Vulnerability database

Known exploited vulnerabilities

Every CVE the US government has confirmed is being exploited in the wild. Each entry has its own page with CISA's description, the required remediation, and the vendor advisory.

1,656Total entries
332Ransomware-linked
276Vendors affected
31 Jul 2026Last verified
250 most recent shown
CVE-2026-20316 Cisco Secure Firewall Management Center (FMC) Use of Hard-coded Password Past due 29 Jul 2026 CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Open 27 Jul 2026 CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Past due 27 Jul 2026 CVE-2026-16232 Check Point SmartConsole Improper Authentication Past due 22 Jul 2026 CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Past due 22 Jul 2026 CVE-2026-60137 WordPress Core SQL Injection Open 21 Jul 2026 CVE-2026-63030 WordPress Core Interpretation Conflict Past due 21 Jul 2026 CVE-2026-0770 Langflow Langflow Inclusion of Functionality from Untrusted Control Sphere Past due 21 Jul 2026 CVE-2021-27137 DD-WRT DD-WRT Stack-Based Buffer Overflow Past due 21 Jul 2026 CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Past due 16 Jul 2026 CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Past due 16 Jul 2026 CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Past due 16 Jul 2026 CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Past due 15 Jul 2026 CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Past due 15 Jul 2026 CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Past due 14 Jul 2026 CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Past due 14 Jul 2026 CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Past due 14 Jul 2026 CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Past due 14 Jul 2026 CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Past due 13 Jul 2026 CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Past due 10 Jul 2026 CVE-2026-48939 iCagenda iCagenda Unrestricted Upload of File with Dangerous Type Past due 10 Jul 2026 CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Past due 07 Jul 2026 CVE-2026-55255 Langflow Langflow Authorization Bypass Through User-Controlled Key Past due 07 Jul 2026 CVE-2026-56290 Joomlack Page Builder Improper Access Control Past due 07 Jul 2026 CVE-2026-48282 Adobe ColdFusion Path Traversal Past due 07 Jul 2026 CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Past due 01 Jul 2026 CVE-2026-48558 SimpleHelp SimpleHelp Authentication Bypass Past due 29 Jun 2026 CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Ransomware 25 Jun 2026 CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Past due 25 Jun 2026 CVE-2025-67038 Lantronix EDS5000 Code Injection Past due 23 Jun 2026 CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Past due 23 Jun 2026 CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Past due 23 Jun 2026 CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Past due 23 Jun 2026 CVE-2026-20253 Splunk Enterprise Missing Authentication for Critical Function Past due 18 Jun 2026 CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Past due 16 Jun 2026 CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Past due 15 Jun 2026 CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Past due 15 Jun 2026 CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Ransomware 12 Jun 2026 CVE-2026-10520 Ivanti Sentry OS Command Injection Past due 11 Jun 2026 CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Past due 09 Jun 2026 CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Past due 09 Jun 2026 CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Past due 09 Jun 2026 CVE-2026-42271 BerriAI LiteLLM Command Injection Past due 08 Jun 2026 CVE-2026-50751 Check Point Security Gateway Improper Authentication Ransomware 08 Jun 2026 CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Past due 05 Jun 2026 CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Past due 03 Jun 2026 CVE-2022-0492 Linux Kernel Improper Authentication Past due 02 Jun 2026 CVE-2025-48595 Android Framework Integer Overflow Past due 02 Jun 2026 CVE-2024-21182 Oracle WebLogic Server Unspecified Past due 01 Jun 2026 CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Ransomware 29 May 2026 CVE-2026-48027 Nx Nx Console Embedded Malicious Code Ransomware 27 May 2026 CVE-2026-45321 TanStack TanStack Unspecified Ransomware 27 May 2026 CVE-2026-8398 Daemon Daemon Tools Lite Embedded Malicious Code Past due 27 May 2026 CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Past due 26 May 2026 CVE-2026-9082 Drupal Core SQL Injection Past due 22 May 2026 CVE-2025-34291 Langflow Langflow Origin Validation Error Past due 21 May 2026 CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Past due 21 May 2026 CVE-2008-4250 Microsoft Windows Buffer Overflow Past due 20 May 2026 CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Past due 20 May 2026 CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Past due 20 May 2026 CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Past due 20 May 2026 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Past due 20 May 2026 CVE-2026-41091 Microsoft Defender Link Following Past due 20 May 2026 CVE-2026-45498 Microsoft Defender Denial of Service Past due 20 May 2026 CVE-2026-42897 Microsoft Microsoft Exchange Server Cross-Site Scripting Past due 15 May 2026 CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Past due 14 May 2026 CVE-2026-42208 BerriAI LiteLLM SQL Injection Past due 08 May 2026 CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Past due 07 May 2026 CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write Past due 06 May 2026 CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Past due 01 May 2026 CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Ransomware 30 Apr 2026 CVE-2024-1708 ConnectWise ScreenConnect Path Traversal Ransomware 28 Apr 2026 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure Past due 28 Apr 2026 CVE-2025-29635 D-Link DIR-823X Command Injection Past due 24 Apr 2026 CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Past due 24 Apr 2026 CVE-2024-57728 SimpleHelp SimpleHelp Path Traversal Ransomware 24 Apr 2026 CVE-2024-57726 SimpleHelp SimpleHelp Missing Authorization Ransomware 24 Apr 2026 CVE-2026-39987 Marimo Marimo Remote Code Execution Past due 23 Apr 2026 CVE-2026-33825 Microsoft Defender Insufficient Granularity of Access Control Ransomware 22 Apr 2026 CVE-2026-20122 Cisco Catalyst SD-WAN Manger Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Past due 20 Apr 2026 CVE-2026-20133 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Past due 20 Apr 2026 CVE-2025-2749 Kentico Kentico Xperience Path Traversal Past due 20 Apr 2026 CVE-2023-27351 PaperCut NG/MF Improper Authentication Ransomware 20 Apr 2026 CVE-2025-48700 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Past due 20 Apr 2026 CVE-2026-20128 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Past due 20 Apr 2026 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) Improper Authentication Past due 20 Apr 2026 CVE-2024-27199 JetBrains TeamCity Relative Path Traversal Ransomware 20 Apr 2026 CVE-2026-34197 Apache ActiveMQ Improper Input Validation Past due 16 Apr 2026 CVE-2009-0238 Microsoft Office Remote Code Execution Past due 14 Apr 2026 CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation Past due 14 Apr 2026 CVE-2012-1854 Microsoft Visual Basic for Applications (VBA) Insecure Library Loading Past due 13 Apr 2026 CVE-2025-60710 Microsoft Windows Link Following Past due 13 Apr 2026 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Ransomware 13 Apr 2026 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Past due 13 Apr 2026 CVE-2020-9715 Adobe Acrobat Use-After-Free Past due 13 Apr 2026 CVE-2026-21643 Fortinet FortiClient EMS SQL Injection Past due 13 Apr 2026 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Past due 13 Apr 2026 CVE-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Past due 08 Apr 2026 CVE-2026-35616 Fortinet FortiClient EMS Improper Access Control Past due 06 Apr 2026 CVE-2026-3502 TrueConf Client Download of Code Without Integrity Check Past due 02 Apr 2026 CVE-2026-5281 Google Dawn Use-After-Free Past due 01 Apr 2026 CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read Past due 30 Mar 2026 CVE-2025-53521 F5 BIG-IP Stack-Based Buffer Overflow Past due 27 Mar 2026 CVE-2026-33634 Aquasecurity Trivy Embedded Malicious Code Past due 26 Mar 2026 CVE-2026-33017 Langflow Langflow Code Injection Past due 25 Mar 2026 CVE-2025-32432 Craft CMS Craft CMS Code Injection Past due 20 Mar 2026 CVE-2025-54068 Laravel Livewire Code Injection Past due 20 Mar 2026 CVE-2025-43510 Apple Multiple Products Improper Locking Past due 20 Mar 2026 CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Past due 20 Mar 2026 CVE-2025-31277 Apple Multiple Products Buffer Overflow Past due 20 Mar 2026 CVE-2026-20131 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Ransomware 19 Mar 2026 CVE-2025-66376 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Past due 18 Mar 2026 CVE-2026-20963 Microsoft SharePoint Deserialization of Untrusted Data Past due 18 Mar 2026 CVE-2025-47813 Wing FTP Server Wing FTP Server Information Disclosure Past due 16 Mar 2026 CVE-2026-3910 Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Past due 13 Mar 2026 CVE-2026-3909 Google Skia Out-of-Bounds Write Past due 13 Mar 2026 CVE-2025-68613 n8n n8n Improper Control of Dynamically-Managed Code Resources Past due 11 Mar 2026 CVE-2021-22054 Omnissa Workspace One UEM Workspace ONE Server-Side Request Forgery Past due 09 Mar 2026 CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Past due 09 Mar 2026 CVE-2026-1603 Ivanti Endpoint Manager (EPM) (EPM) Authentication Bypass Past due 09 Mar 2026 CVE-2017-7921 Hikvision Multiple Products Improper Authentication Past due 05 Mar 2026 CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Past due 05 Mar 2026 CVE-2023-43000 Apple Multiple Products Use-After-Free Past due 05 Mar 2026 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Past due 05 Mar 2026 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Past due 05 Mar 2026 CVE-2026-22719 Broadcom VMware Aria Operations Command Injection Past due 03 Mar 2026 CVE-2026-21385 Qualcomm Multiple Chipsets Memory Corruption Past due 03 Mar 2026 CVE-2022-20775 Cisco SD-WAN Path Traversal Past due 25 Feb 2026 CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Past due 25 Feb 2026 CVE-2026-25108 Soliton Systems K.K FileZen OS Command Injection Past due 24 Feb 2026 CVE-2025-49113 Roundcube Webmail Deserialization of Untrusted Data Past due 20 Feb 2026 CVE-2025-68461 Roundcube Webmail Cross-site Scripting Past due 20 Feb 2026 CVE-2021-22175 GitLab GitLab Server-Side Request Forgery (SSRF) Past due 18 Feb 2026 CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Past due 18 Feb 2026 CVE-2020-7796 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Past due 17 Feb 2026 CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Past due 17 Feb 2026 CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution Past due 17 Feb 2026 CVE-2026-2441 Google Chromium CSS Use-After-Free Past due 17 Feb 2026 CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Ransomware 13 Feb 2026 CVE-2026-20700 Apple Multiple Products Multiple Buffer Overflow Past due 12 Feb 2026 CVE-2024-43468 Microsoft Configuration Manager SQL Injection Past due 12 Feb 2026 CVE-2025-15556 Notepad++ Notepad++ Download of Code Without Integrity Check Past due 12 Feb 2026 CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Past due 12 Feb 2026 CVE-2026-21513 Microsoft Windows MSHTML Framework Protection Mechanism Failure Past due 10 Feb 2026 CVE-2026-21525 Microsoft Windows NULL Pointer Dereference Past due 10 Feb 2026 CVE-2026-21510 Microsoft Windows Shell Protection Mechanism Failure Past due 10 Feb 2026 CVE-2026-21533 Microsoft Windows Improper Privilege Management Past due 10 Feb 2026 CVE-2026-21519 Microsoft Windows Type Confusion Past due 10 Feb 2026 CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Past due 10 Feb 2026 CVE-2025-11953 React Native Community CLI OS Command Injection Past due 05 Feb 2026 CVE-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Ransomware 05 Feb 2026 CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Past due 03 Feb 2026 CVE-2025-64328 Sangoma FreePBX OS Command Injection Past due 03 Feb 2026 CVE-2019-19006 Sangoma FreePBX Improper Authentication Past due 03 Feb 2026 CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Past due 03 Feb 2026 CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Past due 29 Jan 2026 CVE-2026-24858 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Past due 27 Jan 2026 CVE-2018-14634 Linux Kernel Integer Overflow Past due 26 Jan 2026 CVE-2025-52691 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Ransomware 26 Jan 2026 CVE-2026-23760 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Ransomware 26 Jan 2026 CVE-2026-24061 GNU InetUtils Argument Injection Past due 26 Jan 2026 CVE-2026-21509 Microsoft Office Security Feature Bypass Past due 26 Jan 2026 CVE-2024-37079 Broadcom VMware vCenter Server Out-of-bounds Write Past due 23 Jan 2026 CVE-2025-68645 Synacor Zimbra Collaboration Suite (ZCS) (ZCS) PHP Remote File Inclusion Past due 22 Jan 2026 CVE-2025-34026 Versa Concerto Improper Authentication Past due 22 Jan 2026 CVE-2025-31125 Vite Vitejs Improper Access Control Past due 22 Jan 2026 CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code Past due 22 Jan 2026 CVE-2026-20045 Cisco Unified Communications Manager Unified Communications Products Code Injection Past due 21 Jan 2026 CVE-2026-20805 Microsoft Windows Information Disclosure Past due 13 Jan 2026 CVE-2025-8110 Gogs Gogs Path Traversal Past due 12 Jan 2026 CVE-2009-0556 Microsoft Office PowerPoint Code Injection Past due 07 Jan 2026 CVE-2025-37164 Hewlett Packard Enterprise (HPE) OneView Code Injection Past due 07 Jan 2026 CVE-2025-14847 MongoDB MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Past due 29 Dec 2025 CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Past due 22 Dec 2025 CVE-2025-14733 WatchGuard Firebox Out of Bounds Write Past due 19 Dec 2025 CVE-2025-59374 ASUS Live Update Embedded Malicious Code Past due 17 Dec 2025 CVE-2025-40602 SonicWall SMA1000 appliance SMA1000 Missing Authorization Past due 17 Dec 2025 CVE-2025-20393 Cisco Multiple Products Improper Input Validation Past due 17 Dec 2025 CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature Past due 16 Dec 2025 CVE-2025-14611 Gladinet CentreStack and Triofox Hard Coded Cryptographic Past due 15 Dec 2025 CVE-2025-43529 Apple Multiple Products Use-After-Free WebKit Past due 15 Dec 2025 CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Past due 12 Dec 2025 CVE-2025-14174 Google Chromium Out of Bounds Memory Access Past due 12 Dec 2025 CVE-2025-58360 OSGeo GeoServer Improper Restriction of XML External Entity Reference Past due 11 Dec 2025 CVE-2025-6218 RARLAB WinRAR Path Traversal Past due 09 Dec 2025 CVE-2025-62221 Microsoft Windows Use After Free Past due 09 Dec 2025 CVE-2022-37055 D-Link Routers Buffer Overflow Past due 08 Dec 2025 CVE-2025-66644 Array Networks ArrayOS AG ArrayOS AG OS Command Injection Past due 08 Dec 2025 CVE-2025-55182 Meta React Server Components Remote Code Execution Ransomware 05 Dec 2025 CVE-2021-26828 OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Past due 03 Dec 2025 CVE-2025-48633 Android Framework Information Disclosure Past due 02 Dec 2025 CVE-2025-48572 Android Framework Privilege Escalation Past due 02 Dec 2025 CVE-2021-26829 OpenPLC ScadaBR Cross-site Scripting Past due 28 Nov 2025 CVE-2025-61757 Oracle Fusion Middleware Missing Authentication for Critical Function Past due 21 Nov 2025 CVE-2025-13223 Google Chromium V8 Type Confusion Past due 19 Nov 2025 CVE-2025-58034 Fortinet FortiWeb OS Command Injection Past due 18 Nov 2025 CVE-2025-64446 Fortinet FortiWeb Path Traversal Past due 14 Nov 2025 CVE-2025-12480 Gladinet Triofox Improper Access Control Past due 12 Nov 2025 CVE-2025-62215 Microsoft Windows Race Condition Past due 12 Nov 2025 CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Past due 12 Nov 2025 CVE-2025-21042 Samsung Mobile Devices Out-of-Bounds Write Past due 10 Nov 2025 CVE-2025-48703 CWP Control Web Panel OS Command Injection Past due 04 Nov 2025 CVE-2025-11371 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Past due 04 Nov 2025 CVE-2025-41244 Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Past due 30 Oct 2025 CVE-2025-24893 XWiki Platform Eval Injection Past due 30 Oct 2025 CVE-2025-6204 Dassault Systèmes DELMIA Apriso Code Injection Past due 28 Oct 2025 CVE-2025-6205 Dassault Systèmes DELMIA Apriso Missing Authorization Past due 28 Oct 2025 CVE-2025-54236 Adobe Commerce and Magento Improper Input Validation Past due 24 Oct 2025 CVE-2025-59287 Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Past due 24 Oct 2025 CVE-2025-61932 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Past due 22 Oct 2025 CVE-2022-48503 Apple Multiple Products Unspecified Past due 20 Oct 2025 CVE-2025-2746 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Past due 20 Oct 2025 CVE-2025-2747 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Past due 20 Oct 2025 CVE-2025-33073 Microsoft Windows SMB Client Improper Access Control Past due 20 Oct 2025 CVE-2025-61884 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Ransomware 20 Oct 2025 CVE-2025-54253 Adobe Experience Manager (AEM) Forms Code Execution Past due 15 Oct 2025 CVE-2025-47827 IGEL IGEL OS Use of a Key Past its Expiration Date Past due 14 Oct 2025 CVE-2025-24990 Microsoft Windows Untrusted Pointer Dereference Past due 14 Oct 2025 CVE-2025-59230 Microsoft Windows Improper Access Control Past due 14 Oct 2025 CVE-2016-7836 SKYSEA Client View Improper Authentication Past due 14 Oct 2025 CVE-2021-43798 Grafana Labs Grafana Path Traversal Past due 09 Oct 2025 CVE-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Past due 07 Oct 2025 CVE-2021-22555 Linux Kernel Heap Out-of-Bounds Write Past due 06 Oct 2025 CVE-2010-3962 Microsoft Internet Explorer Uninitialized Memory Corruption Past due 06 Oct 2025 CVE-2021-43226 Microsoft Windows Privilege Escalation Past due 06 Oct 2025 CVE-2013-3918 Microsoft Windows Out-of-Bounds Write Past due 06 Oct 2025 CVE-2011-3402 Microsoft Windows Remote Code Execution Past due 06 Oct 2025 CVE-2010-3765 Mozilla Multiple Products Remote Code Execution Past due 06 Oct 2025 CVE-2025-61882 Oracle E-Business Suite Unspecified Ransomware 06 Oct 2025 CVE-2014-6278 GNU GNU Bash OS Command Injection Past due 02 Oct 2025 CVE-2017-1000353 Jenkins Jenkins Remote Code Execution Past due 02 Oct 2025 CVE-2015-7755 Juniper ScreenOS Improper Authentication Past due 02 Oct 2025 CVE-2025-21043 Samsung Mobile Devices Out-of-Bounds Write Past due 02 Oct 2025 CVE-2025-4008 Smartbedded Meteobridge Command Injection Past due 02 Oct 2025 CVE-2025-32463 Sudo Sudo Inclusion of Functionality from Untrusted Control Sphere Past due 29 Sept 2025 CVE-2025-59689 Libraesva Email Security Gateway Command Injection Past due 29 Sept 2025 CVE-2025-10035 Fortra GoAnywhere MFT Deserialization of Untrusted Data Ransomware 29 Sept 2025 CVE-2025-20352 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Past due 29 Sept 2025 CVE-2021-21311 Adminer Adminer Server-Side Request Forgery Past due 29 Sept 2025 CVE-2025-20362 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Past due 25 Sept 2025 CVE-2025-20333 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Past due 25 Sept 2025 CVE-2025-10585 Google Chromium V8 Type Confusion Past due 23 Sept 2025 CVE-2025-5086 Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Past due 11 Sept 2025 CVE-2025-38352 Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Past due 04 Sept 2025 CVE-2025-48543 Android Runtime Use-After-Free Past due 04 Sept 2025 CVE-2025-53690 Sitecore Multiple Products Deserialization of Untrusted Data Past due 04 Sept 2025 CVE-2023-50224 TP-Link TL-WR841N Authentication Bypass by Spoofing Past due 03 Sept 2025 CVE-2025-9377 TP-Link Multiple Routers Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Past due 03 Sept 2025 CVE-2020-24363 TP-Link TL-WA855RE Missing Authentication for Critical Function Past due 02 Sept 2025 CVE-2025-55177 Meta Platforms WhatsApp Incorrect Authorization Past due 02 Sept 2025

Showing the 250 most recently added of 1,656. Every entry has its own page and appears in the sitemap, so nothing is hidden from search engines — this list is trimmed for readability, not for indexing.

Most affected vendors

Microsoft382Cisco95Apple93Adobe80Google72Oracle45Apache39Ivanti35Fortinet29Linux26D-Link26VMware26

Source: CISA KEV catalog · last verified July 31, 2026 · refreshed twice daily.