CISA Known Exploited Vulnerabilities

Vulnerabilities CISA has confirmed are being actively exploited. These are the top priority — federal agencies have a mandated patch-by date, and so should you. 1,716 entries.

CVEAddedPatch byEPSSCVSSRansomwareWhat
CVE-2025-29824 2025-04-08 2025-04-29 13.9% yes Microsoft Windows Common Log File System (CLFS) Driver contains a use-…
CVE-2025-31161 2025-04-07 2025-04-28 100.0% yes CrushFTP contains an authentication bypass vulnerability in the HTTP a…
CVE-2025-22457 2025-04-04 2025-04-11 100.0% 9.0 yes A stack-based buffer overflow in Ivanti Connect Secure before version …
CVE-2025-24813 2025-04-01 2025-04-22 99.9% Apache Tomcat contains a path equivalence vulnerability that allows a …
CVE-2024-20439 2025-03-31 2025-04-21 92.1% Cisco Smart Licensing Utility contains a static credential vulnerabili…
CVE-2025-2783 2025-03-27 2025-04-17 9.2% Google Chromium Mojo on Windows contains a sandbox escape vulnerabilit…
CVE-2019-9874 2025-03-26 2025-04-16 83.7% Sitecore CMS and Experience Platform (XP) contain a deserialization vu…
CVE-2019-9875 2025-03-26 2025-04-16 14.0% Sitecore CMS and Experience Platform (XP) contain a deserialization vu…
CVE-2025-30154 2025-03-24 2025-04-14 2.4% reviewdog action-setup GitHub Action contains an embedded malicious co…
CVE-2024-48248 2025-03-19 2025-04-09 94.4% NAKIVO Backup and Replication contains an absolute path traversal vuln…
CVE-2025-1316 2025-03-19 2025-04-09 74.5% Edimax IC-7100 IP camera contains an OS command injection vulnerabilit…
CVE-2017-12637 2025-03-19 2025-04-09 95.1% SAP NetWeaver Application Server (AS) Java contains a directory traver…
CVE-2025-30066 2025-03-18 2025-04-08 69.8% tj-actions/changed-files GitHub Action contains an embedded malicious …
CVE-2025-24472 2025-03-18 2025-04-08 7.2% 8.1 yes An Authentication Bypass Using an Alternate Path or Channel vulnerabil…
CVE-2025-24201 2025-03-13 2025-04-03 3.8% Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-b…
CVE-2025-21590 2025-03-13 2025-04-03 1.7% Juniper Junos OS contains an improper isolation or compartmentalizatio…
CVE-2025-24983 2025-03-11 2025-04-01 1.3% Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vul…
CVE-2025-24984 2025-03-11 2025-04-01 2.0% Microsoft Windows New Technology File System (NTFS) contains an insert…
CVE-2025-24985 2025-03-11 2025-04-01 3.8% Microsoft Windows Fast FAT File System Driver contains an integer over…
CVE-2025-26633 2025-03-11 2025-04-01 30.4% 7.0 yes Improper neutralization in Microsoft Management Console allows an unau…
CVE-2025-24991 2025-03-11 2025-04-01 2.0% Microsoft Windows New Technology File System (NTFS) contains an out-of…
CVE-2025-24993 2025-03-11 2025-04-01 2.2% Microsoft Windows New Technology File System (NTFS) contains a heap-ba…
CVE-2025-25181 2025-03-10 2025-03-31 57.0% Advantive VeraCore contains a SQL injection vulnerability in timeoutWa…
CVE-2024-57968 2025-03-10 2025-03-31 32.3% Advantive VeraCore contains an unrestricted file upload vulnerability …
CVE-2024-13159 2025-03-10 2025-03-31 100.0% Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln…
CVE-2024-13160 2025-03-10 2025-03-31 91.2% Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln…
CVE-2024-13161 2025-03-10 2025-03-31 90.1% Ivanti Endpoint Manager (EPM) contains an absolute path traversal vuln…
CVE-2024-50302 2025-03-04 2025-03-25 0.8% The Linux kernel contains a use of uninitialized resource vulnerabilit…
CVE-2025-22224 2025-03-04 2025-03-25 1.6% VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTO…
CVE-2025-22225 2025-03-04 2025-03-25 1.0% 8.2 yes VMware ESXi contains an arbitrary write vulnerability. A malicious act…
CVE-2025-22226 2025-03-04 2025-03-25 1.7% VMware ESXi, Workstation, and Fusion contain an information disclosure…
CVE-2024-4885 2025-03-03 2025-03-24 99.3% Progress WhatsUp Gold contains a path traversal vulnerability that all…
CVE-2018-8639 2025-03-03 2025-03-24 22.2% yes Microsoft Windows Win32k contains an improper resource shutdown or rel…
CVE-2022-43769 2025-03-03 2025-03-24 97.7% Hitachi Vantara Pentaho BA Server contains a special element injection…
CVE-2022-43939 2025-03-03 2025-03-24 92.3% Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL …
CVE-2023-20118 2025-03-03 2025-03-24 54.1% Multiple Cisco Small Business RV Series Routers contains a command inj…
CVE-2023-34192 2025-02-25 2025-03-18 77.3% Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripti…
CVE-2024-49035 2025-02-25 2025-03-18 1.3% Microsoft Partner Center contains an improper access control vulnerabi…
CVE-2024-20953 2025-02-24 2025-03-17 3.9% Oracle Agile Product Lifecycle Management (PLM) contains a deserializa…
CVE-2017-3066 2025-02-24 2025-03-17 90.6% Adobe ColdFusion contains a deserialization vulnerability in the Apach…
CVE-2025-24989 2025-02-21 2025-03-14 1.6% Microsoft Power Pages contains an improper access control vulnerabilit…
CVE-2025-23209 2025-02-20 2025-03-13 21.8% Craft CMS contains a code injection vulnerability caused by improper v…
CVE-2025-0111 2025-02-20 2025-03-13 2.0% Palo Alto Networks PAN-OS contains an external control of file name or…
CVE-2025-0108 2025-02-18 2025-03-11 98.5% Palo Alto Networks PAN-OS contains an authentication bypass vulnerabil…
CVE-2024-53704 2025-02-18 2025-03-11 95.1% 9.8 yes An Improper Authentication vulnerability in the SSLVPN authentication …
CVE-2024-57727 2025-02-13 2025-03-06 95.2% 7.5 yes SimpleHelp remote support software v5.5.7 and before is vulnerable to …
CVE-2025-24200 2025-02-12 2025-03-05 4.5% Apple iOS and iPadOS contains an incorrect authorization vulnerability…
CVE-2024-41710 2025-02-12 2025-03-05 41.6% Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including…
CVE-2024-40890 2025-02-11 2025-03-04 22.3% Multiple Zyxel DSL CPE devices contain a post-authentication command i…
CVE-2024-40891 2025-02-11 2025-03-04 21.5% Multiple Zyxel DSL CPE devices contain a post-authentication command i…
CVE-2025-21391 2025-02-11 2025-03-04 2.3% Microsoft Windows Storage contains a link following vulnerability that…
CVE-2025-21418 2025-02-11 2025-03-04 1.6% Microsoft Windows Ancillary Function Driver for WinSock contains a hea…
CVE-2025-0994 2025-02-07 2025-02-28 31.3% Trimble Cityworks contains a deserialization vulnerability. This could…
CVE-2025-0411 2025-02-06 2025-02-27 67.1% 7-Zip contains a protection mechanism failure vulnerability that allow…
CVE-2024-21413 2025-02-06 2025-02-27 94.7% 9.8 Microsoft Outlook Remote Code Execution Vulnerability
CVE-2022-23748 2025-02-06 2025-02-27 9.1% Dante Discovery contains a process control vulnerability in mDNSRespon…
CVE-2020-29574 2025-02-06 2025-02-27 4.7% 9.8 yes An SQL injection vulnerability in the WebAdmin of Cyberoam OS through …
CVE-2020-15069 2025-02-06 2025-02-27 10.7% Sophos XG Firewall contains a buffer overflow vulnerability that allow…
CVE-2024-53104 2025-02-05 2025-02-26 3.4% Linux kernel contains an out-of-bounds write vulnerability in the uvc_…
CVE-2024-45195 2025-02-04 2025-02-25 100.0% Apache OFBiz contains a forced browsing vulnerability that allows a re…
CVE-2024-29059 2025-02-04 2025-02-25 98.6% Microsoft .NET Framework contains an information disclosure vulnerabil…
CVE-2018-19410 2025-02-04 2025-02-25 97.9% Paessler PRTG Network Monitor contains a local file inclusion vulnerab…
CVE-2018-9276 2025-02-04 2025-02-25 87.0% Paessler PRTG Network Monitor contains an OS command injection vulnera…
CVE-2025-24085 2025-01-29 2025-02-19 17.6% Apple iOS, macOS, and other Apple products contain a user-after-free v…
CVE-2025-23006 2025-01-24 2025-02-14 23.4% 9.8 yes Pre-authentication deserialization of untrusted data vulnerability has…
CVE-2020-11023 2025-01-23 2025-02-13 84.9% JQuery contains a persistent cross-site scripting (XSS) vulnerability.…
CVE-2024-50603 2025-01-16 2025-02-06 98.5% Aviatrix Controllers contain an OS command injection vulnerability tha…
CVE-2024-55591 2025-01-14 2025-01-21 98.3% 9.8 yes An Authentication Bypass Using an Alternate Path or Channel vulnerabil…
CVE-2025-21333 2025-01-14 2025-02-04 10.0% Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-ba…
CVE-2025-21334 2025-01-14 2025-02-04 1.6% Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-aft…
CVE-2025-21335 2025-01-14 2025-02-04 1.4% Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-aft…
CVE-2024-12686 2025-01-13 2025-02-03 13.8% BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) con…
CVE-2023-48365 2025-01-13 2025-02-03 24.5% yes Qlik Sense contains an HTTP tunneling vulnerability that allows an att…
CVE-2025-0282 2025-01-08 2025-01-15 100.0% 9.0 yes A stack-based buffer overflow in Ivanti Connect Secure before version …
CVE-2024-55550 2025-01-07 2025-01-28 37.9% 2.7 yes Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker w…
CVE-2024-41713 2025-01-07 2025-01-28 98.1% 9.1 yes A vulnerability in the NuPoint Unified Messaging (NPM) component of Mi…
CVE-2020-2883 2025-01-07 2025-01-28 94.9% Oracle WebLogic Server, a product within the Fusion Middleware suite, …
CVE-2024-3393 2024-12-30 2025-01-20 28.4% Palo Alto Networks PAN-OS contains a vulnerability in parsing and logg…
CVE-2021-44207 2024-12-23 2025-01-13 17.6% Acclaim Systems USAHERDS contains a hard-coded credentials vulnerabili…
CVE-2024-12356 2024-12-19 2024-12-27 88.0% BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) con…
CVE-2022-23227 2024-12-18 2025-01-08 48.5% NUUO NVRmini2 devices contain a missing authentication vulnerability t…
CVE-2021-40407 2024-12-18 2025-01-08 47.6% Reolink RLC-410W IP cameras contain an authenticated OS command inject…
CVE-2019-11001 2024-12-18 2025-01-08 37.5% Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras co…
CVE-2018-14933 2024-12-18 2025-01-08 94.9% NUUO NVRmini devices contain an OS command injection vulnerability. Th…
CVE-2024-55956 2024-12-17 2025-01-07 94.0% 9.8 yes In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom…
CVE-2024-20767 2024-12-16 2025-01-06 98.5% Adobe ColdFusion contains an improper access control vulnerability tha…
CVE-2024-35250 2024-12-16 2025-01-06 25.0% Microsoft Windows Kernel-Mode Driver contains an untrusted pointer der…
CVE-2024-50623 2024-12-13 2025-01-03 98.6% 9.8 yes In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom…
CVE-2024-49138 2024-12-10 2024-12-31 26.2% Microsoft Windows Common Log File System (CLFS) driver contains a heap…
CVE-2024-51378 2024-12-04 2024-12-25 94.7% 10.0 yes getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyb…
CVE-2024-11667 2024-12-03 2024-12-24 2.9% 7.5 yes A directory traversal vulnerability in the web management interface of…
CVE-2024-11680 2024-12-03 2024-12-24 91.7% ProjectSend contains an improper authentication vulnerability that all…
CVE-2023-45727 2024-12-03 2024-12-24 3.5% North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize con…
CVE-2023-28461 2024-11-25 2024-12-16 68.1% 9.8 yes Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow …
CVE-2024-21287 2024-11-21 2024-12-12 1.7% Oracle Agile Product Lifecycle Management (PLM) contains an incorrect …
CVE-2024-44308 2024-11-21 2024-12-12 10.2% Apple iOS, macOS, and other Apple products contain an unspecified vuln…
CVE-2024-44309 2024-11-21 2024-12-12 22.6% Apple iOS, macOS, and other Apple products contain an unspecified vuln…
CVE-2024-38812 2024-11-20 2024-12-11 54.6% VMware vCenter Server contains a heap-based buffer overflow vulnerabil…
CVE-2024-38813 2024-11-20 2024-12-11 17.4% VMware vCenter contains an improper check for dropped privileges vulne…
CVE-2024-1212 2024-11-18 2024-12-09 95.4% Progress Kemp LoadMaster contains an OS command injection vulnerabilit…
← Prev Page 5 of 18 Next →