CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2024-0012 2024-11-18 2024-12-09 99.7% 9.8 yes An authentication bypass in Palo Alto Networks PAN-OS software enables…
CVE-2024-9474 2024-11-18 2024-12-09 94.7% 7.2 yes A privilege escalation vulnerability in Palo Alto Networks PAN-OS soft…
CVE-2024-9463 2024-11-14 2024-12-05 98.5% Palo Alto Networks Expedition contains an OS command injection vulnera…
CVE-2024-9465 2024-11-14 2024-12-05 99.6% Palo Alto Networks Expedition contains a SQL injection vulnerability t…
CVE-2024-43451 2024-11-12 2024-12-03 84.1% Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that …
CVE-2024-49039 2024-11-12 2024-12-03 14.2% 8.8 yes Windows Task Scheduler Elevation of Privilege Vulnerability
CVE-2021-41277 2024-11-12 2024-12-03 97.2% Metabase contains a local file inclusion vulnerability in the custom m…
CVE-2021-26086 2024-11-12 2024-12-03 100.0% Atlassian Jira Server and Data Center contain a path traversal vulnera…
CVE-2014-2120 2024-11-12 2024-12-03 18.8% Cisco Adaptive Security Appliance (ASA) contains a cross-site scriptin…
CVE-2019-16278 2024-11-07 2024-11-28 99.0% Nostromo nhttpd contains a directory traversal vulnerability in the ht…
CVE-2024-51567 2024-11-07 2024-11-28 86.6% 10.0 yes upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Pane…
CVE-2024-5910 2024-11-07 2024-11-28 91.8% Palo Alto Networks Expedition contains a missing authentication vulner…
CVE-2024-43093 2024-11-07 2024-11-28 0.7% Android Framework contains an unspecified vulnerability that allows fo…
CVE-2024-8956 2024-11-04 2024-11-25 61.3% PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object refe…
CVE-2024-8957 2024-11-04 2024-11-25 81.0% PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulner…
CVE-2024-37383 2024-10-24 2024-11-14 73.3% RoundCube Webmail contains a cross-site scripting (XSS) vulnerability …
CVE-2024-20481 2024-10-24 2024-11-14 15.8% 5.8 A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adap…
CVE-2024-47575 2024-10-23 2024-11-13 95.1% Fortinet FortiManager contains a missing authentication vulnerability …
CVE-2024-38094 2024-10-22 2024-11-12 50.9% yes Microsoft SharePoint contains a deserialization vulnerability that all…
CVE-2024-9537 2024-10-21 2024-11-11 3.8% ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerab…
CVE-2024-40711 2024-10-17 2024-11-07 90.4% yes Veeam Backup and Replication contains a deserialization vulnerability …
CVE-2024-30088 2024-10-15 2024-11-05 68.2% 7.0 yes Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-28987 2024-10-15 2024-11-05 93.2% SolarWinds Web Help Desk contains a hardcoded credential vulnerability…
CVE-2024-9680 2024-10-15 2024-11-05 23.2% 9.8 yes An attacker was able to achieve code execution in the content process …
CVE-2024-9379 2024-10-09 2024-10-30 43.8% Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnera…
CVE-2024-9380 2024-10-09 2024-10-30 63.2% Ivanti Cloud Services Appliance (CSA) contains an OS command injection…
CVE-2024-23113 2024-10-09 2024-10-30 61.7% Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format …
CVE-2024-43047 2024-10-08 2024-10-29 0.7% Multiple Qualcomm chipsets contain a use-after-free vulnerability due …
CVE-2024-43572 2024-10-08 2024-10-29 66.7% Microsoft Windows Management Console contains unspecified vulnerabilit…
CVE-2024-43573 2024-10-08 2024-10-29 46.1% Microsoft Windows MSHTML Platform contains an unspecified spoofing vul…
CVE-2024-45519 2024-10-03 2024-10-24 99.9% Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulne…
CVE-2024-29824 2024-10-02 2024-10-23 100.0% Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability i…
CVE-2019-0344 2024-09-30 2024-10-21 7.1% SAP Commerce Cloud (formerly known as Hybris) contains a deserializati…
CVE-2020-15415 2024-09-30 2024-10-21 84.5% DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS comm…
CVE-2023-25280 2024-09-30 2024-10-21 97.9% D-Link DIR-820 routers contain an OS command injection vulnerability t…
CVE-2024-7593 2024-09-24 2024-10-15 100.0% Ivanti Virtual Traffic Manager contains an authentication bypass vulne…
CVE-2024-8963 2024-09-19 2024-10-10 98.6% Ivanti Cloud Services Appliance (CSA) contains a path traversal vulner…
CVE-2024-27348 2024-09-18 2024-10-09 99.2% Apache HugeGraph-Server contains an improper access control vulnerabil…
CVE-2022-21445 2024-09-18 2024-10-09 62.5% Oracle ADF Faces library, included with Oracle JDeveloper Distribution…
CVE-2020-14644 2024-09-18 2024-10-09 94.5% Oracle WebLogic Server, a product within the Fusion Middleware suite, …
CVE-2020-0618 2024-09-18 2024-10-09 99.0% 8.8 yes A remote code execution vulnerability exists in Microsoft SQL Server R…
CVE-2014-0497 2024-09-17 2024-10-08 99.9% Adobe Flash Player contains an integer underflow vulnerability that al…
CVE-2014-0502 2024-09-17 2024-10-08 24.8% Adobe Flash Player contains a double free vulnerability that allows a …
CVE-2013-0643 2024-09-17 2024-10-08 10.5% Adobe Flash Player contains an incorrect default permissions vulnerabi…
CVE-2013-0648 2024-09-17 2024-10-08 11.1% Adobe Flash Player contains an unspecified vulnerability in the Extern…
CVE-2024-6670 2024-09-16 2024-10-07 93.0% yes Progress WhatsUp Gold contains a SQL injection vulnerability that allo…
CVE-2024-43461 2024-09-16 2024-10-07 54.5% 8.8 Windows MSHTML Platform Spoofing Vulnerability
CVE-2024-8190 2024-09-13 2024-10-04 88.5% Ivanti Cloud Services Appliance (CSA) contains an OS command injection…
CVE-2024-38217 2024-09-10 2024-10-01 10.0% 5.4 Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-38226 2024-09-10 2024-10-01 2.7% 7.3 Microsoft Publisher Security Feature Bypass Vulnerability
CVE-2024-38014 2024-09-10 2024-10-01 6.3% 7.8 Windows Installer Elevation of Privilege Vulnerability
CVE-2024-40766 2024-09-09 2024-09-30 18.2% yes SonicWall SonicOS contains an improper access control vulnerability th…
CVE-2017-1000253 2024-09-09 2024-09-30 10.7% yes Linux kernel contains a position-independent executable (PIE) stack bu…
CVE-2016-3714 2024-09-09 2024-09-30 97.5% ImageMagick contains an improper input validation vulnerability that a…
CVE-2021-20123 2024-09-03 2024-09-24 90.2% Draytek VigorConnect contains a path traversal vulnerability in the Do…
CVE-2021-20124 2024-09-03 2024-09-24 96.3% Draytek VigorConnect contains a path traversal vulnerability in the fi…
CVE-2024-7262 2024-09-03 2024-09-24 2.9% Kingsoft WPS Office contains a path traversal vulnerability in promece…
CVE-2024-7965 2024-08-28 2024-09-18 18.5% Google Chromium V8 contains an inappropriate implementation vulnerabil…
CVE-2024-38856 2024-08-27 2024-09-17 99.4% Apache OFBiz contains an incorrect authorization vulnerability that co…
CVE-2024-7971 2024-08-26 2024-09-16 20.7% Google Chromium V8 contains a type confusion vulnerability that allows…
CVE-2024-39717 2024-08-23 2024-09-13 4.0% The Versa Director GUI contains an unrestricted upload of file with da…
CVE-2021-33044 2024-08-21 2024-09-11 99.9% Dahua IP cameras and related products contain an authentication bypass…
CVE-2021-33045 2024-08-21 2024-09-11 99.6% Dahua IP cameras and related products contain an authentication bypass…
CVE-2021-31196 2024-08-21 2024-09-11 54.1% 7.2 Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-0185 2024-08-21 2024-09-11 25.2% Linux kernel contains a heap-based buffer overflow vulnerability in th…
CVE-2024-23897 2024-08-19 2024-09-09 100.0% yes Jenkins Command Line Interface (CLI) contains a path traversal vulnera…
CVE-2024-28986 2024-08-15 2024-09-05 84.6% SolarWinds Web Help Desk contains a deserialization of untrusted data …
CVE-2024-38178 2024-08-13 2024-09-03 41.4% Microsoft Windows Scripting Engine contains a memory corruption vulner…
CVE-2024-38189 2024-08-13 2024-09-03 8.2% Microsoft Project contains an unspecified vulnerability that allows fo…
CVE-2024-38193 2024-08-13 2024-09-03 28.5% Microsoft Windows Ancillary Function Driver for WinSock contains an un…
CVE-2024-38213 2024-08-13 2024-09-03 13.6% Microsoft Windows SmartScreen contains a security feature bypass vulne…
CVE-2024-38106 2024-08-13 2024-09-03 6.3% Microsoft Windows Kernel contains an unspecified vulnerability that al…
CVE-2024-38107 2024-08-13 2024-09-03 1.6% Microsoft Windows Power Dependency Coordinator contains an unspecified…
CVE-2024-36971 2024-08-07 2024-08-28 2.7% Android contains an unspecified vulnerability in the kernel that allow…
CVE-2024-32113 2024-08-07 2024-08-28 99.4% Apache OFBiz contains a path traversal vulnerability that could allow …
CVE-2018-0824 2024-08-05 2024-08-26 73.2% Microsoft COM for Windows contains a deserialization of untrusted data…
CVE-2024-37085 2024-07-30 2024-08-20 26.8% yes VMware ESXi contains an authentication bypass vulnerability. A malicio…
CVE-2023-45249 2024-07-29 2024-08-19 53.3% Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to e…
CVE-2024-4879 2024-07-29 2024-08-19 100.0% ServiceNow Utah, Vancouver, and Washington DC Now Platform releases co…
CVE-2024-5217 2024-07-29 2024-08-19 99.6% ServiceNow Washington DC, Vancouver, and earlier Now Platform releases…
CVE-2024-39891 2024-07-23 2024-08-13 1.7% Twilio Authy contains an information disclosure vulnerability in its A…
CVE-2012-4792 2024-07-23 2024-08-13 78.8% Microsoft Internet Explorer contains a use-after-free vulnerability th…
CVE-2022-22948 2024-07-17 2024-08-07 13.3% VMware vCenter Server contains an incorrect default file permissions v…
CVE-2024-34102 2024-07-17 2024-08-07 100.0% Adobe Commerce and Magento Open Source contain an improper restriction…
CVE-2024-28995 2024-07-17 2024-08-07 99.6% SolarWinds Serv-U contains a path traversal vulnerability that allows …
CVE-2024-36401 2024-07-15 2024-08-05 99.8% OSGeo GeoServer GeoTools contains an improper neutralization of direct…
CVE-2024-23692 2024-07-09 2024-07-30 99.5% 9.8 yes Rejetto HTTP File Server, up to and including version 2.3m, is vulnera…
CVE-2024-38080 2024-07-09 2024-07-30 7.1% Microsoft Windows Hyper-V contains a privilege escalation vulnerabilit…
CVE-2024-38112 2024-07-09 2024-07-30 84.2% Microsoft Windows MSHTML Platform contains a spoofing vulnerability th…
CVE-2024-20399 2024-07-02 2024-07-23 4.3% Cisco NX-OS contains a command injection vulnerability in the command …
CVE-2022-24816 2024-06-26 2024-07-17 98.5% OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, …
CVE-2022-2586 2024-06-26 2024-07-17 10.5% 5.3 It was discovered that a nft object or expression could reference a nf…
CVE-2020-13965 2024-06-26 2024-07-17 76.6% Roundcube Webmail contains a cross-site scripting (XSS) vulnerability …
CVE-2024-4358 2024-06-13 2024-07-04 97.5% Progress Telerik Report Server contains an authorization bypass by spo…
CVE-2024-26169 2024-06-13 2024-07-04 4.0% yes Microsoft Windows Error Reporting Service contains an improper privile…
CVE-2024-32896 2024-06-13 2024-07-04 3.0% Android Pixel contains an unspecified vulnerability in the firmware th…
CVE-2024-4577 2024-06-12 2024-07-03 100.0% yes PHP, specifically Windows-based PHP used in CGI mode, contains an OS c…
CVE-2024-4610 2024-06-12 2024-07-03 0.8% Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vu…
CVE-2017-3506 2024-06-03 2024-06-24 96.3% Oracle WebLogic Server, a product within the Fusion Middleware suite, …
CVE-2024-24919 2024-05-30 2024-06-20 100.0% 8.6 yes Potentially allowing an attacker to read certain information on Check …
← Prev Page 6 of 18 Next →