Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-48172 | LiteSpeed | cPanel Plugin | 10.0 Critical | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | 2026-05-26 | 2026-05-29 | Unknown |
| CVE-2026-9082 | Drupal | Core | 9.8 Critical | Drupal Core SQL Injection Vulnerability | 2026-05-22 | 2026-05-27 | Unknown |
| CVE-2026-34926 | Trend Micro | Apex One | 6.7 Medium | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | 2026-05-21 | 2026-06-04 | Unknown |
| CVE-2025-34291 | Langflow | Langflow | 9.4 Critical | Langflow Origin Validation Error Vulnerability | 2026-05-21 | 2026-06-04 | Unknown |
| CVE-2026-45498 | Microsoft | Defender | 7.5 High | Microsoft Defender Denial of Service Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2026-41091 | Microsoft | Defender | 7.8 High | Microsoft Defender Link Following Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2010-0806 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2010-0249 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2009-3459 | Adobe | Acrobat and Reader | 8.8 High | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2009-1537 | Microsoft | DirectX | 8.8 High | Microsoft DirectX NULL Byte Overwrite Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2008-4250 | Microsoft | Windows | 9.8 Critical | Microsoft Windows Buffer Overflow Vulnerability | 2026-05-20 | 2026-06-03 | Unknown |
| CVE-2026-42897 | Microsoft | Microsoft | 6.1 Medium | Microsoft Exchange Server Cross-Site Scripting Vulnerability | 2026-05-15 | 2026-05-29 | Unknown |
| CVE-2026-20182 | Cisco | Catalyst SD-WAN | 10.0 Critical | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | 2026-05-14 | 2026-05-17 | Unknown |
| CVE-2026-42208 | BerriAI | LiteLLM | 9.3 Critical | BerriAI LiteLLM SQL Injection Vulnerability | 2026-05-08 | 2026-05-11 | Unknown |
| CVE-2026-6973 | Ivanti | Endpoint Manager Mobile (EPMM) | 7.2 High | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | 2026-05-07 | 2026-05-10 | Unknown |
| CVE-2026-0300 | Palo Alto Networks | PAN-OS | 9.3 Critical | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | 2026-05-06 | 2026-05-09 | Unknown |
| CVE-2026-31431 | Linux | Kernel | 7.8 High | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | 2026-05-01 | 2026-05-15 | Unknown |
| CVE-2026-41940 | WebPros | cPanel & WHM and WP2 (WordPress Squared) | 9.3 Critical | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | 2026-04-30 | 2026-05-03 | Known |
| CVE-2026-32202 | Microsoft | Windows | 4.3 Medium | Microsoft Windows Protection Mechanism Failure Vulnerability | 2026-04-28 | 2026-05-12 | Unknown |
| CVE-2024-1708 | ConnectWise | ScreenConnect | 8.4 High | ConnectWise ScreenConnect Path Traversal Vulnerability | 2026-04-28 | 2026-05-12 | Known |
| CVE-2025-29635 | D-Link | DIR-823X | 7.2 High | D-Link DIR-823X Command Injection Vulnerability | 2026-04-24 | 2026-05-08 | Unknown |
| CVE-2024-7399 | Samsung | MagicINFO 9 Server | 9.8 Critical | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 2026-04-24 | 2026-05-08 | Unknown |
| CVE-2024-57728 | SimpleHelp | SimpleHelp | 7.2 High | SimpleHelp Path Traversal Vulnerability | 2026-04-24 | 2026-05-08 | Known |
| CVE-2024-57726 | SimpleHelp | SimpleHelp | 9.9 Critical | SimpleHelp Missing Authorization Vulnerability | 2026-04-24 | 2026-05-08 | Known |
| CVE-2026-39987 | Marimo | Marimo | 9.3 Critical | Marimo Remote Code Execution Vulnerability | 2026-04-23 | 2026-05-07 | Unknown |
| CVE-2026-33825 | Microsoft | Defender | 7.8 High | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | 2026-04-22 | 2026-05-06 | Known |
| CVE-2026-20133 | Cisco | Catalyst SD-WAN Manager | 7.5 High | Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-04-20 | 2026-04-23 | Unknown |
| CVE-2026-20128 | Cisco | Catalyst SD-WAN Manager | 7.5 High | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | 2026-04-20 | 2026-04-23 | Unknown |
| CVE-2026-20122 | Cisco | Catalyst SD-WAN Manger | 5.4 Medium | Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | 2026-04-20 | 2026-04-23 | Unknown |
| CVE-2025-48700 | Synacor | Zimbra Collaboration Suite (ZCS) | 6.1 Medium | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | 2026-04-20 | 2026-04-23 | Unknown |
| CVE-2025-32975 | Quest | KACE Systems Management Appliance (SMA) | 10.0 Critical | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | 2026-04-20 | 2026-05-04 | Unknown |
| CVE-2025-2749 | Kentico | Kentico Xperience | 7.2 High | Kentico Xperience Path Traversal Vulnerability | 2026-04-20 | 2026-05-04 | Unknown |
| CVE-2024-27199 | JetBrains | TeamCity | 7.3 High | JetBrains TeamCity Relative Path Traversal Vulnerability | 2026-04-20 | 2026-05-04 | Known |
| CVE-2023-27351 | PaperCut | NG/MF | 7.5 High | PaperCut NG/MF Improper Authentication Vulnerability | 2026-04-20 | 2026-05-04 | Known |
| CVE-2026-34197 | Apache | ActiveMQ | 8.8 High | Apache ActiveMQ Improper Input Validation Vulnerability | 2026-04-16 | 2026-04-30 | Unknown |
| CVE-2026-32201 | Microsoft | SharePoint Server | 6.5 Medium | Microsoft SharePoint Server Improper Input Validation Vulnerability | 2026-04-14 | 2026-04-28 | Unknown |
| CVE-2009-0238 | Microsoft | Office | 8.8 High | Microsoft Office Remote Code Execution | 2026-04-14 | 2026-04-28 | Unknown |
| CVE-2026-34621 | Adobe | Acrobat and Reader | 8.6 High | Adobe Acrobat and Reader Prototype Pollution Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2026-21643 | Fortinet | FortiClient EMS | 9.8 Critical | Fortinet FortiClient EMS SQL Injection Vulnerability | 2026-04-13 | 2026-04-16 | Unknown |
| CVE-2025-60710 | Microsoft | Windows | 7.8 High | Microsoft Windows Link Following Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2023-36424 | Microsoft | Windows | 7.8 High | Microsoft Windows Out-of-Bounds Read Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2023-21529 | Microsoft | Exchange Server | 8.8 High | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | 2026-04-13 | 2026-04-27 | Known |
| CVE-2020-9715 | Adobe | Acrobat | 7.8 High | Adobe Acrobat Use-After-Free Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2012-1854 | Microsoft | Visual Basic for Applications (VBA) | 7.8 High | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2026-1340 | Ivanti | Endpoint Manager Mobile (EPMM) | 9.8 Critical | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-04-08 | 2026-04-11 | Unknown |
| CVE-2026-35616 | Fortinet | FortiClient EMS | 9.8 Critical | Fortinet FortiClient EMS Improper Access Control Vulnerability | 2026-04-06 | 2026-04-09 | Unknown |
| CVE-2026-3502 | TrueConf | Client | 7.8 High | TrueConf Client Download of Code Without Integrity Check Vulnerability | 2026-04-02 | 2026-04-16 | Unknown |
| CVE-2026-5281 | Dawn | 8.8 High | Google Dawn Use-After-Free Vulnerability | 2026-04-01 | 2026-04-15 | Unknown | |
| CVE-2026-3055 | Citrix | NetScaler | 9.3 Critical | Citrix NetScaler Out-of-Bounds Read Vulnerability | 2026-03-30 | 2026-04-02 | Unknown |
| CVE-2025-53521 | F5 | BIG-IP | 9.3 Critical | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | 2026-03-27 | 2026-03-30 | Unknown |