⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 26 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2025-29635 D-Link DIR-823X D-Link DIR-823X Command Injection Vulnerability D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. 7.2 CISA 2026-04-24 2026-05-08 Unknown
CVE-2022-37055 D-Link Routers D-Link Routers Buffer Overflow Vulnerability D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. 9.8 CISA 2025-12-08 2025-12-29 Unknown
CVE-2022-40799 D-Link DNR-322L D-Link DNR-322L Download of Code Without Integrity Check Vulnerability D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. 8.8 CISA 2025-08-05 2025-08-26 Unknown
CVE-2020-25079 D-Link DCS-2530L and DCS-2670L Devices D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. 8.8 CISA 2025-08-05 2025-08-26 Unknown
CVE-2020-25078 D-Link DCS-2530L and DCS-2670L Devices D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. 7.5 CISA 2025-08-05 2025-08-26 Unknown
CVE-2024-0769 D-Link DIR-859 Router D-Link DIR-859 Router Path Traversal Vulnerability D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. 5.3 CNA 2025-06-25 2025-07-16 Unknown
CVE-2023-25280 D-Link DIR-820 Router D-Link DIR-820 Router OS Command Injection Vulnerability D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. 9.8 CISA 2024-09-30 2024-10-21 Unknown
CVE-2014-100005 D-Link DIR-600 Router D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. 8.0 CISA 2024-05-16 2024-06-06 Unknown
CVE-2021-40655 D-Link DIR-605 Router D-Link DIR-605 Router Information Disclosure Vulnerability D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. 7.5 CISA 2024-05-16 2024-06-06 Unknown
CVE-2024-3272 D-Link Multiple NAS Devices D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. 9.8 CNA 2024-04-11 2024-05-02 Unknown
CVE-2024-3273 D-Link Multiple NAS Devices D-Link Multiple NAS Devices Command Injection Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. 7.3 CNA 2024-04-11 2024-05-02 Unknown
CVE-2016-20017 D-Link DSL-2750B Devices D-Link DSL-2750B Devices Command Injection Vulnerability D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. 9.8 CISA 2024-01-08 2024-01-29 Unknown
CVE-2019-20500 D-Link DWL-2600AP Access Point D-Link DWL-2600AP Access Point Command Injection Vulnerability D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. 7.8 CISA 2023-06-29 2023-07-20 Unknown
CVE-2019-17621 D-Link DIR-859 Router D-Link DIR-859 Router Command Execution Vulnerability D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. 9.8 CISA 2023-06-29 2023-07-20 Unknown
CVE-2011-4723 D-Link DIR-300 Router D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. 5.7 CISA 2022-09-08 2022-09-29 Unknown
CVE-2018-6530 D-Link Multiple Routers D-Link Multiple Routers OS Command Injection Vulnerability Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. 9.8 CISA 2022-09-08 2022-09-29 Known
CVE-2022-26258 D-Link DIR-820L D-Link DIR-820L Remote Code Execution Vulnerability D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. 9.8 CISA 2022-09-08 2022-09-29 Unknown
CVE-2019-16057 D-Link DNS-320 Storage Device D-Link DNS-320 Remote Code Execution Vulnerability The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. 9.8 CISA 2022-04-15 2022-05-06 Known
CVE-2021-45382 D-Link Multiple Routers D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. 9.8 CISA 2022-04-04 2022-04-25 Unknown
CVE-2013-5223 D-Link DSL-2760U D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. 5.4 CISA 2022-03-25 2022-04-15 Unknown
CVE-2016-11021 D-Link DCS-930L Devices D-Link DCS-930L Devices OS Command Injection Vulnerability setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. 7.2 CISA 2022-03-25 2022-04-15 Unknown
CVE-2019-16920 D-Link Multiple Routers D-Link Multiple Routers Command Injection Vulnerability Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise. 9.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2020-9377 D-Link DIR-610 Devices D-Link DIR-610 Devices Remote Command Execution D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php. 8.8 CISA 2022-03-25 2022-04-15 Unknown
CVE-2015-2051 D-Link DIR-645 Router D-Link DIR-645 Router Remote Code Execution Vulnerability D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. 8.8 CISA 2022-02-10 2022-08-10 Unknown
CVE-2020-25506 D-Link DNS-320 Device D-Link DNS-320 Device Command Injection Vulnerability D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Unknown
CVE-2020-29557 D-Link DIR-825 R1 Devices D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. 9.8 CISA 2021-11-03 2022-05-03 Unknown