CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2025-40536 2026-02-12 2026-02-15 82.0% SolarWinds Web Help Desk contains a security control bypass vulnerabil…
CVE-2025-15556 2026-02-12 2026-03-05 1.7% Notepad++ when using the WinGUp updater, contains a download of code w…
CVE-2024-43468 2026-02-12 2026-03-05 82.0% Microsoft Configuration Manager contains an SQL injection vulnerabilit…
CVE-2026-21510 2026-02-10 2026-03-03 26.2% Microsoft Windows Shell contains a protection mechanism failure vulner…
CVE-2026-21513 2026-02-10 2026-03-03 15.6% Microsoft MSHTML Framework contains a protection mechanism failure vul…
CVE-2026-21514 2026-02-10 2026-03-03 1.5% Microsoft Office Word contains a reliance on untrusted inputs in a sec…
CVE-2026-21519 2026-02-10 2026-03-03 2.5% Microsoft Desktop Windows Manager contains a type confusion vulnerabil…
CVE-2026-21525 2026-02-10 2026-03-03 5.0% Microsoft Windows Remote Access Connection Manager contains a NULL poi…
CVE-2026-21533 2026-02-10 2026-03-03 3.9% Microsoft Windows Remote Desktop Services contains an improper privile…
CVE-2026-24423 2026-02-05 2026-02-26 88.0% 9.8 yes SmarterTools SmarterMail versions prior to build 9511 contain an unaut…
CVE-2025-11953 2026-02-05 2026-02-26 94.0% React Native Community CLI contains an OS command injection vulnerabil…
CVE-2025-64328 2026-02-03 2026-02-24 84.6% Sangoma FreePBX Endpoint Manager contains an OS command injection vuln…
CVE-2025-40551 2026-02-03 2026-02-06 83.6% SolarWinds Web Help Desk contains a deserialization of untrusted data …
CVE-2019-19006 2026-02-03 2026-02-24 36.6% Sangoma FreePBX contains an improper authentication vulnerability that…
CVE-2021-39935 2026-02-03 2026-02-24 35.6% GitLab Community and Enterprise Editions contain a server-side request…
CVE-2026-1281 2026-01-29 2026-02-01 98.6% Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner…
CVE-2026-24858 2026-01-27 2026-01-30 86.1% Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain …
CVE-2026-23760 2026-01-26 2026-02-16 96.4% 9.8 yes SmarterTools SmarterMail versions prior to build 9511 contain an authe…
CVE-2026-24061 2026-01-26 2026-02-16 98.1% GNU InetUtils contains an argument injection vulnerability in telnetd …
CVE-2026-21509 2026-01-26 2026-02-16 72.6% Microsoft Office contains a security feature bypass vulnerability in w…
CVE-2025-52691 2026-01-26 2026-02-16 85.7% yes SmarterTools SmarterMail contains an unrestricted upload of file with …
CVE-2018-14634 2026-01-26 2026-02-16 14.7% Linux Kernel contains an integer overflow vulnerability in the create_…
CVE-2024-37079 2026-01-23 2026-02-13 22.4% Broadcom VMware vCenter Server contains an out-of-bounds write vulnera…
CVE-2025-31125 2026-01-22 2026-02-12 58.5% Vite Vitejs contains an improper access control vulnerability that exp…
CVE-2025-54313 2026-01-22 2026-02-12 4.5% Prettier eslint-config-prettier contains an embedded malicious code vu…
CVE-2025-34026 2026-01-22 2026-02-12 81.9% Versa Concerto SD-WAN orchestration platform contains an improper auth…
CVE-2025-68645 2026-01-22 2026-02-12 48.9% Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file in…
CVE-2026-20045 2026-01-21 2026-02-11 4.5% Cisco Unified Communications Manager (Unified CM), Cisco Unified Commu…
CVE-2026-20805 2026-01-13 2026-02-03 5.2% 5.5 Exposure of sensitive information to an unauthorized actor in Desktop …
CVE-2025-8110 2026-01-12 2026-02-02 82.5% Gogs contains a path traversal vulnerability affecting improper Symbol…
CVE-2025-37164 2026-01-07 2026-01-28 90.2% Hewlett Packard Enterprise (HPE) OneView contains a code injection vul…
CVE-2009-0556 2026-01-07 2026-01-28 67.3% Microsoft Office PowerPoint contains a code injection vulnerability th…
CVE-2025-14847 2025-12-29 2026-01-19 83.2% MongoDB Server contains an improper handling of length parameter incon…
CVE-2023-52163 2025-12-22 2026-01-12 96.9% Digiever DS-2105 Pro contains a missing authorization vulnerability wh…
CVE-2025-14733 2025-12-19 2025-12-26 26.5% 9.8 yes An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ike…
CVE-2025-20393 2025-12-17 2025-12-24 29.9% Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Ma…
CVE-2025-40602 2025-12-17 2025-12-24 2.1% SonicWall SMA1000 contains a missing authorization vulnerability that …
CVE-2025-59374 2025-12-17 2026-01-07 1.2% ASUS Live Update contains an embedded malicious code vulnerability cli…
CVE-2025-59718 2025-12-16 2025-12-23 68.3% Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain …
CVE-2025-43529 2025-12-15 2026-01-05 8.8% Apple iOS, iPadOS, macOS, and other Apple products contain a use-after…
CVE-2025-14611 2025-12-15 2026-01-05 53.3% Gladinet CentreStack and TrioFox contain a hardcoded cryptographic key…
CVE-2025-14174 2025-12-12 2026-01-02 22.3% Google Chromium contains an out of bounds memory access vulnerability …
CVE-2018-4063 2025-12-12 2026-01-02 27.1% Sierra Wireless AirLink ALEOS contains an unrestricted upload of file …
CVE-2025-58360 2025-12-11 2026-01-01 64.9% OSGeo GeoServer contains an improper restriction of XML external entit…
CVE-2025-6218 2025-12-09 2025-12-30 90.5% RARLAB WinRAR contains a path traversal vulnerability allowing an atta…
CVE-2025-62221 2025-12-09 2025-12-30 2.5% Microsoft Windows Cloud Files Mini Filter Driver contains a use after …
CVE-2025-66644 2025-12-08 2025-12-29 3.4% Array Networks ArrayOS AG contains an OS command injection vulnerabili…
CVE-2022-37055 2025-12-08 2025-12-29 55.5% D-Link Routers contains a buffer overflow vulnerability that has a hig…
CVE-2025-55182 2025-12-05 2025-12-12 99.8% 10.0 yes A pre-authentication remote code execution vulnerability exists in Rea…
CVE-2021-26828 2025-12-03 2025-12-24 39.4% OpenPLC ScadaBR contains an unrestricted upload of file with dangerous…
CVE-2025-48633 2025-12-02 2025-12-23 0.3% Android Framework contains an unspecified vulnerability that allows fo…
CVE-2025-48572 2025-12-02 2025-12-23 0.3% Android Framework contains an unspecified vulnerability that allows fo…
CVE-2021-26829 2025-11-28 2025-12-19 48.1% OpenPLC ScadaBR contains a cross-site scripting vulnerability via syst…
CVE-2025-61757 2025-11-21 2025-12-12 88.3% Oracle Fusion Middleware contains a missing authentication for critica…
CVE-2025-13223 2025-11-19 2025-12-10 5.0% Google Chromium V8 contains a type confusion vulnerability that allows…
CVE-2025-58034 2025-11-18 2025-11-25 55.6% Fortinet FortiWeb contains an OS command Injection vulnerability that …
CVE-2025-64446 2025-11-14 2025-11-21 91.8% Fortinet FortiWeb contains a relative path traversal vulnerability tha…
CVE-2025-62215 2025-11-12 2025-12-03 6.0% Microsoft Windows Kernel contains a race condition vulnerability that …
CVE-2025-9242 2025-11-12 2025-12-03 91.3% 9.8 An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ike…
CVE-2025-12480 2025-11-12 2025-12-03 90.5% Gladinet Triofox contains an improper access control vulnerability tha…
CVE-2025-21042 2025-11-10 2025-12-01 33.2% Samsung mobile devices contain an out-of-bounds write vulnerability in…
CVE-2025-11371 2025-11-04 2025-11-25 92.1% Gladinet CentreStack and Triofox contains a files or directories acces…
CVE-2025-48703 2025-11-04 2025-11-25 99.7% CWP Control Web Panel (formerly CentOS Web Panel) contains an OS comma…
CVE-2025-41244 2025-10-30 2025-11-20 8.4% Broadcom VMware Aria Operations and VMware Tools contain a privilege d…
CVE-2025-24893 2025-10-30 2025-11-20 99.9% XWiki Platform contains an eval injection vulnerability that could all…
CVE-2025-6204 2025-10-28 2025-11-18 77.3% Dassault Systèmes DELMIA Apriso contains a code injection vulnerabilit…
CVE-2025-6205 2025-10-28 2025-11-18 73.3% Dassault Systèmes DELMIA Apriso contains a missing authorization vulne…
CVE-2025-59287 2025-10-24 2025-11-14 100.0% Microsoft Windows Server Update Service (WSUS) contains a deserializat…
CVE-2025-54236 2025-10-24 2025-11-14 94.5% Adobe Commerce and Magento Open Source contain an improper input valid…
CVE-2025-61932 2025-10-22 2025-11-12 2.6% Motex LANSCOPE Endpoint Manager contains an improper verification of s…
CVE-2025-61884 2025-10-20 2025-11-10 95.9% 7.5 yes Vulnerability in the Oracle Configurator product of Oracle E-Business …
CVE-2025-33073 2025-10-20 2025-11-10 82.7% Microsoft Windows SMB Client contains an improper access control vulne…
CVE-2025-2746 2025-10-20 2025-11-10 59.1% Kentico Xperience CMS contains an authentication bypass using an alter…
CVE-2025-2747 2025-10-20 2025-11-10 92.5% Kentico Xperience CMS contains an authentication bypass using an alter…
CVE-2022-48503 2025-10-20 2025-11-10 3.2% Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vul…
CVE-2025-54253 2025-10-15 2025-11-05 88.0% Adobe Experience Manager Forms in JEE contains an unspecified vulnerab…
CVE-2025-59230 2025-10-14 2025-11-04 2.7% Microsoft Windows contains an improper access control vulnerability in…
CVE-2025-47827 2025-10-14 2025-11-04 4.9% IGEL OS contains a use of a key past its expiration date vulnerability…
CVE-2025-24990 2025-10-14 2025-11-04 6.4% Microsoft Windows Agere Modem Driver contains an untrusted pointer der…
CVE-2016-7836 2025-10-14 2025-11-04 19.2% SKYSEA Client View contains an improper authentication vulnerability t…
CVE-2021-43798 2025-10-09 2025-10-30 88.5% Grafana contains a path traversal vulnerability that could allow acces…
CVE-2025-27915 2025-10-07 2025-10-28 4.0% Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti…
CVE-2025-61882 2025-10-06 2025-10-27 99.7% 9.8 yes Vulnerability in the Oracle Concurrent Processing product of Oracle E-…
CVE-2021-43226 2025-10-06 2025-10-27 3.1% 7.8 yes Windows Common Log File System Driver Elevation of Privilege Vulnerabi…
CVE-2021-22555 2025-10-06 2025-10-27 78.7% Linux Kernel contains a heap out-of-bounds write vulnerability that co…
CVE-2010-3765 2025-10-06 2025-10-27 83.2% Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vul…
CVE-2010-3962 2025-10-06 2025-10-27 96.8% Microsoft Internet Explorer contains an uninitialized memory corruptio…
CVE-2011-3402 2025-10-06 2025-10-27 78.1% Microsoft Windows Kernel contains an unspecified vulnerability in the …
CVE-2013-3918 2025-10-06 2025-10-27 73.7% Microsoft Windows contains an out-of-bounds write vulnerability in the…
CVE-2017-1000353 2025-10-02 2025-10-23 99.7% Jenkins contains a remote code execution vulnerability. This vulnerabi…
CVE-2015-7755 2025-10-02 2025-10-23 61.1% Juniper ScreenOS contains an improper authentication vulnerability tha…
CVE-2014-6278 2025-10-02 2025-10-23 99.5% GNU Bash contains an OS command injection vulnerability which allows r…
CVE-2025-4008 2025-10-02 2025-10-23 93.7% Smartbedded Meteobridge contains a command injection vulnerability tha…
CVE-2025-21043 2025-10-02 2025-10-23 1.9% Samsung mobile devices contain an out-of-bounds write vulnerability in…
CVE-2025-20352 2025-09-29 2025-10-20 39.4% Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerabil…
CVE-2025-32463 2025-09-29 2025-10-20 59.4% Sudo contains an inclusion of functionality from untrusted control sph…
CVE-2025-10035 2025-09-29 2025-10-20 99.8% 10.0 yes A deserialization vulnerability in the License Servlet of Fortra's GoA…
CVE-2025-59689 2025-09-29 2025-10-20 1.9% Libraesva Email Security Gateway (ESG) contains a command injection vu…
CVE-2021-21311 2025-09-29 2025-10-20 90.5% Adminer contains a server-side request forgery vulnerability that, whe…
CVE-2025-20362 2025-09-25 2025-09-26 87.1% 6.5 Update: On November 5, 2025, Cisco became aware of a new attack varian…
← Prev Page 3 of 18 Next →