Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2020-6572 | Chrome Media | 8.8 High | Google Chrome Media Use-After-Free Vulnerability | 2022-01-10 | 2022-07-10 | Unknown | |
| CVE-2019-9670 | Synacor | Zimbra Collaboration Suite (ZCS) | 9.8 Critical | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2019-7609 | Elastic | Kibana | 10.0 Critical | Kibana Arbitrary Code Execution | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2019-2725 | Oracle | WebLogic Server | 9.8 Critical | Oracle WebLogic Server, Injection | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-1579 | Palo Alto Networks | PAN-OS | 8.1 High | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-1458 | Microsoft | Win32k | 7.8 High | Microsoft Win32k Privilege Escalation Vulnerability | 2022-01-10 | 2022-07-10 | Known |
| CVE-2019-10149 | Exim | Mail Transfer Agent (MTA) | 9.8 Critical | Exim Mail Transfer Agent (MTA) Improper Input Validation | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2018-13383 | Fortinet | FortiOS and FortiProxy | 6.5 Medium | Fortinet FortiOS and FortiProxy Out-of-bounds Write | 2022-01-10 | 2022-07-10 | Known |
| CVE-2018-13382 | Fortinet | FortiOS and FortiProxy | 7.5 High | Fortinet FortiOS and FortiProxy Improper Authorization | 2022-01-10 | 2022-07-10 | Known |
| CVE-2017-1000486 | Primetek | Primefaces Application | 9.8 Critical | Primetek Primefaces Remote Code Execution Vulnerability | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2015-7450 | IBM | WebSphere Application Server and Server Hypervisor Edition | 9.8 Critical | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2013-3900 | Microsoft | WinVerifyTrust function | 5.5 Medium | Microsoft WinVerifyTrust function Remote Code Execution | 2022-01-10 | 2022-07-10 | Unknown |
| CVE-2021-43890 | Microsoft | Windows | 7.1 High | Microsoft Windows AppX Installer Spoofing Vulnerability | 2021-12-15 | 2021-12-29 | Known |
| CVE-2021-4102 | Chromium V8 | 8.8 High | Google Chromium V8 Use-After-Free Vulnerability | 2021-12-15 | 2021-12-29 | Unknown | |
| CVE-2021-44515 | Zoho | Desktop Central | 9.8 Critical | Zoho Desktop Central Authentication Bypass Vulnerability | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2021-44228 | Apache | Log4j2 | 10.0 Critical | Apache Log4j2 Remote Code Execution Vulnerability | 2021-12-10 | 2021-12-24 | Known |
| CVE-2021-44168 | Fortinet | FortiOS | 7.8 High | Fortinet FortiOS Arbitrary File Download | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2021-35394 | Realtek | Jungle Software Development Kit (SDK) | 9.8 Critical | Realtek Jungle SDK Remote Code Execution Vulnerability | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2020-8816 | Pi-hole | AdminLTE | 7.2 High | Pi-Hole AdminLTE Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2020-17463 | Fuel CMS | Fuel CMS | 9.8 Critical | Fuel CMS SQL Injection Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-7238 | Sonatype | Nexus Repository Manager | 9.8 Critical | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-13272 | Linux | Kernel | 7.8 High | Linux Kernel Improper Privilege Management Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-10758 | MongoDB | mongo-express | 9.9 Critical | MongoDB mongo-express Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2019-0193 | Apache | Solr | 7.2 High | Apache Solr DataImportHandler Code Injection Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2017-17562 | Embedthis | GoAhead | 8.1 High | Embedthis GoAhead Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2017-12149 | Red Hat | JBoss Application Server | 9.8 Critical | Red Hat JBoss Application Server Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Known |
| CVE-2010-1871 | Red Hat | JBoss Seam 2 | 8.8 High | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | 2021-12-10 | 2022-06-10 | Unknown |
| CVE-2021-44077 | Zoho | ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | 9.8 Critical | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2021-40438 | Apache | Apache | 9.0 Critical | Apache HTTP Server-Side Request Forgery (SSRF) | 2021-12-01 | 2021-12-15 | Known |
| CVE-2021-37415 | Zoho | ManageEngine ServiceDesk Plus (SDP) | 9.8 Critical | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2020-11261 | Qualcomm | Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 7.8 High | Qualcomm Multiple Chipsets Improper Input Validation Vulnerability | 2021-12-01 | 2022-06-01 | Unknown |
| CVE-2018-14847 | MikroTik | RouterOS | 9.1 Critical | MikroTik Router OS Directory Traversal Vulnerability | 2021-12-01 | 2022-06-01 | Unknown |
| CVE-2021-42321 | Microsoft | Exchange | 8.8 High | Microsoft Exchange Server Remote Code Execution Vulnerability | 2021-11-17 | 2021-12-01 | Known |
| CVE-2021-42292 | Microsoft | Office | 7.8 High | Microsoft Excel Security Feature Bypass | 2021-11-17 | 2021-12-01 | Unknown |
| CVE-2021-40449 | Microsoft | Windows | 7.8 High | Microsoft Windows Win32k Privilege Escalation Vulnerability | 2021-11-17 | 2021-12-01 | Known |
| CVE-2021-22204 | Perl | Exiftool | 7.8 High | ExifTool Remote Code Execution Vulnerability | 2021-11-17 | 2021-12-01 | Unknown |
| CVE-2021-42258 | BQE | BillQuick Web Suite | 9.8 Critical | BQE BillQuick Web Suite SQL Injection Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-42013 | Apache | HTTP Server | 9.8 Critical | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-41773 | Apache | HTTP Server | 9.8 Critical | Apache HTTP Server Path Traversal Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-40539 | Zoho | ManageEngine | 9.8 Critical | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-40444 | Microsoft | MSHTML | 8.8 High | Microsoft MSHTML Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-38649 | Microsoft | Open Management Infrastructure (OMI) | 7.0 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38648 | Microsoft | Open Management Infrastructure (OMI) | 7.8 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38647 | Microsoft | Open Management Infrastructure (OMI) | 9.8 Critical | Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 2021-11-03 | 2021-11-17 | Known |
| CVE-2021-38645 | Microsoft | Open Management Infrastructure (OMI) | 7.8 High | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-38003 | Chromium V8 | 8.8 High | Google Chromium V8 Memory Corruption Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-38000 | Chromium Intents | 6.1 Medium | Google Chromium Intents Improper Input Validation Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37976 | Chromium | 6.5 Medium | Google Chromium Information Disclosure Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37975 | Chromium V8 | 8.8 High | Google Chromium V8 Use-After-Free Vulnerability | 2021-11-03 | 2021-11-17 | Unknown | |
| CVE-2021-37973 | Chromium Portals | 9.6 Critical | Google Chromium Portals Use-After-Free Vulnerability | 2021-11-03 | 2021-11-17 | Unknown |