Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2014-4404 | Apple | OS X | 7.8 High | Apple OS X Heap-Based Buffer Overflow Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2022-21882 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-02-04 | 2022-02-18 | Unknown |
| CVE-2022-22587 | Apple | iOS and macOS | 9.8 Critical | Apple Memory Corruption Vulnerability | 2022-01-28 | 2022-02-11 | Unknown |
| CVE-2021-20038 | SonicWall | SMA 100 Appliances | 9.8 Critical | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | 2022-01-28 | 2022-02-11 | Known |
| CVE-2020-5722 | Grandstream | UCM6200 | 9.8 Critical | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2020-0787 | Microsoft | Windows | 7.8 High | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | 2022-01-28 | 2022-07-28 | Known |
| CVE-2017-5689 | Intel | Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | 9.8 Critical | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-7169 | GNU | Bourne-Again Shell (Bash) | 9.8 Critical | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-6271 | GNU | Bourne-Again Shell (Bash) | 9.8 Critical | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-1776 | Microsoft | Internet Explorer | 9.8 Critical | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2021-35247 | SolarWinds | Serv-U | 5.3 Medium | SolarWinds Serv-U Improper Input Validation Vulnerability | 2022-01-21 | 2022-02-04 | Unknown |
| CVE-2018-8453 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-01-21 | 2022-07-21 | Known |
| CVE-2012-0391 | Apache | Struts 2 | 9.8 Critical | Apache Struts 2 Improper Input Validation Vulnerability | 2022-01-21 | 2022-07-21 | Unknown |
| CVE-2006-1547 | Apache | Struts 1 | 7.5 High | Apache Struts 1 ActionForm Denial-of-Service Vulnerability | 2022-01-21 | 2022-07-21 | Unknown |
| CVE-2021-40870 | Aviatrix | Aviatrix Controller | 9.8 Critical | Aviatrix Controller Unrestricted Upload of File | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-33766 | Microsoft | Exchange Server | 7.3 High | Microsoft Exchange Server Information Disclosure | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-32648 | October CMS | October CMS | 9.1 Critical | October CMS Improper Authentication | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25298 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25297 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25296 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-22991 | F5 | BIG-IP Traffic Management Microkernel | 9.8 Critical | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-21975 | VMware | vRealize Operations Manager API | 7.5 High | VMware Server Side Request Forgery in vRealize Operations Manager API | 2022-01-18 | 2022-02-01 | Known |
| CVE-2021-21315 | Npm package | System Information Library for Node.JS | 7.8 High | System Information Library for Node.JS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2020-14864 | Oracle | Intelligence Enterprise Edition | 7.5 High | Oracle Business Intelligence Enterprise Edition Path Transversal | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-13927 | Apache | Airflow's Experimental API | 9.8 Critical | Apache Airflow's Experimental API Authentication Bypass | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-13671 | Drupal | Drupal core | 8.8 High | Drupal core Un-restricted Upload of File | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-11978 | Apache | Airflow | 8.8 High | Apache Airflow Command Injection | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2021-36260 | Hikvision | Security cameras web server | 9.8 Critical | Hikvision Improper Input Validation | 2022-01-10 | 2022-01-24 | Unknown |
| CVE-2021-27860 | FatPipe | WARP, IPVPN, and MPVPN software | 8.8 High | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | 2022-01-10 | 2022-01-24 | Unknown |
| CVE-2021-22017 | VMware | vCenter Server | 5.3 Medium | VMware vCenter Server Improper Access Control | 2022-01-10 | 2022-01-24 | Unknown |
| CVE-2020-6572 | Chrome Media | 8.8 High | Google Chrome Media Use-After-Free Vulnerability | 2022-01-10 | 2022-07-10 | Unknown | |
| CVE-2019-9670 | Synacor | Zimbra Collaboration Suite (ZCS) | 9.8 Critical | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2019-7609 | Elastic | Kibana | 10.0 Critical | Kibana Arbitrary Code Execution | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2019-2725 | Oracle | WebLogic Server | 9.8 Critical | Oracle WebLogic Server, Injection | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-1579 | Palo Alto Networks | PAN-OS | 8.1 High | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-1458 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-10149 | Exim | Mail Transfer Agent (MTA) | 9.8 Critical | Exim Mail Transfer Agent (MTA) Improper Input Validation | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2018-13383 | Fortinet | FortiOS and FortiProxy | 6.5 Medium | Fortinet FortiOS and FortiProxy Out-of-bounds Write | 2022-01-10 | 2022-07-10 | Known |
| CVE-2018-13382 | Fortinet | FortiOS and FortiProxy | 7.5 High | Fortinet FortiOS and FortiProxy Improper Authorization | 2022-01-10 | 2022-07-10 | Known |
| CVE-2017-1000486 | Primetek | Primefaces Application | 9.8 Critical | Primetek Primefaces Remote Code Execution Vulnerability | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2015-7450 | IBM | WebSphere Application Server and Server Hypervisor Edition | 9.8 Critical | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2013-3900 | Microsoft | WinVerifyTrust function | 5.5 Medium | Microsoft WinVerifyTrust function Remote Code Execution | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2021-43890 | Microsoft | Windows | 7.1 High | Microsoft Windows AppX Installer Spoofing Vulnerability | 2021-12-15 | 2021-12-29 | Known |
| CVE-2021-4102 | Chromium V8 | 8.8 High | Google Chromium V8 Use-After-Free Vulnerability | 2021-12-15 | 2021-12-29 | Unknown | |
| CVE-2021-44515 | Zoho | Desktop Central | 9.8 Critical | Zoho Desktop Central Authentication Bypass Vulnerability | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2021-44228 | Apache | Log4j2 | 10.0 Critical | Apache Log4j2 Remote Code Execution Vulnerability | 2021-12-10 | 2021-12-24 | Known |
| CVE-2021-44168 | Fortinet | FortiOS | 7.8 High | Fortinet FortiOS Arbitrary File Download | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2021-35394 | Realtek | Jungle Software Development Kit (SDK) | 9.8 Critical | Realtek Jungle SDK Remote Code Execution Vulnerability | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2020-8816 | Pi-hole | AdminLTE | 7.2 High | Pi-Hole AdminLTE Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2020-17463 | Fuel CMS | Fuel CMS | 9.8 Critical | Fuel CMS SQL Injection Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |