Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2024-29988 | Microsoft | SmartScreen Prompt | 8.8 High | Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability | 2024-04-30 | 2024-05-21 | Unknown |
| CVE-2024-4040 | CrushFTP | CrushFTP | 10.0 Critical | CrushFTP VFS Sandbox Escape Vulnerability | 2024-04-24 | 2024-05-01 | Unknown |
| CVE-2024-20359 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 6.0 Medium | Cisco ASA and FTD Privilege Escalation Vulnerability | 2024-04-24 | 2024-05-01 | Unknown |
| CVE-2024-20353 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 8.6 High | Cisco ASA and FTD Denial of Service Vulnerability | 2024-04-24 | 2024-05-01 | Unknown |
| CVE-2022-38028 | Microsoft | Windows | 7.8 High | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | 2024-04-23 | 2024-05-14 | Unknown |
| CVE-2024-3400 | Palo Alto Networks | PAN-OS | 10.0 Critical | Palo Alto Networks PAN-OS Command Injection Vulnerability | 2024-04-12 | 2024-04-19 | Known |
| CVE-2024-3273 | D-Link | Multiple NAS Devices | 9.8 Critical | D-Link Multiple NAS Devices Command Injection Vulnerability | 2024-04-11 | 2024-05-02 | Unknown |
| CVE-2024-3272 | D-Link | Multiple NAS Devices | 9.8 Critical | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | 2024-04-11 | 2024-05-02 | Unknown |
| CVE-2024-29748 | Android | Pixel | 7.8 High | Android Pixel Privilege Escalation Vulnerability | 2024-04-04 | 2024-04-25 | Unknown |
| CVE-2024-29745 | Android | Pixel | 5.5 Medium | Android Pixel Information Disclosure Vulnerability | 2024-04-04 | 2024-04-25 | Unknown |
| CVE-2023-24955 | Microsoft | SharePoint Server | 7.2 High | Microsoft SharePoint Server Code Injection Vulnerability | 2024-03-26 | 2024-04-16 | Known |
| CVE-2023-48788 | Fortinet | FortiClient EMS | 9.8 Critical | Fortinet FortiClient EMS SQL Injection Vulnerability | 2024-03-25 | 2024-04-15 | Known |
| CVE-2021-44529 | Ivanti | Endpoint Manager Cloud Service Appliance (EPM CSA) | 9.8 Critical | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | 2024-03-25 | 2024-04-15 | Known |
| CVE-2019-7256 | Nice | Linear eMerge E3-Series | 9.8 Critical | Nice Linear eMerge E3-Series OS Command Injection Vulnerability | 2024-03-25 | 2024-04-15 | Unknown |
| CVE-2024-27198 | JetBrains | TeamCity | 9.8 Critical | JetBrains TeamCity Authentication Bypass Vulnerability | 2024-03-07 | 2024-03-28 | Known |
| CVE-2024-23296 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Memory Corruption Vulnerability | 2024-03-06 | 2024-03-27 | Unknown |
| CVE-2024-23225 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Memory Corruption Vulnerability | 2024-03-06 | 2024-03-27 | Unknown |
| CVE-2023-21237 | Android | Pixel | 5.5 Medium | Android Pixel Information Disclosure Vulnerability | 2024-03-05 | 2024-03-26 | Unknown |
| CVE-2021-36380 | Sunhillo | SureLine | 9.8 Critical | Sunhillo SureLine OS Command Injection Vulnerablity | 2024-03-05 | 2024-03-26 | Unknown |
| CVE-2024-21338 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | 2024-03-04 | 2024-03-25 | Known |
| CVE-2023-29360 | Microsoft | Streaming Service | 8.4 High | Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability | 2024-02-29 | 2024-03-21 | Unknown |
| CVE-2024-1709 | ConnectWise | ScreenConnect | 10.0 Critical | ConnectWise ScreenConnect Authentication Bypass Vulnerability | 2024-02-22 | 2024-02-29 | Known |
| CVE-2024-21410 | Microsoft | Exchange Server | 9.8 Critical | Microsoft Exchange Server Privilege Escalation Vulnerability | 2024-02-15 | 2024-03-07 | Unknown |
| CVE-2020-3259 | Cisco | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 7.5 High | Cisco ASA and FTD Information Disclosure Vulnerability | 2024-02-15 | 2024-03-07 | Known |
| CVE-2024-21412 | Microsoft | Windows | 8.1 High | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | 2024-02-13 | 2024-03-05 | Known |
| CVE-2024-21351 | Microsoft | Windows | 7.6 High | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | 2024-02-13 | 2024-03-05 | Unknown |
| CVE-2023-43770 | Roundcube | Webmail | 6.1 Medium | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | 2024-02-12 | 2024-03-04 | Unknown |
| CVE-2024-21762 | Fortinet | FortiOS | 9.8 Critical | Fortinet FortiOS Out-of-Bound Write Vulnerability | 2024-02-09 | 2024-02-16 | Known |
| CVE-2023-4762 | Chromium V8 | 8.8 High | Google Chromium V8 Type Confusion Vulnerability | 2024-02-06 | 2024-02-27 | Unknown | |
| CVE-2024-21893 | Ivanti | Connect Secure, Policy Secure, and Neurons | 8.2 High | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | 2024-01-31 | 2024-02-02 | Known |
| CVE-2022-48618 | Apple | Multiple Products | 7.0 High | Apple Multiple Products Memory Corruption Vulnerability | 2024-01-31 | 2024-02-21 | Unknown |
| CVE-2023-22527 | Atlassian | Confluence Data Center and Server | 9.8 Critical | Atlassian Confluence Data Center and Server Template Injection Vulnerability | 2024-01-24 | 2024-02-14 | Known |
| CVE-2024-23222 | Apple | Multiple Products | 8.8 High | Apple Multiple Products WebKit Type Confusion Vulnerability | 2024-01-23 | 2024-02-13 | Unknown |
| CVE-2023-34048 | VMware | vCenter Server | 9.8 Critical | VMware vCenter Server Out-of-Bounds Write Vulnerability | 2024-01-22 | 2024-02-12 | Unknown |
| CVE-2023-35082 | Ivanti | Endpoint Manager Mobile (EPMM) and MobileIron Core | 9.8 Critical | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | 2024-01-18 | 2024-02-08 | Known |
| CVE-2024-0519 | Chromium V8 | 8.8 High | Google Chromium V8 Out-of-Bounds Memory Access Vulnerability | 2024-01-17 | 2024-02-07 | Unknown | |
| CVE-2023-6549 | Citrix | NetScaler ADC and NetScaler Gateway | 7.5 High | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | 2024-01-17 | 2024-02-07 | Unknown |
| CVE-2023-6548 | Citrix | NetScaler ADC and NetScaler Gateway | 8.8 High | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 2024-01-17 | 2024-01-24 | Unknown |
| CVE-2018-15133 | Laravel | Laravel Framework | 8.1 High | Laravel Deserialization of Untrusted Data Vulnerability | 2024-01-16 | 2024-02-06 | Unknown |
| CVE-2024-21887 | Ivanti | Connect Secure and Policy Secure | 9.1 Critical | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | 2024-01-10 | 2024-01-22 | Known |
| CVE-2023-46805 | Ivanti | Connect Secure and Policy Secure | 8.2 High | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | 2024-01-10 | 2024-01-22 | Known |
| CVE-2023-29357 | Microsoft | SharePoint Server | 9.8 Critical | Microsoft SharePoint Server Privilege Escalation Vulnerability | 2024-01-10 | 2024-01-31 | Known |
| CVE-2023-41990 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Code Execution Vulnerability | 2024-01-08 | 2024-01-29 | Unknown |
| CVE-2023-38203 | Adobe | ColdFusion | 9.8 Critical | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 2024-01-08 | 2024-01-29 | Known |
| CVE-2023-29300 | Adobe | ColdFusion | 9.8 Critical | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | 2024-01-08 | 2024-01-29 | Known |
| CVE-2023-27524 | Apache | Superset | 9.8 Critical | Apache Superset Insecure Default Initialization of Resource Vulnerability | 2024-01-08 | 2024-01-29 | Unknown |
| CVE-2023-23752 | Joomla! | Joomla! | 5.3 Medium | Joomla! Improper Access Control Vulnerability | 2024-01-08 | 2024-01-29 | Unknown |
| CVE-2016-20017 | D-Link | DSL-2750B Devices | 9.8 Critical | D-Link DSL-2750B Devices Command Injection Vulnerability | 2024-01-08 | 2024-01-29 | Unknown |
| CVE-2023-7101 | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel | 7.8 High | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | 2024-01-02 | 2024-01-23 | Unknown |
| CVE-2023-7024 | Chromium WebRTC | 8.8 High | Google Chromium WebRTC Heap Buffer Overflow Vulnerability | 2024-01-02 | 2024-01-23 | Unknown |