Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2018-20250 | RARLAB | WinRAR | 7.8 High | WinRAR Absolute Path Traversal Vulnerability | 2022-02-15 | 2022-08-15 | Known |
| CVE-2018-15982 | Adobe | Flash Player | 7.8 High | Adobe Flash Player Use-After-Free Vulnerability | 2022-02-15 | 2022-08-15 | Known |
| CVE-2017-9841 | PHPUnit | PHPUnit | 9.8 Critical | PHPUnit Command Injection Vulnerability | 2022-02-15 | 2022-08-15 | Unknown |
| CVE-2014-1761 | Microsoft | Word | 7.8 High | Microsoft Word Memory Corruption Vulnerability | 2022-02-15 | 2022-08-15 | Unknown |
| CVE-2013-3906 | Microsoft | Graphics Component | 7.8 High | Microsoft Graphics Component Memory Corruption Vulnerability | 2022-02-15 | 2022-08-15 | Unknown |
| CVE-2022-22620 | Apple | iOS, iPadOS, and macOS | 8.8 High | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | 2022-02-11 | 2022-02-25 | Unknown |
| CVE-2021-36934 | Microsoft | Windows | 7.8 High | Microsoft Windows SAM Local Privilege Escalation Vulnerability | 2022-02-10 | 2022-02-24 | Unknown |
| CVE-2020-0796 | Microsoft | SMBv3 | 10.0 Critical | Microsoft SMBv3 Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Known |
| CVE-2018-1000861 | Jenkins | Jenkins Stapler Web Framework | 9.8 Critical | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2017-9791 | Apache | Struts 1 | 9.8 Critical | Apache Struts 1 Improper Input Validation Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2017-8464 | Microsoft | Windows | 8.8 High | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2017-10271 | Oracle | WebLogic Server | 7.5 High | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Known |
| CVE-2017-0263 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2017-0262 | Microsoft | Office | 7.8 High | Microsoft Office Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2017-0145 | Microsoft | SMBv1 | 8.8 High | Microsoft SMBv1 Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Known |
| CVE-2017-0144 | Microsoft | SMBv1 | 8.8 High | Microsoft SMBv1 Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Known |
| CVE-2016-3088 | Apache | ActiveMQ | 9.8 Critical | Apache ActiveMQ Improper Input Validation Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2015-2051 | D-Link | DIR-645 Router | 8.8 High | D-Link DIR-645 Router Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2015-1635 | Microsoft | HTTP.sys | 9.8 Critical | Microsoft HTTP.sys Remote Code Execution Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2015-1130 | Apple | OS X | 7.8 High | Apple OS X Authentication Bypass Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2014-4404 | Apple | OS X | 7.8 High | Apple OS X Heap-Based Buffer Overflow Vulnerability | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2022-21882 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-02-04 | 2022-02-18 | Known |
| CVE-2022-22587 | Apple | iOS and macOS | 9.8 Critical | Apple Memory Corruption Vulnerability | 2022-01-28 | 2022-02-11 | Unknown |
| CVE-2021-20038 | SonicWall | SMA 100 Appliances | 9.8 Critical | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | 2022-01-28 | 2022-02-11 | Known |
| CVE-2020-5722 | Grandstream | UCM6200 | 9.8 Critical | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2020-0787 | Microsoft | Windows | 7.8 High | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | 2022-01-28 | 2022-07-28 | Known |
| CVE-2017-5689 | Intel | Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | 9.8 Critical | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-7169 | GNU | Bourne-Again Shell (Bash) | 9.8 Critical | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-6271 | GNU | Bourne-Again Shell (Bash) | 9.8 Critical | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2014-1776 | Microsoft | Internet Explorer | 9.8 Critical | Microsoft Internet Explorer Memory Corruption Vulnerability | 2022-01-28 | 2022-07-28 | Unknown |
| CVE-2021-35247 | SolarWinds | Serv-U | 5.3 Medium | SolarWinds Serv-U Improper Input Validation Vulnerability | 2022-01-21 | 2022-02-04 | Unknown |
| CVE-2018-8453 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-01-21 | 2022-07-21 | Known |
| CVE-2012-0391 | Apache | Struts 2 | 9.8 Critical | Apache Struts 2 Improper Input Validation Vulnerability | 2022-01-21 | 2022-07-21 | Unknown |
| CVE-2006-1547 | Apache | Struts 1 | 7.5 High | Apache Struts 1 ActionForm Denial-of-Service Vulnerability | 2022-01-21 | 2022-07-21 | Unknown |
| CVE-2021-40870 | Aviatrix | Aviatrix Controller | 9.8 Critical | Aviatrix Controller Unrestricted Upload of File | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-33766 | Microsoft | Exchange Server | 7.3 High | Microsoft Exchange Server Information Disclosure | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-32648 | October CMS | October CMS | 9.1 Critical | October CMS Improper Authentication | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25298 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25297 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-25296 | Nagios | Nagios XI | 8.8 High | Nagios XI OS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-22991 | F5 | BIG-IP Traffic Management Microkernel | 9.8 Critical | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2021-21975 | VMware | vRealize Operations Manager API | 7.5 High | VMware Server Side Request Forgery in vRealize Operations Manager API | 2022-01-18 | 2022-02-01 | Known |
| CVE-2021-21315 | Npm package | System Information Library for Node.JS | 7.8 High | System Information Library for Node.JS Command Injection | 2022-01-18 | 2022-02-01 | Unknown |
| CVE-2020-14864 | Oracle | Intelligence Enterprise Edition | 7.5 High | Oracle Business Intelligence Enterprise Edition Path Transversal | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-13927 | Apache | Airflow's Experimental API | 9.8 Critical | Apache Airflow's Experimental API Authentication Bypass | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-13671 | Drupal | Drupal core | 8.8 High | Drupal core Un-restricted Upload of File | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2020-11978 | Apache | Airflow | 8.8 High | Apache Airflow Command Injection | 2022-01-18 | 2022-07-18 | Unknown |
| CVE-2021-36260 | Hikvision | Security cameras web server | 9.8 Critical | Hikvision Improper Input Validation | 2022-01-10 | 2022-01-24 | Unknown |
| CVE-2021-27860 | FatPipe | WARP, IPVPN, and MPVPN software | 8.8 High | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | 2022-01-10 | 2022-01-24 | Unknown |
| CVE-2021-22017 | VMware | vCenter Server | 5.3 Medium | VMware vCenter Server Improper Access Control | 2022-01-10 | 2022-01-24 | Unknown |