Browse
CISA KEV catalog
Search and filter the complete official catalog.
My watchlist
| CVE | Vendor | Product | CVSS | Vulnerability | Added | Due | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-24085 | Apple | Multiple Products | 10.0 Critical | Apple Multiple Products Use-After-Free Vulnerability | 2025-01-29 | 2025-02-19 | Unknown |
| CVE-2025-23006 | SonicWall | SMA1000 Appliances | 9.8 Critical | SonicWall SMA1000 Appliances Deserialization Vulnerability | 2025-01-24 | 2025-02-14 | Known |
| CVE-2020-11023 | JQuery | JQuery | 6.1 Medium | JQuery Cross-Site Scripting (XSS) Vulnerability | 2025-01-23 | 2025-02-13 | Unknown |
| CVE-2024-50603 | Aviatrix | Controllers | 9.8 Critical | Aviatrix Controllers OS Command Injection Vulnerability | 2025-01-16 | 2025-02-06 | Unknown |
| CVE-2025-21335 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21334 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21333 | Microsoft | Windows | 7.8 High | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2024-55591 | Fortinet | FortiOS and FortiProxy | 9.8 Critical | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | 2025-01-14 | 2025-01-21 | Known |
| CVE-2024-12686 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | 7.2 High | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | 2025-01-13 | 2025-02-03 | Unknown |
| CVE-2023-48365 | Qlik | Sense | 9.9 Critical | Qlik Sense HTTP Tunneling Vulnerability | 2025-01-13 | 2025-02-03 | Known |
| CVE-2025-0282 | Ivanti | Connect Secure, Policy Secure, and ZTA Gateways | 9.0 Critical | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 2025-01-08 | 2025-01-15 | Known |
| CVE-2024-55550 | Mitel | MiCollab | 2.7 Low | Mitel MiCollab Path Traversal Vulnerability | 2025-01-07 | 2025-01-28 | Known |
| CVE-2024-41713 | Mitel | MiCollab | 9.1 Critical | Mitel MiCollab Path Traversal Vulnerability | 2025-01-07 | 2025-01-28 | Known |
| CVE-2020-2883 | Oracle | WebLogic Server | 9.8 Critical | Oracle WebLogic Server Unspecified Vulnerability | 2025-01-07 | 2025-01-28 | Unknown |
| CVE-2024-3393 | Palo Alto Networks | PAN-OS | 8.7 High | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | 2024-12-30 | 2025-01-20 | Unknown |
| CVE-2021-44207 | Acclaim Systems | USAHERDS | 8.1 High | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | 2024-12-23 | 2025-01-13 | Unknown |
| CVE-2024-12356 | BeyondTrust | Privileged Remote Access (PRA) and Remote Support (RS) | 9.8 Critical | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | 2024-12-19 | 2024-12-27 | Unknown |
| CVE-2022-23227 | NUUO | NVRmini2 Devices | 9.8 Critical | NUUO NVRmini2 Devices Missing Authentication Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2021-40407 | Reolink | RLC-410W IP Camera | 7.2 High | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2019-11001 | Reolink | Multiple IP Cameras | 7.2 High | Reolink Multiple IP Cameras OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2018-14933 | NUUO | NVRmini Devices | 9.8 Critical | NUUO NVRmini Devices OS Command Injection Vulnerability | 2024-12-18 | 2025-01-08 | Unknown |
| CVE-2024-55956 | Cleo | Multiple Products | 9.8 Critical | Cleo Multiple Products Unauthenticated File Upload Vulnerability | 2024-12-17 | 2025-01-07 | Known |
| CVE-2024-35250 | Microsoft | Windows | 7.8 High | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2024-20767 | Adobe | ColdFusion | 7.4 High | Adobe ColdFusion Improper Access Control Vulnerability | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2024-50623 | Cleo | Multiple Products | 9.8 Critical | Cleo Multiple Products Unrestricted File Upload Vulnerability | 2024-12-13 | 2025-01-03 | Known |
| CVE-2024-49138 | Microsoft | Windows | 7.8 High | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | 2024-12-10 | 2024-12-31 | Unknown |
| CVE-2024-51378 | CyberPersons | CyberPanel | 9.8 Critical | CyberPanel Incorrect Default Permissions Vulnerability | 2024-12-04 | 2024-12-25 | Known |
| CVE-2024-11680 | ProjectSend | ProjectSend | 9.8 Critical | ProjectSend Improper Authentication Vulnerability | 2024-12-03 | 2024-12-24 | Unknown |
| CVE-2024-11667 | Zyxel | Multiple Firewalls | 9.8 Critical | Zyxel Multiple Firewalls Path Traversal Vulnerability | 2024-12-03 | 2024-12-24 | Known |
| CVE-2023-45727 | North Grid | Proself | 7.5 High | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability | 2024-12-03 | 2024-12-24 | Unknown |
| CVE-2023-28461 | Array Networks | AG/vxAG ArrayOS | 9.8 Critical | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability | 2024-11-25 | 2024-12-16 | Known |
| CVE-2024-44309 | Apple | Multiple Products | 6.3 Medium | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | 2024-11-21 | 2024-12-12 | Unknown |
| CVE-2024-44308 | Apple | Multiple Products | 8.8 High | Apple Multiple Products Code Execution Vulnerability | 2024-11-21 | 2024-12-12 | Unknown |
| CVE-2024-21287 | Oracle | Agile Product Lifecycle Management (PLM) | 7.5 High | Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability | 2024-11-21 | 2024-12-12 | Unknown |
| CVE-2024-38813 | VMware | vCenter Server | 9.8 Critical | VMware vCenter Server Privilege Escalation Vulnerability | 2024-11-20 | 2024-12-11 | Unknown |
| CVE-2024-38812 | VMware | vCenter Server | 9.8 Critical | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | 2024-11-20 | 2024-12-11 | Unknown |
| CVE-2024-9474 | Palo Alto Networks | PAN-OS | 6.9 Medium | Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | 2024-11-18 | 2024-12-09 | Known |
| CVE-2024-1212 | Progress | Kemp LoadMaster | 9.8 Critical | Progress Kemp LoadMaster OS Command Injection Vulnerability | 2024-11-18 | 2024-12-09 | Unknown |
| CVE-2024-0012 | Palo Alto Networks | PAN-OS | 9.3 Critical | Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | 2024-11-18 | 2024-12-09 | Known |
| CVE-2024-9465 | Palo Alto Networks | Expedition | 9.2 Critical | Palo Alto Networks Expedition SQL Injection Vulnerability | 2024-11-14 | 2024-12-05 | Unknown |
| CVE-2024-9463 | Palo Alto Networks | Expedition | 9.9 Critical | Palo Alto Networks Expedition OS Command Injection Vulnerability | 2024-11-14 | 2024-12-05 | Unknown |
| CVE-2024-49039 | Microsoft | Windows | 8.8 High | Microsoft Windows Task Scheduler Privilege Escalation Vulnerability | 2024-11-12 | 2024-12-03 | Known |
| CVE-2024-43451 | Microsoft | Windows | 6.5 Medium | Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2021-41277 | Metabase | Metabase | 7.5 High | Metabase GeoJSON API Local File Inclusion Vulnerability | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2021-26086 | Atlassian | Jira Server and Data Center | 5.3 Medium | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2014-2120 | Cisco | Adaptive Security Appliance (ASA) | 6.1 Medium | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2024-5910 | Palo Alto Networks | Expedition | 9.3 Critical | Palo Alto Networks Expedition Missing Authentication Vulnerability | 2024-11-07 | 2024-11-28 | Unknown |
| CVE-2024-51567 | CyberPersons | CyberPanel | 9.8 Critical | CyberPanel Incorrect Default Permissions Vulnerability | 2024-11-07 | 2024-11-28 | Known |
| CVE-2024-43093 | Android | Framework | 7.3 High | Android Framework Privilege Escalation Vulnerability | 2024-11-07 | 2024-11-28 | Unknown |
| CVE-2019-16278 | Nostromo | nhttpd | 9.8 Critical | Nostromo nhttpd Directory Traversal Vulnerability | 2024-11-07 | 2024-11-28 | Unknown |