Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2018-10561 | Dasan | Gigabit Passive Optical Network (GPON) Routers | 9.8 Critical | Dasan GPON Routers Authentication Bypass Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2022-1096 | Chromium V8 | 8.8 High | Google Chromium V8 Type Confusion Vulnerability | 2022-03-28 | 2022-04-18 | Unknown | |
| CVE-2022-0543 | Redis | Debian-specific Redis Servers | 10.0 Critical | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2021-38646 | Microsoft | Office | 7.8 High | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2021-34486 | Microsoft | Windows | 7.8 High | Microsoft Windows Event Tracing Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2021-26085 | Atlassian | Confluence Server | 5.3 Medium | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2021-20028 | SonicWall | Secure Remote Access (SRA) | 9.8 Critical | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2019-7483 | SonicWall | SMA100 | 7.5 High | SonicWall SMA100 Directory Traversal Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2018-8440 | Microsoft | Windows | 7.8 High | Microsoft Windows Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2018-8406 | Microsoft | DirectX Graphics Kernel (DXGKRNL) | 7.8 High | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2018-8405 | Microsoft | DirectX Graphics Kernel (DXGKRNL) | 7.8 High | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2017-0213 | Microsoft | Windows | 7.3 High | Microsoft Windows Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2017-0059 | Microsoft | Internet Explorer | 4.3 Medium | Microsoft Internet Explorer Information Disclosure Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2017-0037 | Microsoft | Edge and Internet Explorer | 8.1 High | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-7201 | Microsoft | Edge | 8.8 High | Microsoft Edge Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-7200 | Microsoft | Edge | 8.8 High | Microsoft Edge Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-0189 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-0151 | Microsoft | Client-Server Run-time Subsystem (CSRSS) | 7.8 High | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2016-0040 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-2426 | Microsoft | Windows | 8.8 High | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-2419 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-1770 | Microsoft | Office | 8.8 High | Microsoft Office Uninitialized Memory Use Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-3660 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-2729 | Adobe | Reader and Acrobat | 9.8 Critical | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-2551 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Use-After-Free Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2013-2465 | Oracle | Java SE | 9.8 Critical | Oracle Java SE Unspecified Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2013-1690 | Mozilla | Firefox and Thunderbird | 8.8 High | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-5076 | Oracle | Java SE | 9.8 Critical | Oracle Java SE Sandbox Bypass Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-2539 | Microsoft | Word | 7.8 High | Microsoft Word Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-2034 | Adobe | Flash Player | 7.5 High | Adobe Flash Player Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-0518 | Oracle | Fusion Middleware | 4.7 Medium | Oracle Fusion Middleware Unspecified Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2011-2005 | Microsoft | Ancillary Function Driver (afd.sys) | 7.8 High | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2010-4398 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability | 2022-03-28 | 2022-04-21 | Unknown |
| CVE-2022-26318 | WatchGuard | Firebox and XTM Appliances | 9.8 Critical | WatchGuard Firebox and XTM Appliances Arbitrary Code Execution | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2022-26143 | Mitel | MiCollab, MiVoice Business Express | 9.8 Critical | MiCollab, MiVoice Business Express Access Control Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2022-21999 | Microsoft | Windows | 7.8 High | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | 2022-03-25 | 2022-04-15 | Known |
| CVE-2021-42237 | Sitecore | XP | 9.8 Critical | Sitecore XP Remote Command Execution Vulnerability | 2022-03-25 | 2022-04-15 | Known |
| CVE-2021-22941 | Citrix | ShareFile | 9.8 Critical | Citrix ShareFile Improper Access Control Vulnerability | 2022-03-25 | 2022-04-15 | Known |
| CVE-2020-9377 | D-Link | DIR-610 Devices | 8.8 High | D-Link DIR-610 Devices Remote Command Execution | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-9054 | Zyxel | Multiple Network-Attached Storage (NAS) Devices | 9.8 Critical | Zyxel Multiple NAS Devices OS Command Injection Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-7247 | OpenBSD | OpenSMTPD | 9.8 Critical | OpenSMTPD Remote Code Execution Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-5410 | VMware Tanzu | Spring Cloud Configuration (Config) Server | 7.5 High | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-25223 | Sophos | SG UTM | 9.8 Critical | Sophos SG UTM Remote Code Execution Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-2506 | QNAP Systems | Helpdesk | 9.8 Critical | QNAP Helpdesk Improper Access Control Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-2021 | Palo Alto Networks | PAN-OS | 10.0 Critical | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 2022-03-25 | 2022-04-15 | Known |
| CVE-2020-1956 | Apache | Kylin | 8.8 High | Apache Kylin OS Command Injection Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2020-1631 | Juniper | Junos OS | 9.8 Critical | Juniper Junos OS Path Traversal Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2019-6340 | Drupal | Core | 8.1 High | Drupal Core Remote Code Execution Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2019-2616 | Oracle | BI Publisher (Formerly XML Publisher) | 7.2 High | Oracle BI Publisher Unauthorized Access Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |
| CVE-2019-16920 | D-Link | Multiple Routers | 9.8 Critical | D-Link Multiple Routers Command Injection Vulnerability | 2022-03-25 | 2022-04-15 | Unknown |