scripting (XSS) Vulnerability | 2025-01-23 | 2025-02-13 | Unknown |
| CVE-2024-50603 | Aviatrix | Controllers | 9.8 Critical | Aviatrix Controllers OS Command Injection Vulnerability | 2025-01-16 | 2025-02-06 | Unknown |
| CVE-2025-21335 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21334 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21333 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2024-55591 | Fortinet | FortiOS and FortiProxy | 9.8 Critical | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | 2025-01-14 | 2025-01-21 | Known |
| CVE-2024-12686 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | 7.2 High | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | 2025-01-13 | 2025-02-03 | Unknown |
| CVE-2023-48365 | Qlik | Sense | 9.9 Critical | Qlik Sense HTTP Tunneling Vulnerability | 2025-01-13 | 2025-02-03 | Known |
| CVE-2025-0282 | Ivanti | Connect Secure, Policy Secure, and ZTA Gateways | 9.0 Critical | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 2025-01-08 | 2025-01-15 | Known |
| CVE-2024-55550 | Mitel | MiCollab | 2.7 Low | Mitel MiCollab Path Traversal Vulnerability | 2025-01-07 | 2025-01-28 | Known |
| CVE-2024-41713 | Mitel | MiCollab | 9.1 Critical | Mitel MiCollab Path Traversal Vulnerability | 2025-01-07 | 2025-01-28 | Known |
| CVE-2020-2883 | Oracle | WebLogic Server | 9.8 Critical | Oracle WebLogic Server Unspecified Vulnerability | 2025-01-07 | 2025-01-28 | Unknown |
| CVE-2024-3393 | Palo Alto Networks | PAN-OS | 8.7 High | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | 2024-12-30 | 2025-01-20 | Unknown |
| CVE-2021-44207 | Acclaim Systems | USAHERDS | 8.1 High | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | 2024-12-23 | 2025-01-13 | Unknown |
| CVE-2024-12356 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | 9.8 Critical | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | 2024-12-19 | 2024-12-27 | Unknown |
| CVE-2022-23227 | NUUO | NVRmini2 Devices | 9.8 Critical | NUUO NVRmini2 Devices Missing Authentication Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2021-40407 | Reolink | RLC-410W IP Camera | 7.2 High | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2019-11001 | Reolink | Multiple IP Cameras | 7.2 High | Reolink Multiple IP Cameras OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2018-14933 | NUUO | NVRmini Devices | 9.8 Critical | NUUO NVRmini Devices OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2024-55956 | Cleo | Multiple Products | 9.8 Critical | Cleo Multiple Products Unauthenticated File Upload Vulnerability | 2024-12-17 | 2025-01-07 | Known |
| CVE-2024-35250 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2024-20767 | Adobe | ColdFusion | 7.4 High | Adobe ColdFusion Improper Access Control Vulnerability | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2024-50623 | Cleo | Multiple Products | 9.8 Critical | Cleo Multiple Products Unrestricted File Upload Vulnerability | 2024-12-13 | 2025-01-03 | Known |
| CVE-2024-49138 | Microsoft | Windows | 7.8 High | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | 2024-12-10 | 2024-12-31 | Unknown |
| CVE-2024-51378 | CyberPersons | CyberPanel | 9.8 Critical | CyberPanel Incorrect Default Permissions Vulnerability | 2024-12-04 | 2024-12-25 | Known |
| CVE-2024-11680 | ProjectSend | ProjectSend | 9.8 Critical | ProjectSend Improper Authentication Vulnerability | 2024-12-03 | 2024-12-24 | Unknown |
| CVE-2024-11667 | Zyxel | Multiple Firewalls | 9.8 Critical | Zyxel Multiple Firewalls Path Traversal Vulnerability | 2024-12-03 | 2024-12-24 | Known |
| CVE-2023-45727 | North Grid | Proself | 7.5 High | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability | 2024-12-03 | 2024-12-24 | Unknown |