Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2014-6278 | GNU | GNU Bash | 8.8 High | GNU Bash OS Command Injection Vulnerability | 2025-10-02 | 2025-10-23 | Unknown |
| CVE-2025-59689 | Libraesva | Email Security Gateway | 6.1 Medium | Libraesva Email Security Gateway Command Injection Vulnerability | 2025-09-29 | 2025-10-20 | Unknown |
| CVE-2025-32463 | Sudo | Sudo | 7.8 High | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 2025-09-29 | 2025-10-20 | Unknown |
| CVE-2025-20352 | Cisco | IOS and IOS XE | 7.7 High | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | 2025-09-29 | 2025-10-20 | Unknown |
| CVE-2025-10035 | Fortra | GoAnywhere MFT | 9.8 Critical | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | 2025-09-29 | 2025-10-20 | Known |
| CVE-2021-21311 | Adminer | Adminer | 7.2 High | Adminer Server-Side Request Forgery Vulnerability | 2025-09-29 | 2025-10-20 | Unknown |
| CVE-2025-20362 | Cisco | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 8.6 High | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | 2025-09-25 | 2025-09-26 | Unknown |
| CVE-2025-20333 | Cisco | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 9.9 Critical | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | 2025-09-25 | 2025-09-26 | Unknown |
| CVE-2025-10585 | Chromium V8 | 9.8 Critical | Google Chromium V8 Type Confusion Vulnerability | 2025-09-23 | 2025-10-14 | Unknown | |
| CVE-2025-5086 | Dassault Systèmes | DELMIA Apriso | 9.0 Critical | Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability | 2025-09-11 | 2025-10-02 | Unknown |
| CVE-2025-53690 | Sitecore | Multiple Products | 9.0 Critical | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | 2025-09-04 | 2025-09-25 | Unknown |
| CVE-2025-48543 | Android | Runtime | 8.8 High | Android Runtime Use-After-Free Vulnerability | 2025-09-04 | 2025-09-25 | Unknown |
| CVE-2025-38352 | Linux | Kernel | 7.4 High | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability | 2025-09-04 | 2025-09-25 | Unknown |
| CVE-2025-9377 | TP-Link | Multiple Routers | 8.6 High | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | 2025-09-03 | 2025-09-24 | Unknown |
| CVE-2023-50224 | TP-Link | TL-WR841N | 6.5 Medium | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | 2025-09-03 | 2025-09-24 | Unknown |
| CVE-2025-55177 | Meta Platforms | 5.4 Medium | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | 2025-09-02 | 2025-09-23 | Unknown | |
| CVE-2020-24363 | TP-Link | TL-WA855RE | 8.8 High | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | 2025-09-02 | 2025-09-23 | Unknown |
| CVE-2025-57819 | Sangoma | FreePBX | 10.0 Critical | Sangoma FreePBX Authentication Bypass Vulnerability | 2025-08-29 | 2025-09-19 | Unknown |
| CVE-2025-7775 | Citrix | NetScaler | 9.2 Critical | Citrix NetScaler Memory Overflow Vulnerability | 2025-08-26 | 2025-08-28 | Unknown |
| CVE-2025-48384 | Git | Git | 8.0 High | Git Link Following Vulnerability | 2025-08-25 | 2025-09-15 | Unknown |
| CVE-2024-8069 | Citrix | Session Recording | 5.1 Medium | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | 2025-08-25 | 2025-09-15 | Unknown |
| CVE-2024-8068 | Citrix | Session Recording | 5.1 Medium | Citrix Session Recording Improper Privilege Management Vulnerability | 2025-08-25 | 2025-09-15 | Unknown |
| CVE-2025-43300 | Apple | iOS, iPadOS, and macOS | 10.0 Critical | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | 2025-08-21 | 2025-09-11 | Unknown |
| CVE-2025-54948 | Trend Micro | Apex One | 9.8 Critical | Trend Micro Apex One OS Command Injection Vulnerability | 2025-08-18 | 2025-09-08 | Unknown |
| CVE-2025-8876 | N-able | N-Central | 9.4 Critical | N-able N-Central Command Injection Vulnerability | 2025-08-13 | 2025-08-20 | Unknown |
| CVE-2025-8875 | N-able | N-Central | 9.4 Critical | N-able N-Central Insecure Deserialization Vulnerability | 2025-08-13 | 2025-08-20 | Unknown |
| CVE-2025-8088 | RARLAB | WinRAR | 8.4 High | RARLAB WinRAR Path Traversal Vulnerability | 2025-08-12 | 2025-09-02 | Known |
| CVE-2013-3893 | Microsoft | Internet Explorer | 8.8 High | Microsoft Internet Explorer Resource Management Errors Vulnerability | 2025-08-12 | 2025-09-02 | Unknown |
| CVE-2007-0671 | Microsoft | Office | 8.8 High | Microsoft Office Excel Remote Code Execution Vulnerability | 2025-08-12 | 2025-09-02 | Unknown |
| CVE-2022-40799 | D-Link | DNR-322L | 8.8 High | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2020-25079 | D-Link | DCS-2530L and DCS-2670L Devices | 8.8 High | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2020-25078 | D-Link | DCS-2530L and DCS-2670L Devices | 7.5 High | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | 2025-08-05 | 2025-08-26 | Unknown |
| CVE-2025-20337 | Cisco | Identity Services Engine | 10.0 Critical | Cisco Identity Services Engine Injection Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2025-20281 | Cisco | Identity Services Engine | 10.0 Critical | Cisco Identity Services Engine Injection Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2023-2533 | PaperCut | NG/MF | 8.8 High | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | 2025-07-28 | 2025-08-18 | Unknown |
| CVE-2025-6558 | Chromium | 8.8 High | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability | 2025-07-22 | 2025-08-12 | Unknown | |
| CVE-2025-54309 | CrushFTP | CrushFTP | 9.8 Critical | CrushFTP Unprotected Alternate Channel Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-49706 | Microsoft | SharePoint | 6.5 Medium | Microsoft SharePoint Improper Authentication Vulnerability | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-49704 | Microsoft | SharePoint | 8.8 High | Microsoft SharePoint Code Injection Vulnerability | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-2776 | SysAid | SysAid On-Prem | 9.8 Critical | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-2775 | SysAid | SysAid On-Prem | 7.5 High | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | 2025-07-22 | 2025-08-12 | Unknown |
| CVE-2025-53770 | Microsoft | SharePoint | 9.8 Critical | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2025-07-20 | 2025-07-21 | Known |
| CVE-2025-25257 | Fortinet | FortiWeb | 9.8 Critical | Fortinet FortiWeb SQL Injection Vulnerability | 2025-07-18 | 2025-08-08 | Unknown |
| CVE-2025-47812 | Wing FTP Server | Wing FTP Server | 10.0 Critical | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | 2025-07-14 | 2025-08-04 | Unknown |
| CVE-2025-5777 | Citrix | NetScaler ADC and Gateway | 9.3 Critical | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | 2025-07-10 | 2025-07-11 | Known |
| CVE-2019-9621 | Synacor | Zimbra Collaboration Suite (ZCS) | 7.5 High | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2019-5418 | Rails | Ruby on Rails | 7.5 High | Rails Ruby on Rails Path Traversal Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2016-10033 | PHP | PHPMailer | 9.8 Critical | PHPMailer Command Injection Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2014-3931 | Looking Glass | Multi-Router Looking Glass (MRLG) | 9.8 Critical | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | 2025-07-07 | 2025-07-28 | Unknown |
| CVE-2025-6554 | Chromium V8 | 8.1 High | Google Chromium V8 Type Confusion Vulnerability | 2025-07-02 | 2025-07-23 | Unknown |