Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2021-22175 | GitLab | GitLab | 9.8 Critical | GitLab Server-Side Request Forgery (SSRF) Vulnerability | 2026-02-18 | 2026-03-11 | Unknown |
| CVE-2026-2441 | Chromium | 8.8 High | Google Chromium CSS Use-After-Free Vulnerability | 2026-02-17 | 2026-03-10 | Unknown | |
| CVE-2024-7694 | TeamT5 | ThreatSonar Anti-Ransomware | 7.2 High | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2020-7796 | Synacor | Zimbra Collaboration Suite | 9.8 Critical | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2008-0015 | Microsoft | Windows | 8.8 High | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | 2026-02-17 | 2026-03-10 | Unknown |
| CVE-2026-1731 | BeyondTrust | Remote Support (RS) and Privileged Remote Access (PRA) | 9.9 Critical | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | 2026-02-13 | 2026-02-16 | Known |
| CVE-2026-20700 | Apple | Multiple Products | 7.8 High | Apple Multiple Buffer Overflow Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2025-40536 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Security Control Bypass Vulnerability | 2026-02-12 | 2026-02-15 | Unknown |
| CVE-2025-15556 | Notepad++ | Notepad++ | 7.7 High | Notepad++ Download of Code Without Integrity Check Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2024-43468 | Microsoft | Configuration Manager | 9.8 Critical | Microsoft Configuration Manager SQL Injection Vulnerability | 2026-02-12 | 2026-03-05 | Unknown |
| CVE-2026-21533 | Microsoft | Windows | 7.8 High | Microsoft Windows Improper Privilege Management Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21525 | Microsoft | Windows | 6.2 Medium | Microsoft Windows NULL Pointer Dereference Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21519 | Microsoft | Windows | 7.8 High | Microsoft Windows Type Confusion Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21514 | Microsoft | Office | 7.8 High | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21513 | Microsoft | Windows | 8.8 High | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-21510 | Microsoft | Windows | 8.8 High | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | 2026-02-10 | 2026-03-03 | Unknown |
| CVE-2026-24423 | SmarterTools | SmarterMail | 9.3 Critical | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | 2026-02-05 | 2026-02-26 | Known |
| CVE-2025-11953 | React Native Community | CLI | 9.8 Critical | React Native Community CLI OS Command Injection Vulnerability | 2026-02-05 | 2026-02-26 | Unknown |
| CVE-2025-64328 | Sangoma | FreePBX | 8.6 High | Sangoma FreePBX OS Command Injection Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2025-40551 | SolarWinds | Web Help Desk | 9.8 Critical | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | 2026-02-03 | 2026-02-06 | Unknown |
| CVE-2021-39935 | GitLab | Community and Enterprise Editions | 7.5 High | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2019-19006 | Sangoma | FreePBX | 9.8 Critical | Sangoma FreePBX Improper Authentication Vulnerability | 2026-02-03 | 2026-02-24 | Unknown |
| CVE-2026-1281 | Ivanti | Endpoint Manager Mobile (EPMM) | 9.8 Critical | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-01-29 | 2026-02-01 | Unknown |
| CVE-2026-24858 | Fortinet | Multiple Products | 9.8 Critical | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-01-27 | 2026-01-30 | Unknown |
| CVE-2026-24061 | GNU | InetUtils | 9.8 Critical | GNU InetUtils Argument Injection Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2026-23760 | SmarterTools | SmarterMail | 9.3 Critical | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | 2026-01-26 | 2026-02-16 | Known |
| CVE-2026-21509 | Microsoft | Office | 7.8 High | Microsoft Office Security Feature Bypass Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2025-52691 | SmarterTools | SmarterMail | 10.0 Critical | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-01-26 | 2026-02-16 | Known |
| CVE-2018-14634 | Linux | Kernel | 7.8 High | Linux Kernel Integer Overflow Vulnerability | 2026-01-26 | 2026-02-16 | Unknown |
| CVE-2024-37079 | Broadcom | VMware vCenter Server | 9.8 Critical | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | 2026-01-23 | 2026-02-13 | Unknown |
| CVE-2025-68645 | Synacor | Zimbra Collaboration Suite (ZCS) | 8.8 High | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-54313 | Prettier | eslint-config-prettier | 7.5 High | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-34026 | Versa | Concerto | 9.2 Critical | Versa Concerto Improper Authentication Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2025-31125 | Vite | Vitejs | 7.5 High | Vite Vitejs Improper Access Control Vulnerability | 2026-01-22 | 2026-02-12 | Unknown |
| CVE-2026-20045 | Cisco | Unified Communications Manager | 9.8 Critical | Cisco Unified Communications Products Code Injection Vulnerability | 2026-01-21 | 2026-02-11 | Unknown |
| CVE-2026-20805 | Microsoft | Windows | 5.5 Medium | Microsoft Windows Information Disclosure Vulnerability | 2026-01-13 | 2026-02-03 | Unknown |
| CVE-2025-8110 | Gogs | Gogs | 8.7 High | Gogs Path Traversal Vulnerability | 2026-01-12 | 2026-02-02 | Unknown |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) | OneView | 9.8 Critical | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | 2026-01-07 | 2026-01-28 | Unknown |
| CVE-2009-0556 | Microsoft | Office | 8.8 High | Microsoft Office PowerPoint Code Injection Vulnerability | 2026-01-07 | 2026-01-28 | Unknown |
| CVE-2025-14847 | MongoDB | MongoDB and MongoDB Server | 8.7 High | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | 2025-12-29 | 2026-01-19 | Unknown |
| CVE-2023-52163 | Digiever | DS-2105 Pro | 8.8 High | Digiever DS-2105 Pro Missing Authorization Vulnerability | 2025-12-22 | 2026-01-12 | Unknown |
| CVE-2025-14733 | WatchGuard | Firebox | 9.3 Critical | WatchGuard Firebox Out of Bounds Write Vulnerability | 2025-12-19 | 2025-12-26 | Known |
| CVE-2025-59374 | ASUS | Live Update | 9.3 Critical | ASUS Live Update Embedded Malicious Code Vulnerability | 2025-12-17 | 2026-01-07 | Unknown |
| CVE-2025-40602 | SonicWall | SMA1000 appliance | 6.6 Medium | SonicWall SMA1000 Missing Authorization Vulnerability | 2025-12-17 | 2025-12-24 | Unknown |
| CVE-2025-20393 | Cisco | Multiple Products | 10.0 Critical | Cisco Multiple Products Improper Input Validation Vulnerability | 2025-12-17 | 2025-12-24 | Unknown |
| CVE-2025-59718 | Fortinet | Multiple Products | 9.8 Critical | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | 2025-12-16 | 2025-12-23 | Unknown |
| CVE-2025-43529 | Apple | Multiple Products | 8.8 High | Apple Multiple Products Use-After-Free WebKit Vulnerability | 2025-12-15 | 2026-01-05 | Unknown |
| CVE-2025-14611 | Gladinet | CentreStack and Triofox | 7.1 High | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | 2025-12-15 | 2026-01-05 | Unknown |
| CVE-2025-14174 | Chromium | 8.8 High | Google Chromium Out of Bounds Memory Access Vulnerability | 2025-12-12 | 2026-01-02 | Unknown | |
| CVE-2018-4063 | Sierra Wireless | AirLink ALEOS | 8.8 High | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | 2025-12-12 | 2026-01-02 | Unknown |