⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
1,721 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2024-57727 SimpleHelp SimpleHelp SimpleHelp Path Traversal Vulnerability SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. 9.1 CISA 2025-02-13 2025-03-06 Known
CVE-2024-41710 Mitel SIP Phones Mitel SIP Phones Argument Injection Vulnerability Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. 6.8 CISA 2025-02-12 2025-03-05 Unknown
CVE-2025-24200 Apple iOS and iPadOS Apple iOS and iPadOS Incorrect Authorization Vulnerability Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. 6.1 CISA 2025-02-12 2025-03-05 Unknown
CVE-2025-21391 Microsoft Windows Microsoft Windows Storage Link Following Vulnerability Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. 7.1 CNA 2025-02-11 2025-03-04 Unknown
CVE-2025-21418 Microsoft Windows Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-02-11 2025-03-04 Unknown
CVE-2024-40890 Zyxel DSL CPE Devices Zyxel DSL CPE OS Command Injection Vulnerability Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. 8.8 CNA 2025-02-11 2025-03-04 Unknown
CVE-2024-40891 Zyxel DSL CPE Devices Zyxel DSL CPE OS Command Injection Vulnerability Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. 8.8 CNA 2025-02-11 2025-03-04 Unknown
CVE-2025-0994 Trimble Cityworks Trimble Cityworks Deserialization Vulnerability Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server. 8.6 CNA 2025-02-07 2025-02-28 Unknown
CVE-2025-0411 7-Zip 7-Zip 7-Zip Mark of the Web Bypass Vulnerability 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user. 7.0 CNA 2025-02-06 2025-02-27 Unknown
CVE-2022-23748 Audinate Dante Discovery Dante Discovery Process Control Vulnerability Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code. 7.8 CISA 2025-02-06 2025-02-27 Unknown
CVE-2024-21413 Microsoft Office Outlook Microsoft Outlook Improper Input Validation Vulnerability Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. 9.8 CNA 2025-02-06 2025-02-27 Unknown
CVE-2020-29574 Sophos CyberoamOS CyberoamOS (CROS) SQL Injection Vulnerability CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. 9.8 CISA 2025-02-06 2025-02-27 Known
CVE-2020-15069 Sophos XG Firewall Sophos XG Firewall Buffer Overflow Vulnerability Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. 9.8 CISA 2025-02-06 2025-02-27 Unknown
CVE-2024-53104 Linux Kernel Linux Kernel Out-of-Bounds Write Vulnerability Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. 7.8 CISA 2025-02-05 2025-02-26 Unknown
CVE-2024-45195 Apache OFBiz Apache OFBiz Forced Browsing Vulnerability Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. 9.8 CISA 2025-02-04 2025-02-25 Unknown
CVE-2024-29059 Microsoft .NET Framework Microsoft .NET Framework Information Disclosure Vulnerability Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. 7.5 CNA 2025-02-04 2025-02-25 Unknown
CVE-2018-9276 Paessler PRTG Network Monitor Paessler PRTG Network Monitor OS Command Injection Vulnerability Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. 7.2 CISA 2025-02-04 2025-02-25 Unknown
CVE-2018-19410 Paessler PRTG Network Monitor Paessler PRTG Network Monitor Local File Inclusion Vulnerability Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). 9.8 CISA 2025-02-04 2025-02-25 Unknown
CVE-2025-24085 Apple Multiple Products Apple Multiple Products Use-After-Free Vulnerability Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. 10.0 CISA 2025-01-29 2025-02-19 Unknown
CVE-2025-23006 SonicWall SMA1000 Appliances SonicWall SMA1000 Appliances Deserialization Vulnerability SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands. 9.8 CISA 2025-01-24 2025-02-14 Known
CVE-2020-11023 JQuery JQuery JQuery Cross-Site Scripting (XSS) Vulnerability JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser. 6.9 CNA 2025-01-23 2025-02-13 Unknown
CVE-2024-50603 Aviatrix Controllers Aviatrix Controllers OS Command Injection Vulnerability Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test. 10.0 CNA 2025-01-16 2025-02-06 Unknown
CVE-2024-55591 Fortinet FortiOS and FortiProxy Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. 9.6 CNA 2025-01-14 2025-01-21 Known
CVE-2025-21333 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2025-21334 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2025-21335 Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. 7.8 CNA 2025-01-14 2025-02-04 Unknown
CVE-2024-12686 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user. 6.6 CNA 2025-01-13 2025-02-03 Unknown
CVE-2023-48365 Qlik Sense Qlik Sense HTTP Tunneling Vulnerability Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. 9.6 CNA 2025-01-13 2025-02-03 Known
CVE-2025-0282 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. 9.0 CNA 2025-01-08 2025-01-15 Known
CVE-2024-41713 Mitel MiCollab Mitel MiCollab Path Traversal Vulnerability Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. 9.1 CISA 2025-01-07 2025-01-28 Known
CVE-2024-55550 Mitel MiCollab Mitel MiCollab Path Traversal Vulnerability Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. 4.4 CISA 2025-01-07 2025-01-28 Known
CVE-2020-2883 Oracle WebLogic Server Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3. 9.8 CNA 2025-01-07 2025-01-28 Unknown
CVE-2024-3393 Palo Alto Networks PAN-OS Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode. 8.7 CNA 2024-12-30 2025-01-20 Unknown
CVE-2021-44207 Acclaim Systems USAHERDS Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel. 8.1 CISA 2024-12-23 2025-01-13 Unknown
CVE-2024-12356 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user. 9.8 CNA 2024-12-19 2024-12-27 Unknown
CVE-2018-14933 NUUO NVRmini Devices NUUO NVRmini Devices OS Command Injection Vulnerability NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. 9.8 CISA 2024-12-18 2025-01-08 Unknown
CVE-2022-23227 NUUO NVRmini2 Devices NUUO NVRmini2 Devices Missing Authentication Vulnerability NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. 9.8 CISA 2024-12-18 2025-01-08 Unknown
CVE-2019-11001 Reolink Multiple IP Cameras Reolink Multiple IP Cameras OS Command Injection Vulnerability Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root. 7.2 CISA 2024-12-18 2025-01-08 Unknown
CVE-2021-40407 Reolink RLC-410W IP Camera Reolink RLC-410W IP Camera OS Command Injection Vulnerability Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality. 9.1 CNA 2024-12-18 2025-01-08 Unknown
CVE-2024-55956 Cleo Multiple Products Cleo Multiple Products Unauthenticated File Upload Vulnerability Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. 9.8 CISA 2024-12-17 2025-01-07 Known
CVE-2024-20767 Adobe ColdFusion Adobe ColdFusion Improper Access Control Vulnerability Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. 7.4 CNA 2024-12-16 2025-01-06 Unknown
CVE-2024-35250 Microsoft Windows Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. 7.8 CNA 2024-12-16 2025-01-06 Unknown
CVE-2024-50623 Cleo Multiple Products Cleo Multiple Products Unrestricted File Upload Vulnerability Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges. 9.8 CISA 2024-12-13 2025-01-03 Known
CVE-2024-49138 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. 7.8 CNA 2024-12-10 2024-12-31 Unknown
CVE-2024-51378 CyberPersons CyberPanel CyberPanel Incorrect Default Permissions Vulnerability CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property. 10.0 CNA 2024-12-04 2024-12-25 Known
CVE-2023-45727 North Grid Proself North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack. 7.5 CISA 2024-12-03 2024-12-24 Unknown
CVE-2024-11680 ProjectSend ProjectSend ProjectSend Improper Authentication Vulnerability ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. 9.8 CNA 2024-12-03 2024-12-24 Unknown
CVE-2024-11667 Zyxel Multiple Firewalls Zyxel Multiple Firewalls Path Traversal Vulnerability Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. 7.5 CNA 2024-12-03 2024-12-24 Known
CVE-2023-28461 Array Networks AG/vxAG ArrayOS Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway. 9.8 CISA 2024-11-25 2024-12-16 Known
CVE-2024-44308 Apple Multiple Products Apple Multiple Products Code Execution Vulnerability Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution. 8.8 CISA 2024-11-21 2024-12-12 Unknown