Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-48928 | TeleMessage | TM SGNL | 4.0 Medium | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability | 2025-07-01 | 2025-07-22 | Unknown |
| CVE-2025-48927 | TeleMessage | TM SGNL | 5.3 Medium | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | 2025-07-01 | 2025-07-22 | Unknown |
| CVE-2025-6543 | Citrix | NetScaler ADC and Gateway | 9.2 Critical | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | 2025-06-30 | 2025-07-21 | Unknown |
| CVE-2024-54085 | AMI | MegaRAC SPx | 10.0 Critical | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | 2025-06-25 | 2025-07-16 | Unknown |
| CVE-2024-0769 | D-Link | DIR-859 Router | 9.8 Critical | D-Link DIR-859 Router Path Traversal Vulnerability | 2025-06-25 | 2025-07-16 | Unknown |
| CVE-2019-6693 | Fortinet | FortiOS | 6.5 Medium | Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | 2025-06-25 | 2025-07-16 | Known |
| CVE-2023-0386 | Linux | Kernel | 7.8 High | Linux Kernel Improper Ownership Management Vulnerability | 2025-06-17 | 2025-07-08 | Unknown |
| CVE-2025-43200 | Apple | Multiple Products | 4.2 Medium | Apple Multiple Products Unspecified Vulnerability | 2025-06-16 | 2025-07-07 | Unknown |
| CVE-2023-33538 | TP-Link | Multiple Routers | 8.8 High | TP-Link Multiple Routers Command Injection Vulnerability | 2025-06-16 | 2025-07-07 | Unknown |
| CVE-2025-33053 | Microsoft | Windows | 8.8 High | Microsoft Windows External Control of File Name or Path Vulnerability | 2025-06-10 | 2025-07-01 | Unknown |
| CVE-2025-24016 | Wazuh | Wazuh Server | 9.9 Critical | Wazuh Server Deserialization of Untrusted Data Vulnerability | 2025-06-10 | 2025-07-01 | Unknown |
| CVE-2025-32433 | Erlang | Erlang/OTP | 10.0 Critical | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | 2025-06-09 | 2025-06-30 | Unknown |
| CVE-2024-42009 | Roundcube | Webmail | 9.3 Critical | RoundCube Webmail Cross-Site Scripting Vulnerability | 2025-06-09 | 2025-06-30 | Unknown |
| CVE-2025-5419 | Chromium V8 | 8.8 High | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | 2025-06-05 | 2025-06-26 | Unknown | |
| CVE-2025-27038 | Qualcomm | Multiple Chipsets | 7.5 High | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-21480 | Qualcomm | Multiple Chipsets | 8.6 High | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-21479 | Qualcomm | Multiple Chipsets | 8.6 High | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | 2025-06-03 | 2025-06-24 | Unknown |
| CVE-2025-3935 | ConnectWise | ScreenConnect | 7.2 High | ConnectWise ScreenConnect Improper Authentication Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2025-35939 | Craft CMS | Craft CMS | 6.9 Medium | Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2024-56145 | Craft CMS | Craft CMS | 9.3 Critical | Craft CMS Code Injection Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2023-39780 | ASUS | RT-AX55 Routers | 8.8 High | ASUS RT-AX55 Routers OS Command Injection Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2021-32030 | ASUS | Routers | 9.8 Critical | ASUS Routers Improper Authentication Vulnerability | 2025-06-02 | 2025-06-23 | Unknown |
| CVE-2025-4632 | Samsung | MagicINFO 9 Server | 9.8 Critical | Samsung MagicINFO 9 Server Path Traversal Vulnerability | 2025-05-22 | 2025-06-12 | Unknown |
| CVE-2025-4428 | Ivanti | Endpoint Manager Mobile (EPMM) | 8.8 High | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2025-4427 | Ivanti | Endpoint Manager Mobile (EPMM) | 7.5 High | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2025-27920 | Srimax | Output Messenger | 8.8 High | Srimax Output Messenger Directory Traversal Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2024-27443 | Synacor | Zimbra Collaboration Suite (ZCS) | 6.1 Medium | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2024-11182 | MDaemon | Email Server | 5.3 Medium | MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2023-38950 | ZKTeco | BioTime | 7.5 High | ZKTeco BioTime Path Traversal Vulnerability | 2025-05-19 | 2025-06-09 | Unknown |
| CVE-2025-42999 | SAP | NetWeaver | 9.1 Critical | SAP NetWeaver Deserialization Vulnerability | 2025-05-15 | 2025-06-05 | Known |
| CVE-2024-12987 | DrayTek | Vigor Routers | 6.9 Medium | DrayTek Vigor Routers OS Command Injection Vulnerability | 2025-05-15 | 2025-06-05 | Unknown |
| CVE-2025-32756 | Fortinet | Multiple Products | 9.8 Critical | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | 2025-05-14 | 2025-06-04 | Unknown |
| CVE-2025-32709 | Microsoft | Windows | 7.8 High | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-32706 | Microsoft | Windows | 7.8 High | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-32701 | Microsoft | Windows | 7.8 High | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-30400 | Microsoft | Windows | 7.8 High | Microsoft Windows DWM Core Library Use-After-Free Vulnerability | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-30397 | Microsoft | Windows | 7.5 High | Microsoft Windows Scripting Engine Type Confusion Vulnerability | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-47729 | TeleMessage | TM SGNL | 4.9 Medium | TeleMessage TM SGNL Hidden Functionality Vulnerability | 2025-05-12 | 2025-06-02 | Unknown |
| CVE-2024-6047 | GeoVision | Multiple Devices | 9.8 Critical | GeoVision Devices OS Command Injection Vulnerability | 2025-05-07 | 2025-05-28 | Unknown |
| CVE-2024-11120 | GeoVision | Multiple Devices | 9.8 Critical | GeoVision Devices OS Command Injection Vulnerability | 2025-05-07 | 2025-05-28 | Unknown |
| CVE-2025-27363 | FreeType | FreeType | 8.1 High | FreeType Out-of-Bounds Write Vulnerability | 2025-05-06 | 2025-05-27 | Unknown |
| CVE-2025-3248 | Langflow | Langflow | 9.8 Critical | Langflow Missing Authentication Vulnerability | 2025-05-05 | 2025-05-26 | Known |
| CVE-2025-34028 | Commvault | Command Center | 9.3 Critical | Commvault Command Center Path Traversal Vulnerability | 2025-05-02 | 2025-05-23 | Unknown |
| CVE-2024-58136 | Yiiframework | Yii | 9.8 Critical | Yiiframework Yii Improper Protection of Alternate Path Vulnerability | 2025-05-02 | 2025-05-23 | Unknown |
| CVE-2024-38475 | Apache | HTTP Server | 9.1 Critical | Apache HTTP Server Improper Escaping of Output Vulnerability | 2025-05-01 | 2025-05-22 | Unknown |
| CVE-2023-44221 | SonicWall | SMA100 Appliances | 7.2 High | SonicWall SMA100 Appliances OS Command Injection Vulnerability | 2025-05-01 | 2025-05-22 | Unknown |
| CVE-2025-31324 | SAP | NetWeaver | 9.8 Critical | SAP NetWeaver Unrestricted File Upload Vulnerability | 2025-04-29 | 2025-05-20 | Known |
| CVE-2025-42599 | Qualitia | Active! Mail | 9.8 Critical | Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability | 2025-04-28 | 2025-05-19 | Unknown |
| CVE-2025-3928 | Commvault | Web Server | 8.7 High | Commvault Web Server Unspecified Vulnerability | 2025-04-28 | 2025-05-19 | Unknown |
| CVE-2025-1976 | Broadcom | Brocade Fabric OS | 8.6 High | Broadcom Brocade Fabric OS Code Injection Vulnerability | 2025-04-28 | 2025-05-19 | Unknown |