Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2020-1020 | Microsoft | Windows | 8.8 High | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10199 | Sonatype | Nexus Repository | 8.8 High | Sonatype Nexus Repository Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10189 | Zoho | ManageEngine | 9.8 Critical | Zoho ManageEngine Desktop Central File Upload Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10181 | Sumavision | Enhanced Multimedia Router (EMR) | 9.8 Critical | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10148 | SolarWinds | Orion | 9.8 Critical | SolarWinds Orion Authentication Bypass Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0986 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel Privilege Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0968 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0938 | Microsoft | Windows | 7.8 High | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0878 | Microsoft | Edge and Internet Explorer | 4.2 Medium | Microsoft Edge and Internet Explorer Memory Corruption Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2020-0688 | Microsoft | Exchange Server | 8.8 High | Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2020-0683 | Microsoft | Windows | 7.8 High | Microsoft Windows Installer Privilege Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0674 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0646 | Microsoft | .NET Framework | 9.8 Critical | Microsoft .NET Framework Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0601 | Microsoft | Windows | 8.1 High | Microsoft Windows CryptoAPI Spoofing Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0069 | MediaTek | Multiple Chipsets | 7.8 High | Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-0041 | Android | Android Kernel | 7.8 High | Android Kernel Out-of-Bounds Write Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-9978 | WordPress | Social Warfare Plugin | 6.1 Medium | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-9082 | ThinkPHP | ThinkPHP | 8.8 High | ThinkPHP Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-8394 | Zoho | ManageEngine | 6.5 Medium | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-7481 | SonicWall | SMA100 | 7.5 High | SonicWall SMA100 SQL Injection Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-6223 | Apple | iOS and macOS | 7.5 High | Apple iOS and macOS Group Facetime Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-5591 | Fortinet | FortiOS | 6.5 Medium | Fortinet FortiOS Default Configuration Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-5544 | VMware | VMware ESXi and Horizon DaaS | 9.8 Critical | VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-4716 | IBM | Planning Analytics | 9.8 Critical | IBM Planning Analytics Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-3398 | Atlassian | Confluence Server and Data Center | 8.8 High | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-3396 | Atlassian | Confluence Server and Data Server | 9.8 Critical | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-2215 | Android | Android Kernel | 7.8 High | Android Kernel Use-After-Free Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-20085 | TVT | NVMS-1000 | 7.5 High | TVT NVMS-1000 Directory Traversal Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-19781 | Citrix | Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | 9.8 Critical | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-19356 | Netis | WF2419 Devices | 7.5 High | Netis WF2419 Devices Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18988 | TeamViewer | Desktop | 7.0 High | TeamViewer Desktop Bypass Remote Login Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18935 | Progress | Telerik UI for ASP.NET AJAX | 9.8 Critical | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-18187 | Trend Micro | OfficeScan | 7.5 High | Trend Micro OfficeScan Directory Traversal Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-17558 | Apache | Solr | 7.5 High | Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-17026 | Mozilla | Firefox and Thunderbird | 8.8 High | Mozilla Firefox And Thunderbird Type Confusion Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-16759 | vBulletin | vBulletin | 9.8 Critical | vBulletin PHP Module Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-1653 | Cisco | Small Business RV320 and RV325 Routers | 7.5 High | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-16256 | SIMalliance | Toolbox Browser | 9.8 Critical | SIMalliance Toolbox Browser Command Injection Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-15949 | Nagios | Nagios XI | 8.8 High | Nagios XI Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-15752 | Docker | Desktop Community Edition | 7.8 High | Docker Desktop Community Edition Privilege Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-1429 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-1367 | Microsoft | Internet Explorer | 7.5 High | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-13608 | Citrix | StoreFront Server | 7.5 High | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-1215 | Microsoft | Windows | 7.8 High | Microsoft Windows Privilege Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-1214 | Microsoft | Windows | 7.8 High | Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-11634 | Citrix | Workspace Application and Receiver for Windows | 9.8 Critical | Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-11580 | Atlassian | Crowd and Crowd Data Center | 9.8 Critical | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-11539 | Ivanti | Pulse Connect Secure and Pulse Policy Secure | 7.2 High | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-11510 | Ivanti | Pulse Connect Secure | 10.0 Critical | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-0863 | Microsoft | Windows | 7.8 High | Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability | 2021-11-03 | 2022-05-03 | Unknown |