⚠
About the KEV Catalog For the benefit of the cybersecurity community and network defenders — and to help every organization better manage vulnerabilities and keep pace with threat activity — CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Per Binding Operational Directive 22-01, all federal civilian executive branch (FCEB) agencies are required to remediate KEV catalog vulnerabilities by their listed due dates. CISA strongly recommends all organizations — including private sector entities — prioritize remediation of KEV catalog vulnerabilities. View the full KEV catalog on CISA.gov →
Total KEVs
1,721
in CISA catalog
Ransomware-Linked
360
21% of catalog
Added Last 30 Days
46
92 in last 90 days
Latest Addition
2026-09-22
most recent entry
Tracked Vendors
20+
top 20 shown

Top Vendors

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

388
117 RW · 30%
99
7 RW · 7%
94
81
11 RW · 14%
75
46
13 RW · 28%
40
8 RW · 20%
35
12 RW · 34%
31
2 RW · 6%
30
14 RW · 47%
26
9 RW · 35%
26
2 RW · 8%
24
7 RW · 29%
19
13 RW · 68%
19
6 RW · 32%
17
15
6 RW · 40%
15
SAP
14
3 RW · 21%
13
1 RW · 8%

Top Products

KEV count 21%+ ransomware-linked 42%+ ransomware-linked N RW · %Ransomware-linked share

Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.

Windows · Microsoft
174
49 RW · 28%
Multiple Products · Apple
53
Chromium V8 · Google
41
Internet Explorer · Microsoft
36
6 RW · 17%
Flash Player · Adobe
33
5 RW · 15%
Kernel · Linux
31
2 RW · 6%
Office · Microsoft
29
3 RW · 10%
Win32k · Microsoft
25
11 RW · 44%
Exchange Server · Microsoft
17
13 RW · 76%
Zimbra Collaboration Suite (ZCS) · Synacor
17
5 RW · 29%
ColdFusion · Adobe
16
3 RW · 19%
SharePoint · Microsoft
14
8 RW · 57%
IOS and IOS XE Software · Cisco
14
Acrobat and Reader · Adobe
13
1 RW · 8%
Mobile Devices · Samsung
13
PAN-OS · Palo Alto Networks
12
6 RW · 50%
WebLogic Server · Oracle
12
2 RW · 17%
iOS, iPadOS, and macOS · Apple
11
Multiple Chipsets · Qualcomm
11
NetWeaver · SAP
10
2 RW · 20%
Clear 388 entries
CVE Vendor Product Vulnerability CVSS Added Due per BOD 22-01 Ransomware
CVE-2024-38080 Microsoft Windows Microsoft Windows Hyper-V Privilege Escalation Vulnerability Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. 7.8 CNA 2024-07-09 2024-07-30 Unknown
CVE-2024-26169 Microsoft Windows Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. 7.8 CNA 2024-06-13 2024-07-04 Known
CVE-2024-30051 Microsoft DWM Core Library Microsoft DWM Core Library Privilege Escalation Vulnerability Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. 7.8 CNA 2024-05-14 2024-06-04 Known
CVE-2024-30040 Microsoft Windows Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass. 8.8 CISA 2024-05-14 2024-06-04 Unknown
CVE-2024-29988 Microsoft SmartScreen Prompt Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. 8.8 CNA 2024-04-30 2024-05-21 Unknown
CVE-2022-38028 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. 7.8 CNA 2024-04-23 2024-05-14 Unknown
CVE-2023-24955 Microsoft SharePoint Microsoft SharePoint Server Code Injection Vulnerability Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. 7.2 CNA 2024-03-26 2024-04-16 Known
CVE-2024-21338 Microsoft Windows Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. 7.8 CNA 2024-03-04 2024-03-25 Known
CVE-2023-29360 Microsoft Streaming Service Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. 8.4 CNA 2024-02-29 2024-03-21 Unknown
CVE-2024-21410 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. 9.8 CNA 2024-02-15 2024-03-07 Unknown
CVE-2024-21351 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. 7.6 CNA 2024-02-13 2024-03-05 Unknown
CVE-2024-21412 Microsoft Windows Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. 8.1 CNA 2024-02-13 2024-03-05 Known
CVE-2023-29357 Microsoft SharePoint Microsoft SharePoint Server Privilege Escalation Vulnerability Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. 9.8 CNA 2024-01-10 2024-01-31 Known
CVE-2023-36584 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. 5.4 CNA 2023-11-16 2023-12-07 Unknown
CVE-2023-36036 Microsoft Windows Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges. 7.8 CNA 2023-11-14 2023-12-05 Unknown
CVE-2023-36025 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. 8.8 CNA 2023-11-14 2023-12-05 Unknown
CVE-2023-36033 Microsoft Windows Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-11-14 2023-12-05 Unknown
CVE-2023-36563 Microsoft WordPad Microsoft WordPad Information Disclosure Vulnerability Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure. 6.5 CNA 2023-10-10 2023-10-31 Unknown
CVE-2023-41763 Microsoft Skype for Business Microsoft Skype for Business Privilege Escalation Vulnerability Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation. 5.3 CNA 2023-10-10 2023-10-31 Unknown
CVE-2023-28229 Microsoft Windows CNG Key Isolation Service Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. 7.0 CNA 2023-10-04 2023-10-25 Unknown
CVE-2023-36802 Microsoft Streaming Service Proxy Microsoft Streaming Service Proxy Privilege Escalation Vulnerability Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-09-12 2023-10-03 Unknown
CVE-2023-36761 Microsoft Word Microsoft Word Information Disclosure Vulnerability Microsoft Word contains an unspecified vulnerability that allows for information disclosure. 6.5 CNA 2023-09-12 2023-10-03 Unknown
CVE-2023-38180 Microsoft .NET Core and Visual Studio Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). 7.5 CNA 2023-08-09 2023-08-30 Unknown
CVE-2023-36884 Microsoft Windows Microsoft Windows Search Remote Code Execution Vulnerability Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. 7.5 CNA 2023-07-17 2023-08-29 Known
CVE-2023-36874 Microsoft Windows Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-07-11 2023-08-01 Unknown
CVE-2023-35311 Microsoft Outlook Microsoft Outlook Security Feature Bypass Vulnerability Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. 7.5 CISA 2023-07-11 2023-08-01 Unknown
CVE-2023-32049 Microsoft Windows Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt. 8.8 CNA 2023-07-11 2023-08-01 Unknown
CVE-2023-32046 Microsoft Windows Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-07-11 2023-08-01 Unknown
CVE-2016-0165 Microsoft Win32k Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. 7.8 CISA 2023-06-22 2023-07-13 Unknown
CVE-2023-29336 Microsoft Win32k Microsoft Win32K Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. 7.8 CNA 2023-05-09 2023-05-30 Unknown
CVE-2023-28252 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-04-11 2023-05-02 Known
CVE-2019-1388 Microsoft Windows Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. 7.8 CISA 2023-04-07 2023-04-28 Known
CVE-2013-3163 Microsoft Internet Explorer Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. 8.8 CISA 2023-03-30 2023-04-20 Unknown
CVE-2023-24880 Microsoft Windows Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. 4.4 CNA 2023-03-14 2023-04-04 Known
CVE-2023-23397 Microsoft Office Microsoft Office Outlook Privilege Escalation Vulnerability Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. 9.8 CNA 2023-03-14 2023-04-04 Unknown
CVE-2023-21823 Microsoft Windows Microsoft Windows Graphic Component Privilege Escalation Vulnerability Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-02-14 2023-03-07 Unknown
CVE-2023-23376 Microsoft Windows Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2023-02-14 2023-03-07 Known
CVE-2023-21715 Microsoft Office Microsoft Office Publisher Security Feature Bypass Vulnerability Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. 7.3 CNA 2023-02-14 2023-03-07 Unknown
CVE-2023-21674 Microsoft Windows Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. 8.8 CNA 2023-01-10 2023-01-31 Unknown
CVE-2022-41080 Microsoft Exchange Server Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. 8.8 CNA 2023-01-10 2023-01-31 Known
CVE-2022-44698 Microsoft Defender Microsoft Defender SmartScreen Security Feature Bypass Vulnerability Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. 5.4 CNA 2022-12-13 2023-01-03 Known
CVE-2022-41049 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. 5.4 CNA 2022-11-14 2022-12-09 Unknown
CVE-2022-41128 Microsoft Windows Microsoft Windows Scripting Languages Remote Code Execution Vulnerability Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. 8.8 CNA 2022-11-08 2022-12-09 Unknown
CVE-2022-41125 Microsoft Windows Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. 7.8 CNA 2022-11-08 2022-12-09 Unknown
CVE-2022-41073 Microsoft Windows Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. 7.8 CNA 2022-11-08 2022-12-09 Known
CVE-2022-41091 Microsoft Windows Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. 5.4 CNA 2022-11-08 2022-12-09 Known
CVE-2022-41033 Microsoft Windows COM+ Event System Service Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. 7.8 CNA 2022-10-11 2022-11-01 Unknown
CVE-2022-41040 Microsoft Exchange Server Microsoft Exchange Server Server-Side Request Forgery Vulnerability Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution. 8.8 CNA 2022-09-30 2022-10-21 Known
CVE-2022-41082 Microsoft Exchange Server Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. 8.0 CNA 2022-09-30 2022-10-21 Known
CVE-2010-2568 Microsoft Windows Microsoft Windows Remote Code Execution Vulnerability Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. 7.8 CISA 2022-09-15 2022-10-06 Unknown