Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2023-3519 | Citrix | NetScaler ADC and NetScaler Gateway | 9.8 Critical | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | 2023-07-19 | 2023-08-09 | Known |
| CVE-2023-36884 | Microsoft | Windows | 7.5 High | Microsoft Windows Search Remote Code Execution Vulnerability | 2023-07-17 | 2023-08-29 | Known |
| CVE-2023-37450 | Apple | Multiple Products | 8.8 High | Apple Multiple Products WebKit Code Execution Vulnerability | 2023-07-13 | 2023-08-03 | Unknown |
| CVE-2022-29303 | SolarView | Compact | 9.8 Critical | SolarView Compact Command Injection Vulnerability | 2023-07-13 | 2023-08-03 | Unknown |
| CVE-2023-36874 | Microsoft | Windows | 7.8 High | Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | 2023-07-11 | 2023-08-01 | Unknown |
| CVE-2023-35311 | Microsoft | Outlook | 8.8 High | Microsoft Outlook Security Feature Bypass Vulnerability | 2023-07-11 | 2023-08-01 | Unknown |
| CVE-2023-32049 | Microsoft | Windows | 8.8 High | Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability | 2023-07-11 | 2023-08-01 | Unknown |
| CVE-2023-32046 | Microsoft | Windows | 7.8 High | Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability | 2023-07-11 | 2023-08-01 | Unknown |
| CVE-2022-31199 | Netwrix | Auditor | 9.8 Critical | Netwrix Auditor Insecure Object Deserialization Vulnerability | 2023-07-11 | 2023-08-01 | Known |
| CVE-2021-29256 | Arm | Mali Graphics Processing Unit (GPU) | 8.8 High | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | 2023-07-07 | 2023-07-28 | Unknown |
| CVE-2021-25489 | Samsung | Mobile Devices | 5.5 Medium | Samsung Mobile Devices Improper Input Validation Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25487 | Samsung | Mobile Devices | 7.8 High | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25395 | Samsung | Mobile Devices | 6.4 Medium | Samsung Mobile Devices Race Condition Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25394 | Samsung | Mobile Devices | 6.4 Medium | Samsung Mobile Devices Race Condition Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25372 | Samsung | Mobile Devices | 6.7 Medium | Samsung Mobile Devices Improper Boundary Check Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2021-25371 | Samsung | Mobile Devices | 6.7 Medium | Samsung Mobile Devices Unspecified Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2019-20500 | D-Link | DWL-2600AP Access Point | 7.8 High | D-Link DWL-2600AP Access Point Command Injection Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2019-17621 | D-Link | DIR-859 Router | 9.8 Critical | D-Link DIR-859 Router Command Execution Vulnerability | 2023-06-29 | 2023-07-20 | Unknown |
| CVE-2023-32439 | Apple | Multiple Products | 8.8 High | Apple Multiple Products WebKit Type Confusion Vulnerability | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-32435 | Apple | Multiple Products | 8.8 High | Apple Multiple Products WebKit Memory Corruption Vulnerability | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-32434 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Integer Overflow Vulnerability | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-27992 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | 9.8 Critical | Zyxel Multiple NAS Devices Command Injection Vulnerability | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-20867 | VMware | Tools | 3.9 Low | VMware Tools Authentication Bypass Vulnerability | 2023-06-23 | 2023-07-14 | Unknown |
| CVE-2023-20887 | VMware | Aria Operations for Networks | 9.8 Critical | Vmware Aria Operations for Networks Command Injection Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2021-44026 | Roundcube | Roundcube Webmail | 9.8 Critical | Roundcube Webmail SQL Injection Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2020-35730 | Roundcube | Roundcube Webmail | 6.1 Medium | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2020-12641 | Roundcube | Roundcube Webmail | 9.8 Critical | Roundcube Webmail Remote Code Execution Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2016-9079 | Mozilla | Firefox, Firefox ESR, and Thunderbird | 7.5 High | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2016-0165 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2023-06-22 | 2023-07-13 | Unknown |
| CVE-2023-27997 | Fortinet | FortiOS and FortiProxy SSL-VPN | 9.8 Critical | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | 2023-06-13 | 2023-07-04 | Known |
| CVE-2023-3079 | Chromium V8 | 8.8 High | Google Chromium V8 Type Confusion Vulnerability | 2023-06-07 | 2023-06-28 | Unknown | |
| CVE-2023-33010 | Zyxel | Multiple Firewalls | 9.8 Critical | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 2023-06-05 | 2023-06-26 | Unknown |
| CVE-2023-33009 | Zyxel | Multiple Firewalls | 9.8 Critical | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | 2023-06-05 | 2023-06-26 | Unknown |
| CVE-2023-34362 | Progress | MOVEit Transfer | 9.8 Critical | Progress MOVEit Transfer SQL Injection Vulnerability | 2023-06-02 | 2023-06-23 | Known |
| CVE-2023-28771 | Zyxel | Multiple Firewalls | 9.8 Critical | Zyxel Multiple Firewalls OS Command Injection Vulnerability | 2023-05-31 | 2023-06-21 | Unknown |
| CVE-2023-2868 | Barracuda Networks | Email Security Gateway (ESG) Appliance | 9.8 Critical | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | 2023-05-26 | 2023-06-16 | Unknown |
| CVE-2023-32409 | Apple | Multiple Products | 8.6 High | Apple Multiple Products WebKit Sandbox Escape Vulnerability | 2023-05-22 | 2023-06-12 | Unknown |
| CVE-2023-32373 | Apple | Multiple Products | 8.8 High | Apple Multiple Products WebKit Use-After-Free Vulnerability | 2023-05-22 | 2023-06-12 | Unknown |
| CVE-2023-28204 | Apple | Multiple Products | 6.5 Medium | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | 2023-05-22 | 2023-06-12 | Unknown |
| CVE-2023-21492 | Samsung | Mobile Devices | 4.4 Medium | Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability | 2023-05-19 | 2023-06-09 | Unknown |
| CVE-2016-6415 | Cisco | IOS, IOS XR, and IOS XE | 7.5 High | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | 2023-05-19 | 2023-06-09 | Unknown |
| CVE-2004-1464 | Cisco | IOS | 5.9 Medium | Cisco IOS Denial-of-Service Vulnerability | 2023-05-19 | 2023-06-09 | Unknown |
| CVE-2023-25717 | Ruckus Wireless | Multiple Products | 9.8 Critical | Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2021-3560 | Red Hat | Polkit | 7.8 High | Red Hat Polkit Incorrect Authorization Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2016-8735 | Apache | Tomcat | 9.8 Critical | Apache Tomcat Remote Code Execution Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2016-3427 | Oracle | Java SE and JRockit | 9.8 Critical | Oracle Java SE and JRockit Unspecified Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2015-5317 | Jenkins | Jenkins User Interface (UI) | 7.5 High | Jenkins User Interface (UI) Information Disclosure Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2014-0196 | Linux | Kernel | 5.5 Medium | Linux Kernel Race Condition Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2010-3904 | Linux | Kernel | 7.8 High | Linux Kernel Improper Input Validation Vulnerability | 2023-05-12 | 2023-06-02 | Unknown |
| CVE-2023-29336 | Microsoft | Win32k | 7.8 High | Microsoft Win32K Privilege Escalation Vulnerability | 2023-05-09 | 2023-05-30 | Unknown |