Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-33634 | Aquasecurity | Trivy | 9.4 Critical | Aquasecurity Trivy Embedded Malicious Code Vulnerability | 2026-03-26 | 2026-04-09 | Unknown |
| CVE-2026-33017 | Langflow | Langflow | 9.3 Critical | Langflow Code Injection Vulnerability | 2026-03-25 | 2026-04-08 | Unknown |
| CVE-2025-54068 | Laravel | Livewire | 9.2 Critical | Laravel Livewire Code Injection Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-43520 | Apple | Multiple Products | 5.5 Medium | Apple Multiple Products Classic Buffer Overflow Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-43510 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Improper Locking Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-32432 | Craft CMS | Craft CMS | 10.0 Critical | Craft CMS Code Injection Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-31277 | Apple | Multiple Products | 8.8 High | Apple Multiple Products Buffer Overflow Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2026-20131 | Cisco | Secure Firewall Management Center (FMC) | 10.0 Critical | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | 2026-03-19 | 2026-03-22 | Known |
| CVE-2026-20963 | Microsoft | SharePoint | 9.8 Critical | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-03-18 | 2026-03-21 | Unknown |
| CVE-2025-66376 | Synacor | Zimbra Collaboration Suite (ZCS) | 6.1 Medium | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | 2026-03-18 | 2026-04-01 | Unknown |
| CVE-2025-47813 | Wing FTP Server | Wing FTP Server | 4.3 Medium | Wing FTP Server Information Disclosure Vulnerability | 2026-03-16 | 2026-03-30 | Unknown |
| CVE-2026-3910 | Chromium V8 | 8.8 High | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | 2026-03-13 | 2026-03-27 | Unknown | |
| CVE-2026-3909 | Skia | 8.8 High | Google Skia Out-of-Bounds Write Vulnerability | 2026-03-13 | 2026-03-27 | Unknown | |
| CVE-2025-68613 | n8n | n8n | 8.8 High | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability | 2026-03-11 | 2026-03-25 | Unknown |
| CVE-2026-1603 | Ivanti | Endpoint Manager (EPM) | 7.5 High | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | 2026-03-09 | 2026-03-23 | Unknown |
| CVE-2025-26399 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 2026-03-09 | 2026-03-12 | Unknown |
| CVE-2021-22054 | Omnissa | Workspace One UEM | 7.5 High | Omnissa Workspace ONE Server-Side Request Forgery | 2026-03-09 | 2026-03-23 | Unknown |
| CVE-2023-43000 | Apple | Multiple Products | 8.8 High | Apple Multiple products Use-After-Free Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2023-41974 | Apple | iOS and iPadOS | 7.8 High | Apple iOS and iPadOS Use-After-Free Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2021-30952 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2021-22681 | Rockwell | Multiple Products | 9.8 Critical | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2017-7921 | Hikvision | Multiple Products | 9.8 Critical | Hikvision Multiple Products Improper Authentication Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2026-22719 | Broadcom | VMware Aria Operations | 8.1 High | Broadcom VMware Aria Operations Command Injection Vulnerability | 2026-03-03 | 2026-03-24 | Unknown |
| CVE-2026-21385 | Qualcomm | Multiple Chipsets | 7.8 High | Qualcomm Multiple Chipsets Memory Corruption Vulnerability | 2026-03-03 | 2026-03-24 | Unknown |
| CVE-2026-20127 | Cisco | Catalyst SD-WAN Controller and Manager | 10.0 Critical | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | 2026-02-25 | 2026-02-27 | Unknown |
| CVE-2022-20775 | Cisco | SD-WAN | 7.8 High | Cisco SD-WAN Path Traversal Vulnerability | 2026-02-25 | 2026-02-27 | Unknown |
| CVE-2026-25108 | Soliton Systems K.K | FileZen | 8.7 High | Soliton Systems K.K FileZen OS Command Injection Vulnerability | 2026-02-24 | 2026-03-17 | Unknown |
| CVE-2025-68461 | Roundcube | Webmail | 6.1 Medium | RoundCube Webmail Cross-site Scripting Vulnerability | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2025-49113 | Roundcube | Webmail | 8.8 High | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2026-22769 | Dell | RecoverPoint for Virtual Machines (RP4VMs) | 10.0 Critical | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | 2026-02-18 | 2026-02-21 | Unknown |
| CVE-2021-22175 | GitLab | GitLab | 9.8 Critical | GitLab Server-Side Request Forgery (SSRF) Vulnerability | 2026-02-18 | 2026-03-11 | Unknown |
| CVE-2026-2441 | Chromium | 8.8 High | Google Chromium CSS Use-After-Free Vulnerability | 2026-02-17 | 2026-03-10 | Unknown | |
| CVE-2024-7694 | TeamT5 | ThreatSonar Anti-Ransomware | 7.2 High | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2020-7796 | Synacor | Zimbra Collaboration Suite | 9.8 Critical | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2008-0015 | Microsoft | Windows | 8.8 High | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2026-1731 | BeyondTrust | Remote Support (RS) and Privileged Remote Access (PRA) | 9.9 Critical | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | 2026-02-13 | 2026-02-16 | Known |
| CVE-2026-20700 | Apple | Multiple Products | 7.8 High | Apple Multiple Buffer Overflow Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2025-40536 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Security Control Bypass Vulnerability | 2026-02-12 | 2026-02-15 | Unknown |
| CVE-2025-15556 | Notepad++ | Notepad++ | 7.7 High | Notepad++ Download of Code Without Integrity Check Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2024-43468 | Microsoft | Configuration Manager | 9.8 Critical | Microsoft Configuration Manager SQL Injection Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2026-21533 | Microsoft | Windows | 7.8 High | Microsoft Windows Improper Privilege Management Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21525 | Microsoft | Windows | 6.2 Medium | Microsoft Windows NULL Pointer Dereference Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21519 | Microsoft | Windows | 7.8 High | Microsoft Windows Type Confusion Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21514 | Microsoft | Office | 7.8 High | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21513 | Microsoft | Windows | 8.8 High | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21510 | Microsoft | Windows | 8.8 High | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-24423 | SmarterTools | SmarterMail | 9.3 Critical | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | 2026-02-05 | 2026-02-26 | Known |
| CVE-2025-11953 | React Native Community | CLI | 9.8 Critical | React Native Community CLI OS Command Injection Vulnerability | 2026-02-05 | 2026-02-26 | Unknown |
| CVE-2025-64328 | Sangoma | FreePBX | 8.6 High | Sangoma FreePBX OS Command Injection Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2025-40551 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 2026-02-03 | 2026-02-06 | Unknown |