Skip to main content

Full CISA KEV catalog

Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.

Reset
Showing 1–27 of 27 · Page 1 of 1
Clear all filters
CVE Vendor / product Vulnerability Categories Added to KEV
CVE-2022-0492
Linux
Kernel
Linux Kernel Improper Authentication Vulnerability
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Server OS / DB / Web Yacht-focused Jun 2, 2026
CVE-2008-4250
Microsoft
Windows
Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Server OS / DB / Web Yacht-focused May 20, 2026
CVE-2026-31431
Linux
Kernel
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Server OS / DB / Web Yacht-focused May 1, 2026
CVE-2026-34197
Apache
ActiveMQ
Apache ActiveMQ Improper Input Validation Vulnerability
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Server OS / DB / Web Yacht-focused Apr 16, 2026
CVE-2018-14634
Linux
Kernel
Linux Kernel Integer Overflow Vulnerability
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Server OS / DB / Web Yacht-focused Jan 26, 2026
CVE-2025-14847
MongoDB
MongoDB and MongoDB Server
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
Server OS / DB / Web Yacht-focused Dec 29, 2025
CVE-2025-59287
Microsoft
Windows
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
Server OS / DB / Web Yacht-focused Oct 24, 2025
CVE-2021-22555
Linux
Kernel
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
Server OS / DB / Web Yacht-focused Oct 6, 2025
CVE-2025-38352
Linux
Kernel
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
Server OS / DB / Web Yacht-focused Sep 4, 2025
CVE-2023-50224
TP-Link
TL-WR841N
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Network gear Server OS / DB / Web Yacht-focused Sep 3, 2025
CVE-2023-0386
Linux
Kernel
Linux Kernel Improper Ownership Management Vulnerability
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the syst…
Server OS / DB / Web Yacht-focused Jun 17, 2025
CVE-2024-38475
Apache
HTTP Server
Apache HTTP Server Improper Escaping of Output Vulnerability
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Server OS / DB / Web Yacht-focused May 1, 2025
CVE-2024-53150
Linux
Kernel
Linux Kernel Out-of-Bounds Read Vulnerability
Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.
Server OS / DB / Web Yacht-focused Apr 9, 2025
CVE-2024-53197
Linux
Kernel
Linux Kernel Out-of-Bounds Access Vulnerability
Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.
Server OS / DB / Web Yacht-focused Apr 9, 2025
CVE-2025-24813
Apache
Tomcat
Apache Tomcat Path Equivalence Vulnerability
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
Server OS / DB / Web Yacht-focused Apr 1, 2025
CVE-2024-50302
Linux
Kernel
Linux Kernel Use of Uninitialized Resource Vulnerability
The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.
Server OS / DB / Web Yacht-focused Mar 4, 2025
CVE-2017-3066
Adobe
ColdFusion
Adobe ColdFusion Deserialization Vulnerability
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
Server OS / DB / Web Yacht-focused Feb 24, 2025
CVE-2025-0994
Trimble
Cityworks
Trimble Cityworks Deserialization Vulnerability
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Server OS / DB / Web Yacht-focused Feb 7, 2025
CVE-2024-53104
Linux
Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.
Server OS / DB / Web Yacht-focused Feb 5, 2025
CVE-2024-45195
Apache
OFBiz
Apache OFBiz Forced Browsing Vulnerability
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
Server OS / DB / Web Yacht-focused Feb 4, 2025
CVE-2024-27348
Apache
HugeGraph-Server
Apache HugeGraph-Server Improper Access Control Vulnerability
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
Server OS / DB / Web Yacht-focused Sep 18, 2024
CVE-2017-1000253
Linux
Kernel
Linux Kernel PIE Stack Buffer Corruption Vulnerability
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.
Ransomware Server OS / DB / Web Yacht-focused Sep 9, 2024
CVE-2024-38856
Apache
OFBiz
Apache OFBiz Incorrect Authorization Vulnerability
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
Server OS / DB / Web Yacht-focused Aug 27, 2024
CVE-2022-0185
Linux
Kernel
Linux Kernel Heap-Based Buffer Overflow Vulnerability
Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.
Server OS / DB / Web Yacht-focused Aug 21, 2024
CVE-2024-32113
Apache
OFBiz
Apache OFBiz Path Traversal Vulnerability
Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
Server OS / DB / Web Yacht-focused Aug 7, 2024
CVE-2024-36971
Android
Kernel
Android Kernel Remote Code Execution Vulnerability
Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.
Server OS / DB / Web Mobile Yacht-focused Aug 7, 2024
CVE-2022-2586
Linux
Kernel
Linux Kernel Use-After-Free Vulnerability
Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.
Server OS / DB / Web Yacht-focused Jun 26, 2024

Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →

Enroll your yacht

Ready to harden your crew's
cyber posture?

Contact us +1.754.600.8735