CISA Known Exploited Vulnerabilities
Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.
| CVE | Added | Patch by | EPSS | CVSS | Ransomware | What |
|---|---|---|---|---|---|---|
| CVE-2025-20333 | 2025-09-25 | 2025-09-26 | 70.7% | 9.9 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptiv… | |
| CVE-2025-10585 | 2025-09-23 | 2025-10-14 | 5.4% | — | Google Chromium contains a type confusion vulnerability in the V8 Java… | |
| CVE-2025-5086 | 2025-09-11 | 2025-10-02 | 91.9% | — | Dassault Systèmes DELMIA Apriso contains a deserialization of untruste… | |
| CVE-2025-53690 | 2025-09-04 | 2025-09-25 | 51.1% | — | Sitecore Experience Manager (XM), Experience Platform (XP), Experience… | |
| CVE-2025-48543 | 2025-09-04 | 2025-09-25 | 0.5% | — | Android Runtime contains a use-after-free vulnerability potentially al… | |
| CVE-2025-38352 | 2025-09-04 | 2025-09-25 | 1.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: p… | |
| CVE-2025-9377 | 2025-09-03 | 2025-09-24 | 33.5% | — | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injec… | |
| CVE-2023-50224 | 2025-09-03 | 2025-09-24 | 15.6% | 6.5 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disc… | |
| CVE-2025-55177 | 2025-09-02 | 2025-09-23 | 4.3% | — | Meta Platforms WhatsApp contains an incorrect authorization vulnerabil… | |
| CVE-2020-24363 | 2025-09-02 | 2025-09-23 | 20.7% | — | TP-link TL-WA855RE contains a missing authentication for critical func… | |
| CVE-2025-57819 | 2025-08-29 | 2025-09-19 | 85.5% | — | Sangoma FreePBX contains an authentication bypass vulnerability due to… | |
| CVE-2025-7775 | 2025-08-26 | 2025-08-28 | 19.6% | — | Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow v… | |
| CVE-2025-48384 | 2025-08-25 | 2025-09-15 | 4.1% | — | Git contains a link following vulnerability that stems from Git’s inco… | |
| CVE-2024-8068 | 2025-08-25 | 2025-09-15 | 1.4% | — | Citrix Session Recording contains an improper privilege management vul… | |
| CVE-2024-8069 | 2025-08-25 | 2025-09-15 | 14.6% | — | Citrix Session Recording contains a deserialization of untrusted data … | |
| CVE-2025-43300 | 2025-08-21 | 2025-09-11 | 22.0% | — | Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerabil… | |
| CVE-2025-54948 | 2025-08-18 | 2025-09-08 | 22.0% | — | Trend Micro Apex One Management Console (on-premise) contains an OS co… | |
| CVE-2025-8875 | 2025-08-13 | 2025-08-20 | 1.7% | — | N-able N-Central contains an insecure deserialization vulnerability th… | |
| CVE-2025-8876 | 2025-08-13 | 2025-08-20 | 3.3% | — | N-able N-Central contains a command injection vulnerability via improp… | |
| CVE-2025-8088 | 2025-08-12 | 2025-09-02 | 94.1% | 8.8 | yes | A path traversal vulnerability affecting the Windows version of WinRAR… |
| CVE-2013-3893 | 2025-08-12 | 2025-09-02 | 85.8% | — | Microsoft Internet Explorer contains a memory corruption vulnerability… | |
| CVE-2007-0671 | 2025-08-12 | 2025-09-02 | 42.4% | — | Microsoft Office Excel contains a remote code execution vulnerability … | |
| CVE-2020-25078 | 2025-08-05 | 2025-08-26 | 97.9% | — | D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnera… | |
| CVE-2020-25079 | 2025-08-05 | 2025-08-26 | 56.3% | — | D-Link DCS-2530L and DCS-2670L devices contains a command injection vu… | |
| CVE-2022-40799 | 2025-08-05 | 2025-08-26 | 33.7% | — | D-Link DNR-322L contains a download of code without integrity check vu… | |
| CVE-2023-2533 | 2025-07-28 | 2025-08-18 | 29.2% | — | PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerabil… | |
| CVE-2025-20337 | 2025-07-28 | 2025-08-18 | 67.6% | — | Cisco Identity Services Engine contains an injection vulnerability in … | |
| CVE-2025-20281 | 2025-07-28 | 2025-08-18 | 97.2% | — | Cisco Identity Services Engine contains an injection vulnerability in … | |
| CVE-2025-2775 | 2025-07-22 | 2025-08-12 | 43.0% | — | SysAid On-Prem contains an improper restriction of XML external entity… | |
| CVE-2025-2776 | 2025-07-22 | 2025-08-12 | 64.4% | — | SysAid On-Prem contains an improper restriction of XML external entity… | |
| CVE-2025-6558 | 2025-07-22 | 2025-08-12 | 9.6% | — | Google Chromium contains an improper input validation vulnerability in… | |
| CVE-2025-54309 | 2025-07-22 | 2025-08-12 | 94.9% | — | CrushFTP contains an unprotected alternate channel vulnerability. When… | |
| CVE-2025-49704 | 2025-07-22 | 2025-07-23 | 100.0% | — | yes | Microsoft SharePoint contains a code injection vulnerability that coul… |
| CVE-2025-49706 | 2025-07-22 | 2025-07-23 | 99.1% | 6.5 | yes | Improper authentication in Microsoft Office SharePoint allows an unaut… |
| CVE-2025-53770 | 2025-07-20 | 2025-07-21 | 100.0% | 9.8 | yes | Deserialization of untrusted data in on-premises Microsoft SharePoint … |
| CVE-2025-25257 | 2025-07-18 | 2025-08-08 | 99.8% | — | Fortinet FortiWeb contains a SQL injection vulnerability that may allo… | |
| CVE-2025-47812 | 2025-07-14 | 2025-08-04 | 92.9% | — | Wing FTP Server contains an improper neutralization of null byte or NU… | |
| CVE-2025-5777 | 2025-07-10 | 2025-07-11 | 100.0% | 7.5 | yes | Insufficient input validation leading to memory overread when the NetS… |
| CVE-2014-3931 | 2025-07-07 | 2025-07-28 | 29.0% | — | Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerabi… | |
| CVE-2016-10033 | 2025-07-07 | 2025-07-28 | 99.7% | — | PHPMailer contains a command injection vulnerability because it fails … | |
| CVE-2019-5418 | 2025-07-07 | 2025-07-28 | 98.5% | — | Rails Ruby on Rails contains a path traversal vulnerability in Action … | |
| CVE-2019-9621 | 2025-07-07 | 2025-07-28 | 81.0% | — | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side reques… | |
| CVE-2025-6554 | 2025-07-02 | 2025-07-23 | 12.7% | — | Google Chromium V8 contains a type confusion vulnerability that could … | |
| CVE-2025-48927 | 2025-07-01 | 2025-07-22 | 11.1% | — | TeleMessage TM SGNL contains an initialization of a resource with an i… | |
| CVE-2025-48928 | 2025-07-01 | 2025-07-22 | 0.6% | — | TeleMessage TM SGNL contains an exposure of core dump file to an unaut… | |
| CVE-2025-6543 | 2025-06-30 | 2025-07-21 | 10.1% | — | Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerabili… | |
| CVE-2024-54085 | 2025-06-25 | 2025-07-16 | 60.7% | — | AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerab… | |
| CVE-2024-0769 | 2025-06-25 | 2025-07-16 | 82.7% | — | D-Link DIR-859 routers contain a path traversal vulnerability in the f… | |
| CVE-2019-6693 | 2025-06-25 | 2025-07-16 | 5.8% | 6.5 | yes | Use of a hard-coded cryptographic key to cipher sensitive data in Fort… |
| CVE-2023-0386 | 2025-06-17 | 2025-07-08 | 7.9% | — | Linux Kernel contains an improper ownership management vulnerability, … | |
| CVE-2023-33538 | 2025-06-16 | 2025-07-07 | 41.9% | — | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain… | |
| CVE-2025-43200 | 2025-06-16 | 2025-07-07 | 1.1% | — | Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecifie… | |
| CVE-2025-33053 | 2025-06-10 | 2025-07-01 | 87.6% | — | Microsoft Windows contains an external control of file name or path vu… | |
| CVE-2025-24016 | 2025-06-10 | 2025-07-01 | 93.8% | — | Wazuh contains a deserialization of untrusted data vulnerability that … | |
| CVE-2025-32433 | 2025-06-09 | 2025-06-30 | 98.8% | — | Erlang Erlang/OTP SSH server contains a missing authentication for cri… | |
| CVE-2024-42009 | 2025-06-09 | 2025-06-30 | 82.9% | — | RoundCube Webmail contains a cross-site scripting vulnerability. This … | |
| CVE-2025-5419 | 2025-06-05 | 2025-06-26 | 7.8% | — | Google Chromium V8 contains an out-of-bounds read and write vulnerabil… | |
| CVE-2025-27038 | 2025-06-03 | 2025-06-24 | 1.0% | — | Multiple Qualcomm chipsets contain a use-after-free vulnerability. Thi… | |
| CVE-2025-21479 | 2025-06-03 | 2025-06-24 | 0.8% | — | Multiple Qualcomm chipsets contain an incorrect authorization vulnerab… | |
| CVE-2025-21480 | 2025-06-03 | 2025-06-24 | 0.5% | — | Multiple Qualcomm chipsets contain an incorrect authorization vulnerab… | |
| CVE-2024-56145 | 2025-06-02 | 2025-06-23 | 97.4% | — | Craft CMS contains a code injection vulnerability. Users with affected… | |
| CVE-2025-35939 | 2025-06-02 | 2025-06-23 | 1.3% | — | Craft CMS contains an external control of assumed-immutable web parame… | |
| CVE-2025-3935 | 2025-06-02 | 2025-06-23 | 3.4% | — | ConnectWise ScreenConnect contains an improper authentication vulnerab… | |
| CVE-2023-39780 | 2025-06-02 | 2025-06-23 | 40.2% | — | ASUS RT-AX55 devices contain an OS command injection vulnerability tha… | |
| CVE-2021-32030 | 2025-06-02 | 2025-06-23 | 99.4% | — | ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authenti… | |
| CVE-2025-4632 | 2025-05-22 | 2025-06-12 | 24.3% | — | Samsung MagicINFO 9 Server contains a path traversal vulnerability tha… | |
| CVE-2025-4427 | 2025-05-19 | 2025-06-09 | 99.9% | — | Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypas… | |
| CVE-2025-4428 | 2025-05-19 | 2025-06-09 | 86.5% | — | Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulner… | |
| CVE-2025-27920 | 2025-05-19 | 2025-06-09 | 1.9% | — | Srimax Output Messenger contains a directory traversal vulnerability t… | |
| CVE-2024-27443 | 2025-05-19 | 2025-06-09 | 23.6% | — | Zimbra Collaboration contains a cross-site scripting (XSS) vulnerabili… | |
| CVE-2024-11182 | 2025-05-19 | 2025-06-09 | 17.7% | — | MDaemon Email Server contains a cross-site scripting (XSS) vulnerabili… | |
| CVE-2023-38950 | 2025-05-19 | 2025-06-09 | 84.7% | — | ZKTeco BioTime contains a path traversal vulnerability in the iclock A… | |
| CVE-2024-12987 | 2025-05-15 | 2025-06-05 | 98.1% | — | DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS comm… | |
| CVE-2025-42999 | 2025-05-15 | 2025-06-05 | 13.9% | 9.1 | yes | SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a p… |
| CVE-2025-32756 | 2025-05-14 | 2025-06-04 | 29.8% | — | Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack… | |
| CVE-2025-32701 | 2025-05-13 | 2025-06-03 | 1.4% | — | Microsoft Windows Common Log File System (CLFS) Driver contains a use-… | |
| CVE-2025-32706 | 2025-05-13 | 2025-06-03 | 2.3% | — | Microsoft Windows Common Log File System (CLFS) Driver contains a heap… | |
| CVE-2025-32709 | 2025-05-13 | 2025-06-03 | 2.1% | — | Microsoft Windows Ancillary Function Driver for WinSock contains a use… | |
| CVE-2025-30397 | 2025-05-13 | 2025-06-03 | 26.8% | — | Microsoft Windows Scripting Engine contains a type confusion vulnerabi… | |
| CVE-2025-30400 | 2025-05-13 | 2025-06-03 | 1.9% | — | Microsoft Windows DWM Core Library contains a use-after-free vulnerabi… | |
| CVE-2025-47729 | 2025-05-12 | 2025-06-02 | 0.4% | — | TeleMessage TM SGNL contains a hidden functionality vulnerability in w… | |
| CVE-2024-6047 | 2025-05-07 | 2025-05-28 | 10.1% | — | Multiple GeoVision devices contain an OS command injection vulnerabili… | |
| CVE-2024-11120 | 2025-05-07 | 2025-05-28 | 28.4% | — | Multiple GeoVision devices contain an OS command injection vulnerabili… | |
| CVE-2025-27363 | 2025-05-06 | 2025-05-27 | 27.8% | — | FreeType contains an out-of-bounds write vulnerability when attempting… | |
| CVE-2025-3248 | 2025-05-05 | 2025-05-26 | 100.0% | — | yes | Langflow contains a missing authentication vulnerability in the /api/v… |
| CVE-2024-58136 | 2025-05-02 | 2025-05-23 | 87.8% | — | Yii Framework contains an improper protection of alternate path vulner… | |
| CVE-2025-34028 | 2025-05-02 | 2025-05-23 | 97.6% | — | Commvault Command Center contains a path traversal vulnerability that … | |
| CVE-2023-44221 | 2025-05-01 | 2025-05-22 | 76.3% | — | SonicWall SMA100 appliances contain an OS command injection vulnerabil… | |
| CVE-2024-38475 | 2025-05-01 | 2025-05-22 | 100.0% | — | Apache HTTP Server contains an improper escaping of output vulnerabili… | |
| CVE-2025-31324 | 2025-04-29 | 2025-05-20 | 99.5% | 10.0 | yes | SAP NetWeaver Visual Composer Metadata Uploader is not protected with … |
| CVE-2025-1976 | 2025-04-28 | 2025-05-19 | 0.7% | — | Broadcom Brocade Fabric OS contains a code injection vulnerability tha… | |
| CVE-2025-3928 | 2025-04-28 | 2025-05-19 | 2.1% | — | Commvault Web Server contains an unspecified vulnerability that allows… | |
| CVE-2025-42599 | 2025-04-28 | 2025-05-19 | 3.3% | — | Qualitia Active! Mail contains a stack-based buffer overflow vulnerabi… | |
| CVE-2025-24054 | 2025-04-17 | 2025-05-08 | 58.9% | — | Microsoft Windows NTLM contains an external control of file name or pa… | |
| CVE-2025-31200 | 2025-04-17 | 2025-05-08 | 18.6% | — | Apple iOS, iPadOS, macOS, and other Apple products contain a memory co… | |
| CVE-2025-31201 | 2025-04-17 | 2025-05-08 | 13.9% | — | Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrar… | |
| CVE-2021-20035 | 2025-04-16 | 2025-05-07 | 4.2% | — | SonicWall SMA100 appliances contain an OS command injection vulnerabil… | |
| CVE-2024-53150 | 2025-04-09 | 2025-04-30 | 1.4% | — | Linux Kernel contains an out-of-bounds read vulnerability in the USB-a… | |
| CVE-2024-53197 | 2025-04-09 | 2025-04-30 | 3.6% | — | Linux Kernel contains an out-of-bounds access vulnerability in the USB… | |
| CVE-2025-30406 | 2025-04-08 | 2025-04-29 | 94.3% | — | Gladinet CentreStack and Triofox contains a use of hard-coded cryptogr… |