Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2021-33044 | Dahua | IP Camera Firmware | 9.8 Critical | Dahua IP Camera Authentication Bypass Vulnerability | 2024-08-21 | 2024-09-11 | Unknown |
| CVE-2021-31196 | Microsoft | Exchange Server | 7.2 High | Microsoft Exchange Server Information Disclosure Vulnerability | 2024-08-21 | 2024-09-11 | Unknown |
| CVE-2024-23897 | Jenkins | Jenkins Command Line Interface (CLI) | 9.8 Critical | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | 2024-08-19 | 2024-09-09 | Known |
| CVE-2024-28986 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 2024-08-15 | 2024-09-05 | Unknown |
| CVE-2024-38213 | Microsoft | Windows | 6.5 Medium | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38193 | Microsoft | Windows | 7.8 High | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38189 | Microsoft | Project | 8.8 High | Microsoft Project Remote Code Execution Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38178 | Microsoft | Windows | 7.5 High | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38107 | Microsoft | Windows | 7.8 High | Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38106 | Microsoft | Windows | 7.0 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-36971 | Android | Kernel | 7.8 High | Android Kernel Remote Code Execution Vulnerability | 2024-08-07 | 2024-08-28 | Unknown |
| CVE-2024-32113 | Apache | OFBiz | 9.8 Critical | Apache OFBiz Path Traversal Vulnerability | 2024-08-07 | 2024-08-28 | Unknown |
| CVE-2018-0824 | Microsoft | Windows | 8.8 High | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability | 2024-08-05 | 2024-08-26 | Unknown |
| CVE-2024-37085 | VMware | ESXi | 7.2 High | VMware ESXi Authentication Bypass Vulnerability | 2024-07-30 | 2024-08-20 | Known |
| CVE-2024-5217 | ServiceNow | Utah, Vancouver, and Washington DC Now Platform | 9.2 Critical | ServiceNow Incomplete List of Disallowed Inputs Vulnerability | 2024-07-29 | 2024-08-19 | Unknown |
| CVE-2024-4879 | ServiceNow | Utah, Vancouver, and Washington DC Now Platform | 9.3 Critical | ServiceNow Improper Input Validation Vulnerability | 2024-07-29 | 2024-08-19 | Unknown |
| CVE-2023-45249 | Acronis | Cyber Infrastructure (ACI) | 9.8 Critical | Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability | 2024-07-29 | 2024-08-19 | Unknown |
| CVE-2024-39891 | Twilio | Authy | 5.3 Medium | Twilio Authy Information Disclosure Vulnerability | 2024-07-23 | 2024-08-13 | Unknown |
| CVE-2012-4792 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Use-After-Free Vulnerability | 2024-07-23 | 2024-08-13 | Unknown |
| CVE-2024-34102 | Adobe | Commerce and Magento Open Source | 9.8 Critical | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | 2024-07-17 | 2024-08-07 | Unknown |
| CVE-2024-28995 | SolarWinds | Serv-U | 7.5 High | SolarWinds Serv-U Path Traversal Vulnerability | 2024-07-17 | 2024-08-07 | Unknown |
| CVE-2022-22948 | VMware | vCenter Server | 6.5 Medium | VMware vCenter Server Incorrect Default File Permissions Vulnerability | 2024-07-17 | 2024-08-07 | Unknown |
| CVE-2024-36401 | OSGeo | GeoServer | 9.8 Critical | OSGeo GeoServer GeoTools Eval Injection Vulnerability | 2024-07-15 | 2024-08-05 | Unknown |
| CVE-2024-38112 | Microsoft | Windows | 7.5 High | Microsoft Windows MSHTML Platform Spoofing Vulnerability | 2024-07-09 | 2024-07-30 | Unknown |
| CVE-2024-38080 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V Privilege Escalation Vulnerability | 2024-07-09 | 2024-07-30 | Unknown |
| CVE-2024-23692 | Rejetto | HTTP File Server | 9.8 Critical | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | 2024-07-09 | 2024-07-30 | Unknown |
| CVE-2024-20399 | Cisco | NX-OS | 6.7 Medium | Cisco NX-OS Command Injection Vulnerability | 2024-07-02 | 2024-07-23 | Unknown |
| CVE-2022-2586 | Linux | Kernel | 7.8 High | Linux Kernel Use-After-Free Vulnerability | 2024-06-26 | 2024-07-17 | Unknown |
| CVE-2022-24816 | OSGeo | JAI-EXT | 10.0 Critical | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | 2024-06-26 | 2024-07-17 | Unknown |
| CVE-2020-13965 | Roundcube | Webmail | 6.1 Medium | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | 2024-06-26 | 2024-07-17 | Unknown |
| CVE-2024-4358 | Progress | Telerik Report Server | 9.8 Critical | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | 2024-06-13 | 2024-07-04 | Unknown |
| CVE-2024-32896 | Android | Pixel | 7.8 High | Android Pixel Privilege Escalation Vulnerability | 2024-06-13 | 2024-07-04 | Unknown |
| CVE-2024-26169 | Microsoft | Windows | 7.8 High | Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability | 2024-06-13 | 2024-07-04 | Known |
| CVE-2024-4610 | Arm | Mali GPU Kernel Driver | 7.8 High | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 2024-06-12 | 2024-07-03 | Unknown |
| CVE-2024-4577 | PHP Group | PHP | 9.8 Critical | PHP-CGI OS Command Injection Vulnerability | 2024-06-12 | 2024-07-03 | Known |
| CVE-2017-3506 | Oracle | WebLogic Server | 7.4 High | Oracle WebLogic Server OS Command Injection Vulnerability | 2024-06-03 | 2024-06-24 | Unknown |
| CVE-2024-24919 | Check Point | Quantum Security Gateways | 8.6 High | Check Point Quantum Security Gateways Information Disclosure Vulnerability | 2024-05-30 | 2024-06-20 | Known |
| CVE-2024-1086 | Linux | Kernel | 7.8 High | Linux Kernel Use-After-Free Vulnerability | 2024-05-30 | 2024-06-20 | Known |
| CVE-2024-4978 | Justice AV Solutions | Viewer | 8.7 High | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | 2024-05-29 | 2024-06-19 | Unknown |
| CVE-2024-5274 | Chromium V8 | 9.6 Critical | Google Chromium V8 Type Confusion Vulnerability | 2024-05-28 | 2024-06-18 | Unknown | |
| CVE-2020-17519 | Apache | Flink | 7.5 High | Apache Flink Improper Access Control Vulnerability | 2024-05-23 | 2024-06-13 | Unknown |
| CVE-2024-4947 | Chromium V8 | 9.6 Critical | Google Chromium V8 Type Confusion Vulnerability | 2024-05-20 | 2024-06-10 | Unknown | |
| CVE-2023-43208 | NextGen Healthcare | Mirth Connect | 9.8 Critical | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability | 2024-05-20 | 2024-06-10 | Known |
| CVE-2024-4761 | Chromium V8 | 8.8 High | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | 2024-05-16 | 2024-06-06 | Unknown | |
| CVE-2021-40655 | D-Link | DIR-605 Router | 7.5 High | D-Link DIR-605 Router Information Disclosure Vulnerability | 2024-05-16 | 2024-06-06 | Unknown |
| CVE-2014-100005 | D-Link | DIR-600 Router | 8.0 High | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | 2024-05-16 | 2024-06-06 | Unknown |
| CVE-2024-30051 | Microsoft | DWM Core Library | 7.8 High | Microsoft DWM Core Library Privilege Escalation Vulnerability | 2024-05-14 | 2024-06-04 | Known |
| CVE-2024-30040 | Microsoft | Windows | 8.8 High | Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability | 2024-05-14 | 2024-06-04 | Unknown |
| CVE-2024-4671 | Chromium | 9.6 Critical | Google Chromium Visuals Use-After-Free Vulnerability | 2024-05-13 | 2024-06-03 | Unknown | |
| CVE-2023-7028 | GitLab | GitLab CE/EE | 9.8 Critical | GitLab Community and Enterprise Editions Improper Access Control Vulnerability | 2024-05-01 | 2024-05-22 | Unknown |