Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2024-8069 | Citrix | Session Recording | 5.1 Medium | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | 2025-08-25 | 2025-09-15 | Unknown |
| CVE-2024-8068 | Citrix | Session Recording | 5.1 Medium | Citrix Session Recording Improper Privilege Management Vulnerability | 2025-08-25 | 2025-09-15 | Unknown |
| CVE-2025-43300 | Apple | iOS, iPadOS, and macOS | 10.0 Critical | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | 2025-08-21 | 2025-09-11 | Unknown |
| CVE-2025-54948 | Trend Micro | Apex One | 9.8 Critical | Trend Micro Apex One OS Command Injection Vulnerability | 2025-08-18 | 2025-09-08 | Unknown |
| CVE-2025-8876 | N-able | N-Central | 9.4 Critical | N-able N-Central Command Injection Vulnerability | 2025-08-13 | 2025-08-20 | Unknown |
| CVE-2025-8875 | N-able | N-Central | 9.4 Critical | N-able N-Central Insecure Deserialization Vulnerability | 2025-08-13 | 2025-08-20 | Unknown |
| CVE-2025-8088 | RARLAB | WinRAR | 8.4 High | RARLAB WinRAR Path Traversal Vulnerability | 2025-08-12 | 2025-09-02 | Unknown |
| CVE-2013-3893 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Resource Management Errors Vulnerability | 2025-08-12 | 2025-09-02 | Unknown |
| CVE-2007-0671 | Microsoft | Office | 8.8 High | Microsoft Office Excel Remote Code Execution Vulnerability | 2025-08-12 | 2025-09-02 | Unknown |
| CVE-2022-40799 | D-Link | DNR-322L | 8.8 High | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2020-25079 | D-Link | DCS-2530L and DCS-2670L Devices | 8.8 High | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2020-25078 | D-Link | DCS-2530L and DCS-2670L Devices | 7.5 High | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2025-20337 | Cisco | Identity Services Engine | 10.0 Critical | Cisco Identity Services Engine Injection Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2025-20281 | Cisco | Identity Services Engine | 10.0 Critical | Cisco Identity Services Engine Injection Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2023-2533 | PaperCut | NG/MF | 8.8 High | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2025-6558 | Chromium | 8.8 High | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability | 2025-07-22 | 2025-08-12 | Unknown | |
| CVE-2025-54309 | CrushFTP | CrushFTP | 9.8 Critical | CrushFTP Unprotected Alternate Channel Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-49706 | Microsoft | SharePoint | 6.5 Medium | Microsoft SharePoint Improper Authentication Vulnerability | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-49704 | Microsoft | SharePoint | 8.8 High | Microsoft SharePoint Code Injection Vulnerability | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-2776 | SysAid | SysAid On-Prem | 9.8 Critical | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-2775 | SysAid | SysAid On-Prem | 7.5 High | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-53770 | Microsoft | SharePoint | 9.8 Critical | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2025-07-20 | 2025-07-21 | Known |
| CVE-2025-25257 | Fortinet | FortiWeb | 9.8 Critical | Fortinet FortiWeb SQL Injection Vulnerability | 2025-07-18 | 2025-08-08 | Unknown |
| CVE-2025-47812 | Wing FTP Server | Wing FTP Server | 10.0 Critical | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | 2025-07-14 | 2025-08-04 | Unknown |
| CVE-2025-5777 | Citrix | NetScaler ADC and Gateway | 9.3 Critical | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | 2025-07-10 | 2025-07-11 | Known |
| CVE-2019-9621 | Synacor | Zimbra Collaboration Suite (ZCS) | 7.5 High | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2019-5418 | Rails | Ruby on Rails | 7.5 High | Rails Ruby on Rails Path Traversal Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2016-10033 | PHP | PHPMailer | 9.8 Critical | PHPMailer Command Injection Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2014-3931 | Looking Glass | Multi-Router Looking Glass (MRLG) | 9.8 Critical | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2025-6554 | Chromium V8 | 8.1 High | Google Chromium V8 Type Confusion Vulnerability | 2025-07-02 | 2025-07-23 | Unknown | |
| CVE-2025-48928 | TeleMessage | TM SGNL | 4.0 Medium | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability | 2025-07-01 | 2025-07-22 | Unknown |
| CVE-2025-48927 | TeleMessage | TM SGNL | 5.3 Medium | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | 2025-07-01 | 2025-07-22 | Unknown |
| CVE-2025-6543 | Citrix | NetScaler ADC and Gateway | 9.2 Critical | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | 2025-06-30 | 2025-07-21 | Unknown |
| CVE-2024-54085 | AMI | MegaRAC SPx | 10.0 Critical | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | 2025-06-25 | 2025-07-16 | Unknown |
| CVE-2024-0769 | D-Link | DIR-859 Router | 9.8 Critical | D-Link DIR-859 Router Path Traversal Vulnerability | 2025-06-25 | 2025-07-16 | Unknown |
| CVE-2019-6693 | Fortinet | FortiOS | 6.5 Medium | Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | 2025-06-25 | 2025-07-16 | Known |
| CVE-2023-0386 | Linux | Kernel | 7.8 High | Linux Kernel Improper Ownership Management Vulnerability | 2025-06-17 | 2025-07-08 | Unknown |
| CVE-2025-43200 | Apple | Multiple Products | 4.2 Medium | Apple Multiple Products Unspecified Vulnerability | 2025-06-16 | 2025-07-07 | Unknown |
| CVE-2023-33538 | TP-Link | Multiple Routers | 8.8 High | TP-Link Multiple Routers Command Injection Vulnerability | 2025-06-16 | 2025-07-07 | Unknown |
| CVE-2025-33053 | Microsoft | Windows | 8.8 High | Microsoft Windows External Control of File Name or Path Vulnerability | 2025-06-10 | 2025-07-01 | Unknown |
| CVE-2025-24016 | Wazuh | Wazuh Server | 9.9 Critical | Wazuh Server Deserialization of Untrusted Data Vulnerability | 2025-06-10 | 2025-07-01 | Unknown |
| CVE-2025-32433 | Erlang | Erlang/OTP | 10.0 Critical | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | 2025-06-09 | 2025-06-30 | Unknown |
| CVE-2024-42009 | Roundcube | Webmail | 9.3 Critical | RoundCube Webmail Cross-Site Scripting Vulnerability | 2025-06-09 | 2025-06-30 | Unknown |
| CVE-2025-5419 | Chromium V8 | 8.8 High | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | 2025-06-05 | 2025-06-26 | Unknown | |
| CVE-2025-27038 | Qualcomm | Multiple Chipsets | 7.5 High | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-21480 | Qualcomm | Multiple Chipsets | 8.6 High | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-21479 | Qualcomm | Multiple Chipsets | 8.6 High | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-3935 | ConnectWise | ScreenConnect | 7.2 High | ConnectWise ScreenConnect Improper Authentication Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2025-35939 | Craft CMS | Craft CMS | 6.9 Medium | Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2024-56145 | Craft CMS | Craft CMS | 9.3 Critical | Craft CMS Code Injection Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |