Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2020-25078 |
D-Link
DCS-2530L and DCS-2670L Devices
|
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2020-25079 |
D-Link
DCS-2530L and DCS-2670L Devices
|
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2022-40799 |
D-Link
DNR-322L
|
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2025-20337 |
Cisco
Identity Services Engine
|
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root p…
|
Network gear Yacht-focused | Jul 28, 2025 |
| CVE-2025-20281 |
Cisco
Identity Services Engine
|
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root p…
|
Network gear Yacht-focused | Jul 28, 2025 |
| CVE-2025-25257 |
Fortinet
FortiWeb
|
Fortinet FortiWeb SQL Injection Vulnerability
Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
|
Network gear Yacht-focused | Jul 18, 2025 |
| CVE-2019-6693 |
Fortinet
FortiOS
|
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
|
Ransomware Network gear Yacht-focused | Jun 25, 2025 |
| CVE-2024-0769 |
D-Link
DIR-859 Router
|
D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. Thi…
|
Network gear Yacht-focused | Jun 25, 2025 |
| CVE-2023-33538 |
TP-Link
Multiple Routers
|
TP-Link Multiple Routers Command Injection Vulnerability
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Jun 16, 2025 |
| CVE-2025-32756 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
|
Network gear Yacht-focused | May 14, 2025 |
| CVE-2023-44221 |
SonicWall
SMA100 Appliances
|
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.
|
Network gear VPN / Remote access Yacht-focused | May 1, 2025 |
| CVE-2025-1976 |
Broadcom
Brocade Fabric OS
|
Broadcom Brocade Fabric OS Code Injection Vulnerability
Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.
|
Network gear Yacht-focused | Apr 28, 2025 |
| CVE-2021-20035 |
SonicWall
SMA100 Appliances
|
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
|
Network gear Yacht-focused | Apr 16, 2025 |
| CVE-2024-20439 |
Cisco
Smart Licensing Utility
|
Cisco Smart Licensing Utility Static Credential Vulnerability
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
|
Network gear Yacht-focused | Mar 31, 2025 |
| CVE-2025-24472 |
Fortinet
FortiOS and FortiProxy
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
|
Ransomware Network gear Yacht-focused | Mar 18, 2025 |
| CVE-2025-21590 |
Juniper
Junos OS
|
Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
|
Network gear Yacht-focused | Mar 13, 2025 |
| CVE-2023-20118 |
Cisco
Small Business RV Series Routers
|
Cisco Small Business RV Series Routers Command Injection Vulnerability
Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.
|
Network gear Yacht-focused | Mar 3, 2025 |
| CVE-2025-0111 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS File Read Vulnerability
Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.
|
Network gear Yacht-focused | Feb 20, 2025 |
| CVE-2025-0108 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.
|
Network gear Yacht-focused | Feb 18, 2025 |
| CVE-2024-53704 |
SonicWall
SonicOS
|
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
|
Ransomware Network gear VPN / Remote access Yacht-focused | Feb 18, 2025 |
| CVE-2024-40891 |
Zyxel
DSL CPE Devices
|
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
|
Network gear Yacht-focused | Feb 11, 2025 |
| CVE-2024-40890 |
Zyxel
DSL CPE Devices
|
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
|
Network gear Yacht-focused | Feb 11, 2025 |
| CVE-2020-15069 |
Sophos
XG Firewall
|
Sophos XG Firewall Buffer Overflow Vulnerability
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
|
Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2020-29574 |
Sophos
CyberoamOS
|
CyberoamOS (CROS) SQL Injection Vulnerability
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
|
Ransomware Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2025-23006 |
SonicWall
SMA1000 Appliances
|
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
|
Ransomware Network gear Yacht-focused | Jan 24, 2025 |
| CVE-2024-55591 |
Fortinet
FortiOS and FortiProxy
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
|
Ransomware Network gear Yacht-focused | Jan 14, 2025 |
| CVE-2024-3393 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
|
Network gear Yacht-focused | Dec 30, 2024 |
| CVE-2024-11667 |
Zyxel
Multiple Firewalls
|
Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
|
Ransomware Network gear Yacht-focused | Dec 3, 2024 |
| CVE-2024-9474 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →