Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2026-35273 |
Oracle
PeopleSoft Enterprise PeopleTools
|
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
|
Ransomware Enterprise stack Yacht-focused | Jun 12, 2026 |
| CVE-2024-21182 |
Oracle
WebLogic Server
|
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
|
Enterprise stack Yacht-focused | Jun 1, 2026 |
| CVE-2021-22054 |
Omnissa
Workspace One UEM
|
Omnissa Workspace ONE Server-Side Request Forgery
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
|
Enterprise stack Yacht-focused | Mar 9, 2026 |
| CVE-2026-22719 |
Broadcom
VMware Aria Operations
|
Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
|
Enterprise stack Yacht-focused | Mar 3, 2026 |
| CVE-2021-22175 |
GitLab
GitLab
|
GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
|
Enterprise stack Yacht-focused | Feb 18, 2026 |
| CVE-2021-39935 |
GitLab
Community and Enterprise Editions
|
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
|
Enterprise stack Yacht-focused | Feb 3, 2026 |
| CVE-2024-37079 |
Broadcom
VMware vCenter Server
|
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
|
Enterprise stack Yacht-focused | Jan 23, 2026 |
| CVE-2025-41244 |
Broadcom
VMware Aria Operations and VMware Tools
|
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
|
Enterprise stack Yacht-focused | Oct 30, 2025 |
| CVE-2017-1000353 |
Jenkins
Jenkins
|
Jenkins Remote Code Execution Vulnerability
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.
|
Enterprise stack Yacht-focused | Oct 2, 2025 |
| CVE-2025-42999 |
SAP
NetWeaver
|
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
|
Enterprise stack Yacht-focused | May 15, 2025 |
| CVE-2025-31324 |
SAP
NetWeaver
|
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
|
Ransomware Enterprise stack Yacht-focused | Apr 29, 2025 |
| CVE-2017-12637 |
SAP
NetWeaver
|
SAP NetWeaver Directory Traversal Vulnerability
SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.
|
Enterprise stack Yacht-focused | Mar 19, 2025 |
| CVE-2025-22226 |
VMware
ESXi, Workstation, and Fusion
|
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
|
Enterprise stack Yacht-focused | Mar 4, 2025 |
| CVE-2025-22225 |
VMware
ESXi
|
VMware ESXi Arbitrary Write Vulnerability
VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
|
Ransomware Enterprise stack Yacht-focused | Mar 4, 2025 |
| CVE-2025-22224 |
VMware
ESXi and Workstation
|
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
|
Enterprise stack Yacht-focused | Mar 4, 2025 |
| CVE-2020-2883 |
Oracle
WebLogic Server
|
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
|
Enterprise stack Yacht-focused | Jan 7, 2025 |
| CVE-2024-38813 |
VMware
vCenter Server
|
VMware vCenter Server Privilege Escalation Vulnerability
VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
|
Enterprise stack Yacht-focused | Nov 20, 2024 |
| CVE-2024-38812 |
VMware
vCenter Server
|
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
|
Enterprise stack Yacht-focused | Nov 20, 2024 |
| CVE-2021-26086 |
Atlassian
Jira Server and Data Center
|
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
|
Enterprise stack Yacht-focused | Nov 12, 2024 |
| CVE-2024-40711 |
Veeam
Backup & Replication
|
Veeam Backup and Replication Deserialization Vulnerability
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
|
Ransomware Enterprise stack Yacht-focused | Oct 17, 2024 |
| CVE-2020-14644 |
Oracle
WebLogic Server
|
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
|
Enterprise stack Yacht-focused | Sep 18, 2024 |
| CVE-2024-23897 |
Jenkins
Jenkins Command Line Interface (CLI)
|
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
|
Ransomware Enterprise stack Yacht-focused | Aug 19, 2024 |
| CVE-2024-37085 |
VMware
ESXi
|
VMware ESXi Authentication Bypass Vulnerability
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
|
Ransomware Enterprise stack Yacht-focused | Jul 30, 2024 |
| CVE-2024-5217 |
ServiceNow
Utah, Vancouver, and Washington DC Now Platform
|
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.
|
Enterprise stack Yacht-focused | Jul 29, 2024 |
| CVE-2024-4879 |
ServiceNow
Utah, Vancouver, and Washington DC Now Platform
|
ServiceNow Improper Input Validation Vulnerability
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
|
Enterprise stack Yacht-focused | Jul 29, 2024 |
| CVE-2022-22948 |
VMware
vCenter Server
|
VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
|
Enterprise stack Yacht-focused | Jul 17, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →