Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-32975 | Quest | KACE Systems Management Appliance (SMA) | 10.0 Critical | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | 2026-04-20 | 2026-05-04 | Unknown |
| CVE-2025-2749 | Kentico | Kentico Xperience | 7.2 High | Kentico Xperience Path Traversal Vulnerability | 2026-04-20 | 2026-05-04 | Unknown |
| CVE-2024-27199 | JetBrains | TeamCity | 7.3 High | JetBrains TeamCity Relative Path Traversal Vulnerability | 2026-04-20 | 2026-05-04 | Known |
| CVE-2023-27351 | PaperCut | NG/MF | 7.5 High | PaperCut NG/MF Improper Authentication Vulnerability | 2026-04-20 | 2026-05-04 | Known |
| CVE-2026-34197 | Apache | ActiveMQ | 8.8 High | Apache ActiveMQ Improper Input Validation Vulnerability | 2026-04-16 | 2026-04-30 | Unknown |
| CVE-2026-32201 | Microsoft | SharePoint Server | 6.5 Medium | Microsoft SharePoint Server Improper Input Validation Vulnerability | 2026-04-14 | 2026-04-28 | Unknown |
| CVE-2009-0238 | Microsoft | Office | 8.8 High | Microsoft Office Remote Code Execution | 2026-04-14 | 2026-04-28 | Unknown |
| CVE-2026-34621 | Adobe | Acrobat and Reader | 8.6 High | Adobe Acrobat and Reader Prototype Pollution Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2026-21643 | Fortinet | FortiClient EMS | 9.8 Critical | Fortinet FortiClient EMS SQL Injection Vulnerability | 2026-04-13 | 2026-04-16 | Unknown |
| CVE-2025-60710 | Microsoft | Windows | 7.8 High | Microsoft Windows Link Following Vulnerability | 2026-04-13 | 2026-04-27 | Known |
| CVE-2023-36424 | Microsoft | Windows | 7.8 High | Microsoft Windows Out-of-Bounds Read Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2023-21529 | Microsoft | Exchange Server | 8.8 High | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | 2026-04-13 | 2026-04-27 | Known |
| CVE-2020-9715 | Adobe | Acrobat | 7.8 High | Adobe Acrobat Use-After-Free Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2012-1854 | Microsoft | Visual Basic for Applications (VBA) | 7.8 High | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | 2026-04-13 | 2026-04-27 | Unknown |
| CVE-2026-1340 | Ivanti | Endpoint Manager Mobile (EPMM) | 9.8 Critical | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-04-08 | 2026-04-11 | Unknown |
| CVE-2026-35616 | Fortinet | FortiClient EMS | 9.8 Critical | Fortinet FortiClient EMS Improper Access Control Vulnerability | 2026-04-06 | 2026-04-09 | Unknown |
| CVE-2026-3502 | TrueConf | Client | 7.8 High | TrueConf Client Download of Code Without Integrity Check Vulnerability | 2026-04-02 | 2026-04-16 | Unknown |
| CVE-2026-5281 | Dawn | 8.8 High | Google Dawn Use-After-Free Vulnerability | 2026-04-01 | 2026-04-15 | Unknown | |
| CVE-2026-3055 | Citrix | NetScaler | 9.3 Critical | Citrix NetScaler Out-of-Bounds Read Vulnerability | 2026-03-30 | 2026-04-02 | Unknown |
| CVE-2025-53521 | F5 | BIG-IP | 9.3 Critical | F5 BIG-IP Stack-Based Buffer Overflow Vulnerability | 2026-03-27 | 2026-03-30 | Unknown |
| CVE-2026-33634 | Aquasecurity | Trivy | 9.4 Critical | Aquasecurity Trivy Embedded Malicious Code Vulnerability | 2026-03-26 | 2026-04-09 | Unknown |
| CVE-2026-33017 | Langflow | Langflow | 9.3 Critical | Langflow Code Injection Vulnerability | 2026-03-25 | 2026-04-08 | Unknown |
| CVE-2025-54068 | Laravel | Livewire | 9.2 Critical | Laravel Livewire Code Injection Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-43520 | Apple | Multiple Products | 5.5 Medium | Apple Multiple Products Classic Buffer Overflow Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-43510 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Improper Locking Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-32432 | Craft CMS | Craft CMS | 10.0 Critical | Craft CMS Code Injection Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2025-31277 | Apple | Multiple Products | 8.8 High | Apple Multiple Products Buffer Overflow Vulnerability | 2026-03-20 | 2026-04-03 | Unknown |
| CVE-2026-20131 | Cisco | Secure Firewall Management Center (FMC) | 10.0 Critical | Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability | 2026-03-19 | 2026-03-22 | Known |
| CVE-2026-20963 | Microsoft | SharePoint | 9.8 Critical | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-03-18 | 2026-03-21 | Unknown |
| CVE-2025-66376 | Synacor | Zimbra Collaboration Suite (ZCS) | 6.1 Medium | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability | 2026-03-18 | 2026-04-01 | Unknown |
| CVE-2025-47813 | Wing FTP Server | Wing FTP Server | 4.3 Medium | Wing FTP Server Information Disclosure Vulnerability | 2026-03-16 | 2026-03-30 | Unknown |
| CVE-2026-3910 | Chromium V8 | 8.8 High | Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability | 2026-03-13 | 2026-03-27 | Unknown | |
| CVE-2026-3909 | Skia | 8.8 High | Google Skia Out-of-Bounds Write Vulnerability | 2026-03-13 | 2026-03-27 | Unknown | |
| CVE-2025-68613 | n8n | n8n | 8.8 High | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability | 2026-03-11 | 2026-03-25 | Unknown |
| CVE-2026-1603 | Ivanti | Endpoint Manager (EPM) | 7.5 High | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | 2026-03-09 | 2026-03-23 | Unknown |
| CVE-2025-26399 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 2026-03-09 | 2026-03-12 | Known |
| CVE-2021-22054 | Omnissa | Workspace One UEM | 7.5 High | Omnissa Workspace ONE Server-Side Request Forgery | 2026-03-09 | 2026-03-23 | Unknown |
| CVE-2023-43000 | Apple | Multiple Products | 8.8 High | Apple Multiple products Use-After-Free Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2023-41974 | Apple | iOS and iPadOS | 7.8 High | Apple iOS and iPadOS Use-After-Free Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2021-30952 | Apple | Multiple Products | 7.8 High | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2021-22681 | Rockwell | Multiple Products | 9.8 Critical | Rockwell Multiple Products Insufficient Protected Credentials Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2017-7921 | Hikvision | Multiple Products | 9.8 Critical | Hikvision Multiple Products Improper Authentication Vulnerability | 2026-03-05 | 2026-03-26 | Unknown |
| CVE-2026-22719 | Broadcom | VMware Aria Operations | 8.1 High | Broadcom VMware Aria Operations Command Injection Vulnerability | 2026-03-03 | 2026-03-24 | Unknown |
| CVE-2026-21385 | Qualcomm | Multiple Chipsets | 7.8 High | Qualcomm Multiple Chipsets Memory Corruption Vulnerability | 2026-03-03 | 2026-03-24 | Unknown |
| CVE-2026-20127 | Cisco | Catalyst SD-WAN Controller and Manager | 10.0 Critical | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | 2026-02-25 | 2026-02-27 | Unknown |
| CVE-2022-20775 | Cisco | SD-WAN | 7.8 High | Cisco SD-WAN Path Traversal Vulnerability | 2026-02-25 | 2026-02-27 | Unknown |
| CVE-2026-25108 | Soliton Systems K.K | FileZen | 8.7 High | Soliton Systems K.K FileZen OS Command Injection Vulnerability | 2026-02-24 | 2026-03-17 | Unknown |
| CVE-2025-68461 | Roundcube | Webmail | 6.1 Medium | RoundCube Webmail Cross-site Scripting Vulnerability | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2025-49113 | Roundcube | Webmail | 8.8 High | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | 2026-02-20 | 2026-03-13 | Unknown |
| CVE-2026-22769 | Dell | RecoverPoint for Virtual Machines (RP4VMs) | 10.0 Critical | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | 2026-02-18 | 2026-02-21 | Unknown |