Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2021-42287 | Microsoft | Active Directory | 7.5 High | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | 2022-04-11 | 2022-05-02 | Known |
| CVE-2021-42278 | Microsoft | Active Directory | 7.5 High | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | 2022-04-11 | 2022-05-02 | Known |
| CVE-2021-39793 | Pixel | 7.8 High | Google Pixel Out-of-Bounds Write Vulnerability | 2022-04-11 | 2022-05-02 | Unknown | |
| CVE-2021-27852 | Checkbox | Checkbox Survey | 9.8 Critical | Checkbox Survey Deserialization of Untrusted Data Vulnerability | 2022-04-11 | 2022-05-02 | Unknown |
| CVE-2021-22600 | Linux | Kernel | 7.0 High | Linux Kernel Privilege Escalation Vulnerability | 2022-04-11 | 2022-05-02 | Unknown |
| CVE-2020-2509 | QNAP | QNAP Network-Attached Storage (NAS) | 9.8 Critical | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | 2022-04-11 | 2022-05-02 | Unknown |
| CVE-2017-11317 | Telerik | User Interface (UI) for ASP.NET AJAX | 9.8 Critical | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | 2022-04-11 | 2022-05-02 | Unknown |
| CVE-2021-3156 | Sudo | Sudo | 7.8 High | Sudo Heap-Based Buffer Overflow Vulnerability | 2022-04-06 | 2022-04-27 | Unknown |
| CVE-2021-31166 | Microsoft | HTTP Protocol Stack | 9.8 Critical | Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability | 2022-04-06 | 2022-04-27 | Unknown |
| CVE-2017-0148 | Microsoft | SMBv1 server | 8.1 High | Microsoft SMBv1 Server Remote Code Execution Vulnerability | 2022-04-06 | 2022-04-27 | Known |
| CVE-2022-22965 | VMware | Spring Framework | 9.8 Critical | Spring Framework JDK 9+ Remote Code Execution Vulnerability | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2022-22675 | Apple | macOS | 7.8 High | Apple macOS Out-of-Bounds Write Vulnerability | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2022-22674 | Apple | macOS | 5.5 Medium | Apple macOS Out-of-Bounds Read Vulnerability | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2021-45382 | D-Link | Multiple Routers | 9.8 Critical | D-Link Multiple Routers Remote Code Execution Vulnerability | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2022-26871 | Trend Micro | Apex Central | 9.8 Critical | Trend Micro Apex Central Arbitrary File Upload Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2022-1040 | Sophos | Firewall | 9.8 Critical | Sophos Firewall Authentication Bypass Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2021-34484 | Microsoft | Windows | 7.8 High | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2021-28799 | QNAP | Network Attached Storage (NAS) | 9.8 Critical | QNAP NAS Improper Authorization Vulnerability | 2022-03-31 | 2022-04-21 | Known |
| CVE-2021-21551 | Dell | dbutil Driver | 7.8 High | Dell dbutil Driver Insufficient Access Control Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2018-10562 | Dasan | Gigabit Passive Optical Network (GPON) Routers | 9.8 Critical | Dasan GPON Routers Command Injection Vulnerability | 2022-03-31 | 2022-04-21 | Known |
| CVE-2018-10561 | Dasan | Gigabit Passive Optical Network (GPON) Routers | 9.8 Critical | Dasan GPON Routers Authentication Bypass Vulnerability | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2022-1096 | Chromium V8 | 8.8 High | Google Chromium V8 Type Confusion Vulnerability | 2022-03-28 | 2022-04-18 | Unknown | |
| CVE-2022-0543 | Redis | Debian-specific Redis Servers | 10.0 Critical | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2021-38646 | Microsoft | Office | 7.8 High | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2021-34486 | Microsoft | Windows | 7.8 High | Microsoft Windows Event Tracing Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2021-26085 | Atlassian | Confluence Server | 5.3 Medium | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2021-20028 | SonicWall | Secure Remote Access (SRA) | 9.8 Critical | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2019-7483 | SonicWall | SMA100 | 7.5 High | SonicWall SMA100 Directory Traversal Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2018-8440 | Microsoft | Windows | 7.8 High | Microsoft Windows Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2018-8406 | Microsoft | DirectX Graphics Kernel (DXGKRNL) | 7.8 High | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2018-8405 | Microsoft | DirectX Graphics Kernel (DXGKRNL) | 7.8 High | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2017-0213 | Microsoft | Windows | 7.3 High | Microsoft Windows Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2017-0059 | Microsoft | Internet Explorer | 4.3 Medium | Microsoft Internet Explorer Information Disclosure Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2017-0037 | Microsoft | Edge and Internet Explorer | 8.1 High | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-7201 | Microsoft | Edge | 8.8 High | Microsoft Edge Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-7200 | Microsoft | Edge | 8.8 High | Microsoft Edge Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2016-0189 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2016-0151 | Microsoft | Client-Server Run-time Subsystem (CSRSS) | 7.8 High | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2016-0040 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-2426 | Microsoft | Windows | 8.8 High | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-2419 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2015-1770 | Microsoft | Office | 8.8 High | Microsoft Office Uninitialized Memory Use Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-3660 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-2729 | Adobe | Reader and Acrobat | 9.8 Critical | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2013-2551 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Use-After-Free Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2013-2465 | Oracle | Java SE | 9.8 Critical | Oracle Java SE Unspecified Vulnerability | 2022-03-28 | 2022-04-18 | Known |
| CVE-2013-1690 | Mozilla | Firefox and Thunderbird | 8.8 High | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-5076 | Oracle | Java SE | 9.8 Critical | Oracle Java SE Sandbox Bypass Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-2539 | Microsoft | Word | 7.8 High | Microsoft Word Remote Code Execution Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |
| CVE-2012-2034 | Adobe | Flash Player | 7.5 High | Adobe Flash Player Memory Corruption Vulnerability | 2022-03-28 | 2022-04-18 | Unknown |