Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2026-24858 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
|
Network gear Yacht-focused | Jan 27, 2026 |
| CVE-2018-14634 |
Linux
Kernel
|
Linux Kernel Integer Overflow Vulnerability
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
|
Server OS / DB / Web Yacht-focused | Jan 26, 2026 |
| CVE-2024-37079 |
Broadcom
VMware vCenter Server
|
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
|
Enterprise stack Yacht-focused | Jan 23, 2026 |
| CVE-2025-68645 |
Synacor
Zimbra Collaboration Suite (ZCS)
|
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
|
Endpoint Yacht-focused | Jan 22, 2026 |
| CVE-2026-20045 |
Cisco
Unified Communications Manager
|
Cisco Unified Communications Products Code Injection Vulnerability
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain us…
|
Network gear Yacht-focused | Jan 21, 2026 |
| CVE-2025-14847 |
MongoDB
MongoDB and MongoDB Server
|
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by an unauthenticated client.
|
Server OS / DB / Web Yacht-focused | Dec 29, 2025 |
| CVE-2025-40602 |
SonicWall
SMA1000 appliance
|
SonicWall SMA1000 Missing Authorization Vulnerability
SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
|
Network gear Yacht-focused | Dec 17, 2025 |
| CVE-2025-20393 |
Cisco
Multiple Products
|
Cisco Multiple Products Improper Input Validation Vulnerability
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
|
Network gear M365 / Email Yacht-focused | Dec 17, 2025 |
| CVE-2025-59718 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message. Please be aware that CVE-2025-59719 pertains to the same problem and is mentioned in the same vendor a…
|
Network gear Yacht-focused | Dec 16, 2025 |
| CVE-2022-37055 |
D-Link
Routers
|
D-Link Routers Buffer Overflow Vulnerability
D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Dec 8, 2025 |
| CVE-2025-58034 |
Fortinet
FortiWeb
|
Fortinet FortiWeb OS Command Injection Vulnerability
Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
|
Network gear Yacht-focused | Nov 18, 2025 |
| CVE-2025-64446 |
Fortinet
FortiWeb
|
Fortinet FortiWeb Path Traversal Vulnerability
Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
|
Network gear Yacht-focused | Nov 14, 2025 |
| CVE-2025-41244 |
Broadcom
VMware Aria Operations and VMware Tools
|
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.
|
Enterprise stack Yacht-focused | Oct 30, 2025 |
| CVE-2025-59287 |
Microsoft
Windows
|
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
|
Server OS / DB / Web Yacht-focused | Oct 24, 2025 |
| CVE-2021-22555 |
Linux
Kernel
|
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.
|
Server OS / DB / Web Yacht-focused | Oct 6, 2025 |
| CVE-2017-1000353 |
Jenkins
Jenkins
|
Jenkins Remote Code Execution Vulnerability
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would be deserialized using a new ObjectInputStream, bypassing the existing blocklist-based protection mechanism.
|
Enterprise stack Yacht-focused | Oct 2, 2025 |
| CVE-2015-7755 |
Juniper
ScreenOS
|
Juniper ScreenOS Improper Authentication Vulnerability
Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.
|
Network gear Yacht-focused | Oct 2, 2025 |
| CVE-2025-20352 |
Cisco
IOS and IOS XE
|
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attac…
|
Network gear Yacht-focused | Sep 29, 2025 |
| CVE-2025-20362 |
Cisco
Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
|
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
|
Network gear Yacht-focused | Sep 25, 2025 |
| CVE-2025-20333 |
Cisco
Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
|
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
|
Network gear Yacht-focused | Sep 25, 2025 |
| CVE-2025-38352 |
Linux
Kernel
|
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
|
Server OS / DB / Web Yacht-focused | Sep 4, 2025 |
| CVE-2023-50224 |
TP-Link
TL-WR841N
|
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Server OS / DB / Web Yacht-focused | Sep 3, 2025 |
| CVE-2025-9377 |
TP-Link
Multiple Routers
|
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Sep 3, 2025 |
| CVE-2020-24363 |
TP-Link
TL-WA855RE
|
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password. The impacted products co…
|
Network gear Yacht-focused | Sep 2, 2025 |
| CVE-2025-7775 |
Citrix
NetScaler
|
Citrix NetScaler Memory Overflow Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
|
VPN / Remote access Yacht-focused | Aug 26, 2025 |
| CVE-2025-54948 |
Trend Micro
Apex One
|
Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
|
Endpoint Yacht-focused | Aug 18, 2025 |
| CVE-2020-25078 |
D-Link
DCS-2530L and DCS-2670L Devices
|
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2020-25079 |
D-Link
DCS-2530L and DCS-2670L Devices
|
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2022-40799 |
D-Link
DNR-322L
|
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Aug 5, 2025 |
| CVE-2025-20337 |
Cisco
Identity Services Engine
|
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root p…
|
Network gear Yacht-focused | Jul 28, 2025 |
| CVE-2025-20281 |
Cisco
Identity Services Engine
|
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root p…
|
Network gear Yacht-focused | Jul 28, 2025 |
| CVE-2025-49704 |
Microsoft
SharePoint
|
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
|
Ransomware M365 / Email Yacht-focused | Jul 22, 2025 |
| CVE-2025-49706 |
Microsoft
SharePoint
|
Microsoft SharePoint Improper Authentication Vulnerability
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass…
|
Ransomware M365 / Email Yacht-focused | Jul 22, 2025 |
| CVE-2025-53770 |
Microsoft
SharePoint
|
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those…
|
Ransomware M365 / Email Yacht-focused | Jul 20, 2025 |
| CVE-2025-25257 |
Fortinet
FortiWeb
|
Fortinet FortiWeb SQL Injection Vulnerability
Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
|
Network gear Yacht-focused | Jul 18, 2025 |
| CVE-2025-5777 |
Citrix
NetScaler ADC and Gateway
|
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
|
Ransomware VPN / Remote access Yacht-focused | Jul 10, 2025 |
| CVE-2025-6543 |
Citrix
NetScaler ADC and Gateway
|
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
|
VPN / Remote access Yacht-focused | Jun 30, 2025 |
| CVE-2019-6693 |
Fortinet
FortiOS
|
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
|
Ransomware Network gear Yacht-focused | Jun 25, 2025 |
| CVE-2024-0769 |
D-Link
DIR-859 Router
|
D-Link DIR-859 Router Path Traversal Vulnerability
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. Thi…
|
Network gear Yacht-focused | Jun 25, 2025 |
| CVE-2023-0386 |
Linux
Kernel
|
Linux Kernel Improper Ownership Management Vulnerability
Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the syst…
|
Server OS / DB / Web Yacht-focused | Jun 17, 2025 |
| CVE-2023-33538 |
TP-Link
Multiple Routers
|
TP-Link Multiple Routers Command Injection Vulnerability
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
|
Network gear Yacht-focused | Jun 16, 2025 |
| CVE-2025-42999 |
SAP
NetWeaver
|
SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
|
Enterprise stack Yacht-focused | May 15, 2025 |
| CVE-2025-32756 |
Fortinet
Multiple Products
|
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
|
Network gear Yacht-focused | May 14, 2025 |
| CVE-2024-38475 |
Apache
HTTP Server
|
Apache HTTP Server Improper Escaping of Output Vulnerability
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
|
Server OS / DB / Web Yacht-focused | May 1, 2025 |
| CVE-2023-44221 |
SonicWall
SMA100 Appliances
|
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.
|
Network gear VPN / Remote access Yacht-focused | May 1, 2025 |
| CVE-2025-31324 |
SAP
NetWeaver
|
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
|
Ransomware Enterprise stack Yacht-focused | Apr 29, 2025 |
| CVE-2025-1976 |
Broadcom
Brocade Fabric OS
|
Broadcom Brocade Fabric OS Code Injection Vulnerability
Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.
|
Network gear Yacht-focused | Apr 28, 2025 |
| CVE-2021-20035 |
SonicWall
SMA100 Appliances
|
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
|
Network gear Yacht-focused | Apr 16, 2025 |
| CVE-2024-53150 |
Linux
Kernel
|
Linux Kernel Out-of-Bounds Read Vulnerability
Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.
|
Server OS / DB / Web Yacht-focused | Apr 9, 2025 |
| CVE-2024-53197 |
Linux
Kernel
|
Linux Kernel Out-of-Bounds Access Vulnerability
Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.
|
Server OS / DB / Web Yacht-focused | Apr 9, 2025 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →