Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2021-39935 | GitLab | Community and Enterprise Editions | 7.5 High | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2019-19006 | Sangoma | FreePBX | 9.8 Critical | Sangoma FreePBX Improper Authentication Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2026-1281 | Ivanti | Endpoint Manager Mobile (EPMM) | 9.8 Critical | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-01-29 | 2026-02-01 | Unknown |
| CVE-2026-24858 | Fortinet | Multiple Products | 9.8 Critical | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-01-27 | 2026-01-30 | Unknown |
| CVE-2026-24061 | GNU | InetUtils | 9.8 Critical | GNU InetUtils Argument Injection Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2026-23760 | SmarterTools | SmarterMail | 9.3 Critical | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-01-26 | 2026-02-16 | Known |
| CVE-2026-21509 | Microsoft | Office | 7.8 High | Microsoft Office Security Feature Bypass Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2025-52691 | SmarterTools | SmarterMail | 10.0 Critical | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-01-26 | 2026-02-16 | Known |
| CVE-2018-14634 | Linux | Kernel | 7.8 High | Linux Kernel Integer Overflow Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2024-37079 | Broadcom | VMware vCenter Server | 9.8 Critical | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | 2026-01-23 | 2026-02-13 | Unknown |
| CVE-2025-68645 | Synacor | Zimbra Collaboration Suite (ZCS) | 8.8 High | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-54313 | Prettier | eslint-config-prettier | 7.5 High | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-34026 | Versa | Concerto | 9.2 Critical | Versa Concerto Improper Authentication Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-31125 | Vite | Vitejs | 7.5 High | Vite Vitejs Improper Access Control Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2026-20045 | Cisco | Unified Communications Manager | 9.8 Critical | Cisco Unified Communications Products Code Injection Vulnerability | 2026-01-21 | 2026-02-11 | Unknown |
| CVE-2026-20805 | Microsoft | Windows | 5.5 Medium | Microsoft Windows Information Disclosure Vulnerability | 2026-01-13 | 2026-02-03 | Unknown |
| CVE-2025-8110 | Gogs | Gogs | 8.7 High | Gogs Path Traversal Vulnerability | 2026-01-12 | 2026-02-02 | Unknown |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) | OneView | 9.8 Critical | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | 2026-01-07 | 2026-01-28 | Unknown |
| CVE-2009-0556 | Microsoft | Office | 8.8 High | Microsoft Office PowerPoint Code Injection Vulnerability | 2026-01-07 | 2026-01-28 | Unknown |
| CVE-2025-14847 | MongoDB | MongoDB and MongoDB Server | 8.7 High | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | 2025-12-29 | 2026-01-19 | Unknown |
| CVE-2023-52163 | Digiever | DS-2105 Pro | 8.8 High | Digiever DS-2105 Pro Missing Authorization Vulnerability | 2025-12-22 | 2026-01-12 | Unknown |
| CVE-2025-14733 | WatchGuard | Firebox | 9.3 Critical | WatchGuard Firebox Out of Bounds Write Vulnerability | 2025-12-19 | 2025-12-26 | Unknown |
| CVE-2025-59374 | ASUS | Live Update | 9.3 Critical | ASUS Live Update Embedded Malicious Code Vulnerability | 2025-12-17 | 2026-01-07 | Unknown |
| CVE-2025-40602 | SonicWall | SMA1000 appliance | 6.6 Medium | SonicWall SMA1000 Missing Authorization Vulnerability | 2025-12-17 | 2025-12-24 | Unknown |
| CVE-2025-20393 | Cisco | Multiple Products | 10.0 Critical | Cisco Multiple Products Improper Input Validation Vulnerability | 2025-12-17 | 2025-12-24 | Unknown |
| CVE-2025-59718 | Fortinet | Multiple Products | 9.8 Critical | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | 2025-12-16 | 2025-12-23 | Unknown |
| CVE-2025-43529 | Apple | Multiple Products | 8.8 High | Apple Multiple Products Use-After-Free WebKit Vulnerability | 2025-12-15 | 2026-01-05 | Unknown |
| CVE-2025-14611 | Gladinet | CentreStack and Triofox | 7.1 High | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | 2025-12-15 | 2026-01-05 | Unknown |
| CVE-2025-14174 | Chromium | 8.8 High | Google Chromium Out of Bounds Memory Access Vulnerability | 2025-12-12 | 2026-01-02 | Unknown | |
| CVE-2018-4063 | Sierra Wireless | AirLink ALEOS | 8.8 High | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | 2025-12-12 | 2026-01-02 | Unknown |
| CVE-2025-58360 | OSGeo | GeoServer | 9.8 Critical | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability | 2025-12-11 | 2026-01-01 | Unknown |
| CVE-2025-62221 | Microsoft | Windows | 7.8 High | Microsoft Windows Use After Free Vulnerability | 2025-12-09 | 2025-12-30 | Unknown |
| CVE-2025-6218 | RARLAB | WinRAR | 7.8 High | RARLAB WinRAR Path Traversal Vulnerability | 2025-12-09 | 2025-12-30 | Unknown |
| CVE-2025-66644 | Array Networks | ArrayOS AG | 9.8 Critical | Array Networks ArrayOS AG OS Command Injection Vulnerability | 2025-12-08 | 2025-12-29 | Unknown |
| CVE-2022-37055 | D-Link | Routers | 9.8 Critical | D-Link Routers Buffer Overflow Vulnerability | 2025-12-08 | 2025-12-29 | Unknown |
| CVE-2025-55182 | Meta | React Server Components | 10.0 Critical | Meta React Server Components Remote Code Execution Vulnerability | 2025-12-05 | 2025-12-12 | Known |
| CVE-2021-26828 | OpenPLC | ScadaBR | 8.8 High | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | 2025-12-03 | 2025-12-24 | Unknown |
| CVE-2025-48633 | Android | Framework | 5.5 Medium | Android Framework Information Disclosure Vulnerability | 2025-12-02 | 2025-12-23 | Unknown |
| CVE-2025-48572 | Android | Framework | 7.8 High | Android Framework Privilege Escalation Vulnerability | 2025-12-02 | 2025-12-23 | Unknown |
| CVE-2021-26829 | OpenPLC | ScadaBR | 5.4 Medium | OpenPLC ScadaBR Cross-site Scripting Vulnerability | 2025-11-28 | 2025-12-19 | Unknown |
| CVE-2025-61757 | Oracle | Fusion Middleware | 9.8 Critical | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | 2025-11-21 | 2025-12-12 | Unknown |
| CVE-2025-13223 | Chromium V8 | 8.8 High | Google Chromium V8 Type Confusion Vulnerability | 2025-11-19 | 2025-12-10 | Unknown | |
| CVE-2025-58034 | Fortinet | FortiWeb | 7.2 High | Fortinet FortiWeb OS Command Injection Vulnerability | 2025-11-18 | 2025-11-25 | Unknown |
| CVE-2025-64446 | Fortinet | FortiWeb | 9.8 Critical | Fortinet FortiWeb Path Traversal Vulnerability | 2025-11-14 | 2025-11-21 | Unknown |
| CVE-2025-9242 | WatchGuard | Firebox | 9.3 Critical | WatchGuard Firebox Out-of-Bounds Write Vulnerability | 2025-11-12 | 2025-12-03 | Unknown |
| CVE-2025-62215 | Microsoft | Windows | 7.0 High | Microsoft Windows Race Condition Vulnerability | 2025-11-12 | 2025-12-03 | Unknown |
| CVE-2025-12480 | Gladinet | Triofox | 9.1 Critical | Gladinet Triofox Improper Access Control Vulnerability | 2025-11-12 | 2025-12-03 | Unknown |
| CVE-2025-21042 | Samsung | Mobile Devices | 9.8 Critical | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | 2025-11-10 | 2025-12-01 | Unknown |
| CVE-2025-48703 | CWP | Control Web Panel | 9.0 Critical | CWP Control Web Panel OS Command Injection Vulnerability | 2025-11-04 | 2025-11-25 | Unknown |
| CVE-2025-11371 | Gladinet | CentreStack and Triofox | 7.5 High | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | 2025-11-04 | 2025-11-25 | Unknown |