Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2024-40890 |
Zyxel
DSL CPE Devices
|
Zyxel DSL CPE OS Command Injection Vulnerability
Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.
|
Network gear Yacht-focused | Feb 11, 2025 |
| CVE-2020-15069 |
Sophos
XG Firewall
|
Sophos XG Firewall Buffer Overflow Vulnerability
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
|
Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2020-29574 |
Sophos
CyberoamOS
|
CyberoamOS (CROS) SQL Injection Vulnerability
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
|
Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2025-23006 |
SonicWall
SMA1000 Appliances
|
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
|
Ransomware Network gear Yacht-focused | Jan 24, 2025 |
| CVE-2024-55591 |
Fortinet
FortiOS and FortiProxy
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
|
Ransomware Network gear Yacht-focused | Jan 14, 2025 |
| CVE-2024-3393 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.
|
Network gear Yacht-focused | Dec 30, 2024 |
| CVE-2024-11667 |
Zyxel
Multiple Firewalls
|
Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
|
Ransomware Network gear Yacht-focused | Dec 3, 2024 |
| CVE-2024-9474 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-0012 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-9465 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition SQL Injection Vulnerability
Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
|
Network gear Yacht-focused | Nov 14, 2024 |
| CVE-2024-9463 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition OS Command Injection Vulnerability
Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
|
Network gear Yacht-focused | Nov 14, 2024 |
| CVE-2014-2120 |
Cisco
Adaptive Security Appliance (ASA)
|
Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
Network gear Yacht-focused | Nov 12, 2024 |
| CVE-2024-5910 |
Palo Alto Networks
Expedition
|
Palo Alto Networks Expedition Missing Authentication Vulnerability
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
|
Network gear Yacht-focused | Nov 7, 2024 |
| CVE-2024-20481 |
Cisco
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
|
Cisco ASA and FTD Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.
|
Network gear Yacht-focused | Oct 24, 2024 |
| CVE-2024-47575 |
Fortinet
FortiManager
|
Fortinet FortiManager Missing Authentication Vulnerability
Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
|
Network gear Yacht-focused | Oct 23, 2024 |
| CVE-2024-23113 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Format String Vulnerability
Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
|
Network gear Yacht-focused | Oct 9, 2024 |
| CVE-2023-25280 |
D-Link
DIR-820 Router
|
D-Link DIR-820 Router OS Command Injection Vulnerability
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
|
Network gear Yacht-focused | Sep 30, 2024 |
| CVE-2024-40766 |
SonicWall
SonicOS
|
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
|
Ransomware Network gear Yacht-focused | Sep 9, 2024 |
| CVE-2024-20399 |
Cisco
NX-OS
|
Cisco NX-OS Command Injection Vulnerability
Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
|
Network gear Yacht-focused | Jul 2, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →