Skip to main content

Full CISA KEV catalog

Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.

Reset
Showing 1–30 of 30 · Page 1 of 1
Clear all filters
CVE Vendor / product Vulnerability Categories Added to KEV
CVE-2025-39964
Linux
Kernel
Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Server OS / DB / Web Yacht-focused Sep 18, 2026
CVE-2026-53266
Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or…
Server OS / DB / Web Yacht-focused Sep 18, 2026
CVE-2025-39682
Linux
Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted prod…
Server OS / DB / Web Yacht-focused Sep 18, 2026
CVE-2026-9586
Sangoma
Switchvox
Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Server OS / DB / Web Yacht-focused Sep 2, 2026
CVE-2026-53362
Linux
Kernel
Linux Kernel Unspecified Vulnerability
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
Server OS / DB / Web Yacht-focused Aug 27, 2026
CVE-2015-3246
Red Hat
Libuser
Red Hat Libuser Race Condition Vulnerability
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Server OS / DB / Web Yacht-focused Aug 26, 2026
CVE-2015-5287
Red Hat
Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a…
Server OS / DB / Web Yacht-focused Aug 26, 2026
CVE-2022-0995
Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Server OS / DB / Web Yacht-focused Aug 26, 2026
CVE-2026-34486
Apache
Tomcat
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Server OS / DB / Web Yacht-focused Aug 4, 2026
CVE-2026-20253
Splunk
Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Server OS / DB / Web Yacht-focused Jun 18, 2026
CVE-2022-0492
Linux
Kernel
Linux Kernel Improper Authentication Vulnerability
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Server OS / DB / Web Yacht-focused Jun 2, 2026
CVE-2008-4250
Microsoft
Windows
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Server OS / DB / Web Yacht-focused May 20, 2026
CVE-2026-31431
Linux
Kernel
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Server OS / DB / Web Yacht-focused May 1, 2026
CVE-2026-34197
Apache
ActiveMQ
Apache ActiveMQ Improper Input Validation Vulnerability
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Server OS / DB / Web Yacht-focused Apr 16, 2026
CVE-2018-14634
Linux
Kernel
Linux Kernel Integer Overflow Vulnerability
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Server OS / DB / Web Yacht-focused Jan 26, 2026
CVE-2025-14847
MongoDB
MongoDB and MongoDB Server
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
Server OS / DB / Web Yacht-focused Dec 29, 2025
CVE-2025-59287
Microsoft
Windows
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Server OS / DB / Web Yacht-focused Oct 24, 2025
CVE-2021-22555
Linux
Kernel
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
Server OS / DB / Web Yacht-focused Oct 6, 2025
CVE-2025-38352
Linux
Kernel
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
Server OS / DB / Web Yacht-focused Sep 4, 2025
CVE-2023-50224
TP-Link
TL-WR841N
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Network gear Server OS / DB / Web Yacht-focused Sep 3, 2025
CVE-2023-0386
Linux
Kernel
Linux Kernel Improper Ownership Management Vulnerability
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the syst…
Server OS / DB / Web Yacht-focused Jun 17, 2025
CVE-2024-38475
Apache
HTTP Server
Apache HTTP Server Improper Escaping of Output Vulnerability
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Server OS / DB / Web Yacht-focused May 1, 2025
CVE-2024-53150
Linux
Kernel
Linux Kernel Out-of-Bounds Read Vulnerability
Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.
Server OS / DB / Web Yacht-focused Apr 9, 2025
CVE-2024-53197
Linux
Kernel
Linux Kernel Out-of-Bounds Access Vulnerability
Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.
Server OS / DB / Web Yacht-focused Apr 9, 2025
CVE-2025-24813
Apache
Tomcat
Apache Tomcat Path Equivalence Vulnerability
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.
Server OS / DB / Web Yacht-focused Apr 1, 2025
CVE-2024-50302
Linux
Kernel
Linux Kernel Use of Uninitialized Resource Vulnerability
The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
Server OS / DB / Web Yacht-focused Mar 4, 2025
CVE-2017-3066
Adobe
ColdFusion
Adobe ColdFusion Deserialization Vulnerability
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
Server OS / DB / Web Yacht-focused Feb 24, 2025
CVE-2025-0994
Trimble
Cityworks
Trimble Cityworks Deserialization Vulnerability
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Server OS / DB / Web Yacht-focused Feb 7, 2025
CVE-2024-53104
Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
Server OS / DB / Web Yacht-focused Feb 5, 2025
CVE-2024-45195
Apache
OFBiz
Apache OFBiz Forced Browsing Vulnerability
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
Server OS / DB / Web Yacht-focused Feb 4, 2025

Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →

Enroll your yacht

Ready to harden your crew's
cyber posture?

Contact us +1.754.600.8735