CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2025-20333 2025-09-25 2025-09-26 70.7% 9.9 A vulnerability in the VPN web server of Cisco Secure Firewall Adaptiv…
CVE-2025-10585 2025-09-23 2025-10-14 5.4% Google Chromium contains a type confusion vulnerability in the V8 Java…
CVE-2025-5086 2025-09-11 2025-10-02 91.9% Dassault Systèmes DELMIA Apriso contains a deserialization of untruste…
CVE-2025-53690 2025-09-04 2025-09-25 51.1% Sitecore Experience Manager (XM), Experience Platform (XP), Experience…
CVE-2025-48543 2025-09-04 2025-09-25 0.5% Android Runtime contains a use-after-free vulnerability potentially al…
CVE-2025-38352 2025-09-04 2025-09-25 1.3% 7.8 In the Linux kernel, the following vulnerability has been resolved: p…
CVE-2025-9377 2025-09-03 2025-09-24 33.5% TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injec…
CVE-2023-50224 2025-09-03 2025-09-24 15.6% 6.5 TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disc…
CVE-2025-55177 2025-09-02 2025-09-23 4.3% Meta Platforms WhatsApp contains an incorrect authorization vulnerabil…
CVE-2020-24363 2025-09-02 2025-09-23 20.7% TP-link TL-WA855RE contains a missing authentication for critical func…
CVE-2025-57819 2025-08-29 2025-09-19 85.5% Sangoma FreePBX contains an authentication bypass vulnerability due to…
CVE-2025-7775 2025-08-26 2025-08-28 19.6% Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow v…
CVE-2025-48384 2025-08-25 2025-09-15 4.1% Git contains a link following vulnerability that stems from Git’s inco…
CVE-2024-8068 2025-08-25 2025-09-15 1.4% Citrix Session Recording contains an improper privilege management vul…
CVE-2024-8069 2025-08-25 2025-09-15 14.6% Citrix Session Recording contains a deserialization of untrusted data …
CVE-2025-43300 2025-08-21 2025-09-11 22.0% Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerabil…
CVE-2025-54948 2025-08-18 2025-09-08 22.0% Trend Micro Apex One Management Console (on-premise) contains an OS co…
CVE-2025-8875 2025-08-13 2025-08-20 1.7% N-able N-Central contains an insecure deserialization vulnerability th…
CVE-2025-8876 2025-08-13 2025-08-20 3.3% N-able N-Central contains a command injection vulnerability via improp…
CVE-2025-8088 2025-08-12 2025-09-02 94.1% 8.8 yes A path traversal vulnerability affecting the Windows version of WinRAR…
CVE-2013-3893 2025-08-12 2025-09-02 85.8% Microsoft Internet Explorer contains a memory corruption vulnerability…
CVE-2007-0671 2025-08-12 2025-09-02 42.4% Microsoft Office Excel contains a remote code execution vulnerability …
CVE-2020-25078 2025-08-05 2025-08-26 97.9% D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnera…
CVE-2020-25079 2025-08-05 2025-08-26 56.3% D-Link DCS-2530L and DCS-2670L devices contains a command injection vu…
CVE-2022-40799 2025-08-05 2025-08-26 33.7% D-Link DNR-322L contains a download of code without integrity check vu…
CVE-2023-2533 2025-07-28 2025-08-18 29.2% PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerabil…
CVE-2025-20337 2025-07-28 2025-08-18 67.6% Cisco Identity Services Engine contains an injection vulnerability in …
CVE-2025-20281 2025-07-28 2025-08-18 97.2% Cisco Identity Services Engine contains an injection vulnerability in …
CVE-2025-2775 2025-07-22 2025-08-12 43.0% SysAid On-Prem contains an improper restriction of XML external entity…
CVE-2025-2776 2025-07-22 2025-08-12 64.4% SysAid On-Prem contains an improper restriction of XML external entity…
CVE-2025-6558 2025-07-22 2025-08-12 9.6% Google Chromium contains an improper input validation vulnerability in…
CVE-2025-54309 2025-07-22 2025-08-12 94.9% CrushFTP contains an unprotected alternate channel vulnerability. When…
CVE-2025-49704 2025-07-22 2025-07-23 100.0% yes Microsoft SharePoint contains a code injection vulnerability that coul…
CVE-2025-49706 2025-07-22 2025-07-23 99.1% 6.5 yes Improper authentication in Microsoft Office SharePoint allows an unaut…
CVE-2025-53770 2025-07-20 2025-07-21 100.0% 9.8 yes Deserialization of untrusted data in on-premises Microsoft SharePoint …
CVE-2025-25257 2025-07-18 2025-08-08 99.8% Fortinet FortiWeb contains a SQL injection vulnerability that may allo…
CVE-2025-47812 2025-07-14 2025-08-04 92.9% Wing FTP Server contains an improper neutralization of null byte or NU…
CVE-2025-5777 2025-07-10 2025-07-11 100.0% 7.5 yes Insufficient input validation leading to memory overread when the NetS…
CVE-2014-3931 2025-07-07 2025-07-28 29.0% Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerabi…
CVE-2016-10033 2025-07-07 2025-07-28 99.7% PHPMailer contains a command injection vulnerability because it fails …
CVE-2019-5418 2025-07-07 2025-07-28 98.5% Rails Ruby on Rails contains a path traversal vulnerability in Action …
CVE-2019-9621 2025-07-07 2025-07-28 81.0% Synacor Zimbra Collaboration Suite (ZCS) contains a server-side reques…
CVE-2025-6554 2025-07-02 2025-07-23 12.7% Google Chromium V8 contains a type confusion vulnerability that could …
CVE-2025-48927 2025-07-01 2025-07-22 11.1% TeleMessage TM SGNL contains an initialization of a resource with an i…
CVE-2025-48928 2025-07-01 2025-07-22 0.6% TeleMessage TM SGNL contains an exposure of core dump file to an unaut…
CVE-2025-6543 2025-06-30 2025-07-21 10.1% Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerabili…
CVE-2024-54085 2025-06-25 2025-07-16 60.7% AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerab…
CVE-2024-0769 2025-06-25 2025-07-16 82.7% D-Link DIR-859 routers contain a path traversal vulnerability in the f…
CVE-2019-6693 2025-06-25 2025-07-16 5.8% 6.5 yes Use of a hard-coded cryptographic key to cipher sensitive data in Fort…
CVE-2023-0386 2025-06-17 2025-07-08 7.9% Linux Kernel contains an improper ownership management vulnerability, …
CVE-2023-33538 2025-06-16 2025-07-07 41.9% TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain…
CVE-2025-43200 2025-06-16 2025-07-07 1.1% Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecifie…
CVE-2025-33053 2025-06-10 2025-07-01 87.6% Microsoft Windows contains an external control of file name or path vu…
CVE-2025-24016 2025-06-10 2025-07-01 93.8% Wazuh contains a deserialization of untrusted data vulnerability that …
CVE-2025-32433 2025-06-09 2025-06-30 98.8% Erlang Erlang/OTP SSH server contains a missing authentication for cri…
CVE-2024-42009 2025-06-09 2025-06-30 82.9% RoundCube Webmail contains a cross-site scripting vulnerability. This …
CVE-2025-5419 2025-06-05 2025-06-26 7.8% Google Chromium V8 contains an out-of-bounds read and write vulnerabil…
CVE-2025-27038 2025-06-03 2025-06-24 1.0% Multiple Qualcomm chipsets contain a use-after-free vulnerability. Thi…
CVE-2025-21479 2025-06-03 2025-06-24 0.8% Multiple Qualcomm chipsets contain an incorrect authorization vulnerab…
CVE-2025-21480 2025-06-03 2025-06-24 0.5% Multiple Qualcomm chipsets contain an incorrect authorization vulnerab…
CVE-2024-56145 2025-06-02 2025-06-23 97.4% Craft CMS contains a code injection vulnerability. Users with affected…
CVE-2025-35939 2025-06-02 2025-06-23 1.3% Craft CMS contains an external control of assumed-immutable web parame…
CVE-2025-3935 2025-06-02 2025-06-23 3.4% ConnectWise ScreenConnect contains an improper authentication vulnerab…
CVE-2023-39780 2025-06-02 2025-06-23 40.2% ASUS RT-AX55 devices contain an OS command injection vulnerability tha…
CVE-2021-32030 2025-06-02 2025-06-23 99.4% ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authenti…
CVE-2025-4632 2025-05-22 2025-06-12 24.3% Samsung MagicINFO 9 Server contains a path traversal vulnerability tha…
CVE-2025-4427 2025-05-19 2025-06-09 99.9% Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypas…
CVE-2025-4428 2025-05-19 2025-06-09 86.5% Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner…
CVE-2025-27920 2025-05-19 2025-06-09 1.9% Srimax Output Messenger contains a directory traversal vulnerability t…
CVE-2024-27443 2025-05-19 2025-06-09 23.6% Zimbra Collaboration contains a cross-site scripting (XSS) vulnerabili…
CVE-2024-11182 2025-05-19 2025-06-09 17.7% MDaemon Email Server contains a cross-site scripting (XSS) vulnerabili…
CVE-2023-38950 2025-05-19 2025-06-09 84.7% ZKTeco BioTime contains a path traversal vulnerability in the iclock A…
CVE-2024-12987 2025-05-15 2025-06-05 98.1% DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS comm…
CVE-2025-42999 2025-05-15 2025-06-05 13.9% 9.1 yes SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a p…
CVE-2025-32756 2025-05-14 2025-06-04 29.8% Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack…
CVE-2025-32701 2025-05-13 2025-06-03 1.4% Microsoft Windows Common Log File System (CLFS) Driver contains a use-…
CVE-2025-32706 2025-05-13 2025-06-03 2.3% Microsoft Windows Common Log File System (CLFS) Driver contains a heap…
CVE-2025-32709 2025-05-13 2025-06-03 2.1% Microsoft Windows Ancillary Function Driver for WinSock contains a use…
CVE-2025-30397 2025-05-13 2025-06-03 26.8% Microsoft Windows Scripting Engine contains a type confusion vulnerabi…
CVE-2025-30400 2025-05-13 2025-06-03 1.9% Microsoft Windows DWM Core Library contains a use-after-free vulnerabi…
CVE-2025-47729 2025-05-12 2025-06-02 0.4% TeleMessage TM SGNL contains a hidden functionality vulnerability in w…
CVE-2024-6047 2025-05-07 2025-05-28 10.1% Multiple GeoVision devices contain an OS command injection vulnerabili…
CVE-2024-11120 2025-05-07 2025-05-28 28.4% Multiple GeoVision devices contain an OS command injection vulnerabili…
CVE-2025-27363 2025-05-06 2025-05-27 27.8% FreeType contains an out-of-bounds write vulnerability when attempting…
CVE-2025-3248 2025-05-05 2025-05-26 100.0% yes Langflow contains a missing authentication vulnerability in the /api/v…
CVE-2024-58136 2025-05-02 2025-05-23 87.8% Yii Framework contains an improper protection of alternate path vulner…
CVE-2025-34028 2025-05-02 2025-05-23 97.6% Commvault Command Center contains a path traversal vulnerability that …
CVE-2023-44221 2025-05-01 2025-05-22 76.3% SonicWall SMA100 appliances contain an OS command injection vulnerabil…
CVE-2024-38475 2025-05-01 2025-05-22 100.0% Apache HTTP Server contains an improper escaping of output vulnerabili…
CVE-2025-31324 2025-04-29 2025-05-20 99.5% 10.0 yes SAP NetWeaver Visual Composer Metadata Uploader is not protected with …
CVE-2025-1976 2025-04-28 2025-05-19 0.7% Broadcom Brocade Fabric OS contains a code injection vulnerability tha…
CVE-2025-3928 2025-04-28 2025-05-19 2.1% Commvault Web Server contains an unspecified vulnerability that allows…
CVE-2025-42599 2025-04-28 2025-05-19 3.3% Qualitia Active! Mail contains a stack-based buffer overflow vulnerabi…
CVE-2025-24054 2025-04-17 2025-05-08 58.9% Microsoft Windows NTLM contains an external control of file name or pa…
CVE-2025-31200 2025-04-17 2025-05-08 18.6% Apple iOS, iPadOS, macOS, and other Apple products contain a memory co…
CVE-2025-31201 2025-04-17 2025-05-08 13.9% Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrar…
CVE-2021-20035 2025-04-16 2025-05-07 4.2% SonicWall SMA100 appliances contain an OS command injection vulnerabil…
CVE-2024-53150 2025-04-09 2025-04-30 1.4% Linux Kernel contains an out-of-bounds read vulnerability in the USB-a…
CVE-2024-53197 2025-04-09 2025-04-30 3.6% Linux Kernel contains an out-of-bounds access vulnerability in the USB…
CVE-2025-30406 2025-04-08 2025-04-29 94.3% Gladinet CentreStack and Triofox contains a use of hard-coded cryptogr…
← Prev Page 4 of 18 Next →