Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-24472 | Fortinet | FortiOS and FortiProxy | 8.1 High | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | 2025-03-18 | 2025-04-08 | Known |
| CVE-2025-24201 | Apple | Multiple Products | 10.0 Critical | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | 2025-03-13 | 2025-04-03 | Unknown |
| CVE-2025-21590 | Juniper | Junos OS | 6.7 Medium | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | 2025-03-13 | 2025-04-03 | Unknown |
| CVE-2025-26633 | Microsoft | Windows | 7.0 High | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability | 2025-03-11 | 2025-04-01 | Known |
| CVE-2025-24993 | Microsoft | Windows | 7.8 High | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24991 | Microsoft | Windows | 5.5 Medium | Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24985 | Microsoft | Windows | 7.8 High | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24984 | Microsoft | Windows | 4.6 Medium | Microsoft Windows NTFS Information Disclosure Vulnerability | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24983 | Microsoft | Windows | 7.0 High | Microsoft Windows Win32k Use-After-Free Vulnerability | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-25181 | Advantive | VeraCore | 7.5 High | Advantive VeraCore SQL Injection Vulnerability | 2025-03-10 | 2025-03-31 | Unknown |
| CVE-2024-57968 | Advantive | VeraCore | 8.8 High | Advantive VeraCore Unrestricted File Upload Vulnerability | 2025-03-10 | 2025-03-31 | Unknown |
| CVE-2024-13161 | Ivanti | Endpoint Manager (EPM) | 7.5 High | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | 2025-03-31 | Unknown |
| CVE-2024-13160 | Ivanti | Endpoint Manager (EPM) | 7.5 High | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | 2025-03-31 | Unknown |
| CVE-2024-13159 | Ivanti | Endpoint Manager (EPM) | 7.5 High | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | 2025-03-31 | Unknown |
| CVE-2025-22226 | VMware | ESXi, Workstation, and Fusion | 6.0 Medium | VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | 2025-03-04 | 2025-03-25 | Unknown |
| CVE-2025-22225 | VMware | ESXi | 8.2 High | VMware ESXi Arbitrary Write Vulnerability | 2025-03-04 | 2025-03-25 | Known |
| CVE-2025-22224 | VMware | ESXi and Workstation | 8.2 High | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | 2025-03-04 | 2025-03-25 | Unknown |
| CVE-2024-50302 | Linux | Kernel | 5.5 Medium | Linux Kernel Use of Uninitialized Resource Vulnerability | 2025-03-04 | 2025-03-25 | Unknown |
| CVE-2024-4885 | Progress | WhatsUp Gold | 9.8 Critical | Progress WhatsUp Gold Path Traversal Vulnerability | 2025-03-03 | 2025-03-24 | Unknown |
| CVE-2023-20118 | Cisco | Small Business RV Series Routers | 7.2 High | Cisco Small Business RV Series Routers Command Injection Vulnerability | 2025-03-03 | 2025-03-24 | Unknown |
| CVE-2022-43939 | Hitachi Vantara | Pentaho Business Analytics (BA) Server | 9.8 Critical | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability | 2025-03-03 | 2025-03-24 | Unknown |
| CVE-2022-43769 | Hitachi Vantara | Pentaho Business Analytics (BA) Server | 7.2 High | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability | 2025-03-03 | 2025-03-24 | Unknown |
| CVE-2018-8639 | Microsoft | Windows | 7.8 High | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability | 2025-03-03 | 2025-03-24 | Known |
| CVE-2024-49035 | Microsoft | Partner Center | 9.8 Critical | Microsoft Partner Center Improper Access Control Vulnerability | 2025-02-25 | 2025-03-18 | Unknown |
| CVE-2023-34192 | Synacor | Zimbra Collaboration Suite (ZCS) | 9.0 Critical | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 2025-02-25 | 2025-03-18 | Unknown |
| CVE-2024-20953 | Oracle | Agile Product Lifecycle Management (PLM) | 8.8 High | Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability | 2025-02-24 | 2025-03-17 | Unknown |
| CVE-2017-3066 | Adobe | ColdFusion | 9.8 Critical | Adobe ColdFusion Deserialization Vulnerability | 2025-02-24 | 2025-03-17 | Unknown |
| CVE-2025-24989 | Microsoft | Power Pages | 9.8 Critical | Microsoft Power Pages Improper Access Control Vulnerability | 2025-02-21 | 2025-03-14 | Unknown |
| CVE-2025-23209 | Craft CMS | Craft CMS | 8.1 High | Craft CMS Code Injection Vulnerability | 2025-02-20 | 2025-03-13 | Unknown |
| CVE-2025-0111 | Palo Alto Networks | PAN-OS | 7.1 High | Palo Alto Networks PAN-OS File Read Vulnerability | 2025-02-20 | 2025-03-13 | Unknown |
| CVE-2025-0108 | Palo Alto Networks | PAN-OS | 8.8 High | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 2025-02-18 | 2025-03-11 | Unknown |
| CVE-2024-53704 | SonicWall | SonicOS | 9.8 Critical | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | 2025-02-18 | 2025-03-11 | Known |
| CVE-2024-57727 | SimpleHelp | SimpleHelp | 7.5 High | SimpleHelp Path Traversal Vulnerability | 2025-02-13 | 2025-03-06 | Known |
| CVE-2025-24200 | Apple | iOS and iPadOS | 6.1 Medium | Apple iOS and iPadOS Incorrect Authorization Vulnerability | 2025-02-12 | 2025-03-05 | Unknown |
| CVE-2024-41710 | Mitel | SIP Phones | 7.2 High | Mitel SIP Phones Argument Injection Vulnerability | 2025-02-12 | 2025-03-05 | Unknown |
| CVE-2025-21418 | Microsoft | Windows | 7.8 High | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2025-21391 | Microsoft | Windows | 7.1 High | Microsoft Windows Storage Link Following Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-40891 | Zyxel | DSL CPE Devices | 8.8 High | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-40890 | Zyxel | DSL CPE Devices | 8.8 High | Zyxel DSL CPE OS Command Injection Vulnerability | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2025-0994 | Trimble | Cityworks | 8.6 High | Trimble Cityworks Deserialization Vulnerability | 2025-02-07 | 2025-02-28 | Unknown |
| CVE-2025-0411 | 7-Zip | 7-Zip | 7.0 High | 7-Zip Mark of the Web Bypass Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2024-21413 | Microsoft | Office Outlook | 9.8 Critical | Microsoft Outlook Improper Input Validation Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2022-23748 | Audinate | Dante Discovery | 7.8 High | Dante Discovery Process Control Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2020-29574 | Sophos | CyberoamOS | 9.8 Critical | CyberoamOS (CROS) SQL Injection Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2020-15069 | Sophos | XG Firewall | 9.8 Critical | Sophos XG Firewall Buffer Overflow Vulnerability | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2024-53104 | Linux | Kernel | 7.8 High | Linux Kernel Out-of-Bounds Write Vulnerability | 2025-02-05 | 2025-02-26 | Unknown |
| CVE-2024-45195 | Apache | OFBiz | 7.5 High | Apache OFBiz Forced Browsing Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2024-29059 | Microsoft | .NET Framework | 7.5 High | Microsoft .NET Framework Information Disclosure Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2018-9276 | Paessler | PRTG Network Monitor | 7.2 High | Paessler PRTG Network Monitor OS Command Injection Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2018-19410 | Paessler | PRTG Network Monitor | 9.8 Critical | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | 2025-02-04 | 2025-02-25 | Unknown |