Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2023-28461 |
Array Networks
AG/vxAG ArrayOS
|
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
|
Ransomware VPN / Remote access Yacht-focused | Nov 25, 2024 |
| CVE-2024-9474 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-0012 |
Palo Alto Networks
PAN-OS
|
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
|
Ransomware Network gear Yacht-focused | Nov 18, 2024 |
| CVE-2024-49039 |
Microsoft
Windows
|
Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
|
Ransomware | Nov 12, 2024 |
| CVE-2024-51567 |
CyberPersons
CyberPanel
|
CyberPanel Incorrect Default Permissions Vulnerability
CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
|
Ransomware | Nov 7, 2024 |
| CVE-2024-38094 |
Microsoft
SharePoint
|
Microsoft SharePoint Deserialization Vulnerability
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
|
Ransomware M365 / Email Yacht-focused | Oct 22, 2024 |
| CVE-2024-40711 |
Veeam
Backup & Replication
|
Veeam Backup and Replication Deserialization Vulnerability
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
|
Ransomware Enterprise stack Yacht-focused | Oct 17, 2024 |
| CVE-2024-9680 |
Mozilla
Firefox
|
Mozilla Firefox Use-After-Free Vulnerability
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
|
Ransomware Browsers | Oct 15, 2024 |
| CVE-2024-30088 |
Microsoft
Windows
|
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
|
Ransomware | Oct 15, 2024 |
| CVE-2024-6670 |
Progress
WhatsUp Gold
|
Progress WhatsUp Gold SQL Injection Vulnerability
Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.
|
Ransomware | Sep 16, 2024 |
| CVE-2024-40766 |
SonicWall
SonicOS
|
SonicWall SonicOS Improper Access Control Vulnerability
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
|
Ransomware Network gear Yacht-focused | Sep 9, 2024 |
| CVE-2017-1000253 |
Linux
Kernel
|
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
|
Ransomware Server OS / DB / Web Yacht-focused | Sep 9, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →