Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2024-57727 |
SimpleHelp
SimpleHelp
|
SimpleHelp Path Traversal Vulnerability
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
|
Ransomware | Feb 13, 2025 |
| CVE-2020-29574 |
Sophos
CyberoamOS
|
CyberoamOS (CROS) SQL Injection Vulnerability
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
|
Ransomware Network gear Yacht-focused | Feb 6, 2025 |
| CVE-2025-23006 |
SonicWall
SMA1000 Appliances
|
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
|
Ransomware Network gear Yacht-focused | Jan 24, 2025 |
| CVE-2024-55591 |
Fortinet
FortiOS and FortiProxy
|
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
|
Ransomware Network gear Yacht-focused | Jan 14, 2025 |
| CVE-2023-48365 |
Qlik
Sense
|
Qlik Sense HTTP Tunneling Vulnerability
Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
|
Ransomware | Jan 13, 2025 |
| CVE-2025-0282 |
Ivanti
Connect Secure, Policy Secure, and ZTA Gateways
|
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
|
Ransomware VPN / Remote access Yacht-focused | Jan 8, 2025 |
| CVE-2024-55550 |
Mitel
MiCollab
|
Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
|
Ransomware | Jan 7, 2025 |
| CVE-2024-41713 |
Mitel
MiCollab
|
Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
|
Ransomware | Jan 7, 2025 |
| CVE-2024-55956 |
Cleo
Multiple Products
|
Cleo Multiple Products Unauthenticated File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
|
Ransomware | Dec 17, 2024 |
| CVE-2024-50623 |
Cleo
Multiple Products
|
Cleo Multiple Products Unrestricted File Upload Vulnerability
Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.
|
Ransomware | Dec 13, 2024 |
| CVE-2024-51378 |
CyberPersons
CyberPanel
|
CyberPanel Incorrect Default Permissions Vulnerability
CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
|
Ransomware | Dec 4, 2024 |
| CVE-2024-11667 |
Zyxel
Multiple Firewalls
|
Zyxel Multiple Firewalls Path Traversal Vulnerability
Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
|
Ransomware Network gear Yacht-focused | Dec 3, 2024 |
| CVE-2023-28461 |
Array Networks
AG/vxAG ArrayOS
|
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
|
Ransomware VPN / Remote access Yacht-focused | Nov 25, 2024 |
| CVE-2024-9474 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →